diff --git a/app/controllers/api/v1/users_controller.rb b/app/controllers/api/v1/users_controller.rb index 55f5cfb22..37a41ff75 100644 --- a/app/controllers/api/v1/users_controller.rb +++ b/app/controllers/api/v1/users_controller.rb @@ -1,6 +1,78 @@ class Api::V1::UsersController < Api::V1::BaseController - def index - render_ok + before_action :load_observe_user + before_action :check_auth_for_observe_user + + def send_email_vefify_code + code = %W(0 1 2 3 4 5 6 7 8 9) + verification_code = code.sample(6).join + mail = params[:email] + code_type = params[:code_type] + + sign = Digest::MD5.hexdigest("#{OPENKEY}#{mail}") + Rails.logger.info sign + + tip_exception(501, "请求不合理") if sign != params[:smscode] + + # 60s内不能重复发送 + send_email_limit_cache_key = "send_email_60_second_limit:#{mail}" + tip_exception(-1, '请勿频繁操作') if Rails.cache.exist?(send_email_limit_cache_key) + send_email_control = LimitForbidControl::SendEmailCode.new(mail) + tip_exception(-1, '邮件发送太频繁,请稍后再试') if send_email_control.forbid? + begin + UserMailer.update_email(mail, verification_code).deliver_now + + Rails.cache.write(send_email_limit_cache_key, 1, expires_in: 1.minute) + send_email_control.increment! + rescue Exception => e + logger_error(e) + tip_exception(-2,"邮件发送失败,请稍后重试") + end + ver_params = {code_type: code_type, code: verification_code, email: mail} + data = VerificationCode.new(ver_params) + if data.save! + render_ok + else + tip_exception(-1, "创建数据失败") + end + end + + def check_password + password = params[:password] + return render_error("8~16位密码,支持字母数字和符号") unless password =~ CustomRegexp::PASSWORD + return render_error("密码错误") unless @observe_user.check_password?(password) + render_ok + end + + def check_email + mail = strip(params[:email]) + return render_error("邮件格式有误") unless mail =~ CustomRegexp::EMAIL + + exist_owner = Owner.find_by(mail: mail) + return render_error('邮箱已被使用') if exist_owner + render_ok + end + + def check_email_verify_code + code = strip(params[:code]) + mail = strip(params[:email]) + code_type = params[:code_type] + + return render_error("邮件格式有误") unless mail =~ CustomRegexp::EMAIL + + verifi_code = VerificationCode.where(email: mail, code: code, code_type: code_type).last + + return render_error("验证码不正确") if verifi_code&.code != code + return render_error("验证码已失效") if !verifi_code&.effective? + render_ok + end + + def update_email + @result_object = Api::V1::Users::UpdateEmailService.call(@observe_user, params, current_user.gitea_token) + if @result_object + return render_ok + else + return render_error('更改邮箱失败!') + end end end \ No newline at end of file diff --git a/app/controllers/concerns/api/user_helper.rb b/app/controllers/concerns/api/user_helper.rb index e6156ea56..4c7b713fc 100644 --- a/app/controllers/concerns/api/user_helper.rb +++ b/app/controllers/concerns/api/user_helper.rb @@ -16,4 +16,13 @@ module Api::UserHelper end @observe_user end + + # 是否具有查看用户或编辑用户的权限 + def check_auth_for_observe_user + return render_forbidden unless current_user.admin? || @observe_user.id == current_user.id + end + + def strip(str) + str.to_s.strip.presence + end end \ No newline at end of file diff --git a/app/controllers/concerns/register_helper.rb b/app/controllers/concerns/register_helper.rb index 2e910d8c4..e1b7dee24 100644 --- a/app/controllers/concerns/register_helper.rb +++ b/app/controllers/concerns/register_helper.rb @@ -16,6 +16,7 @@ module RegisterHelper return unless user.valid? interactor = Gitea::RegisterInteractor.call({username: username, email: email, password: password}) + result ={} if interactor.success? gitea_user = interactor.result result = Gitea::User::GenerateTokenService.call(username, password) @@ -26,7 +27,7 @@ module RegisterHelper result[:user] = {id: user.id, token: user.gitea_token} end else - result[:message] = interactor.error + result[:message] = interactor.result[:message] end result end diff --git a/app/docs/slate/source/includes/_users.md b/app/docs/slate/source/includes/_users.md index 318c7930a..e16a52033 100644 --- a/app/docs/slate/source/includes/_users.md +++ b/app/docs/slate/source/includes/_users.md @@ -2304,4 +2304,189 @@ await octokit.request('GET /api/users/:login/applied_projects/:id/refuse.json') "created_at": "2021-06-09 16:41", "time_ago": "7分钟前" } +``` + + +## 用户发送邮件验证码 +用户发送邮件验证码 + +> 示例: + +```shell +curl -X GET http://localhost:3000/api/v1/yystopf/send_email_vefify_code.json +``` + +```javascript +await octokit.request('GET /api/v1/:login/send_email_vefify_code.json') +``` + +### HTTP 请求 +`GET /api/v1/:login/send_email_vefify_code.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|code_type |int |10: 更新邮箱| +|email |string |邮箱| +|smscode |string |邮箱md5加密值| + +### 返回字段说明: + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} +``` + + +## 用户验证邮件验证码 +用户验证邮件验证码 + +> 示例: + +```shell +curl -X POST http://localhost:3000/api/v1/yystopf/check_email_verify_code.json +``` + +```javascript +await octokit.request('POST /api/v1/:login/check_email_verify_code.json') +``` + +### HTTP 请求 +`POST /api/v1/:login/check_email_verify_code.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|code_type |int |10: 更新邮箱| +|email |string |邮箱| +|code |string |邮箱验证码| + +### 返回字段说明: + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} +``` + + +## 用户验证密码 +用户验证密码,检查是否和用户密码一致 + +> 示例: + +```shell +curl -X POST http://localhost:3000/api/v1/yystopf/check_password.json +``` + +```javascript +await octokit.request('POST /api/v1/:login/check_password.json') +``` + +### HTTP 请求 +`POST /api/v1/:login/check_password.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|password |string |用户密码| + +### 返回字段说明: + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} +``` + + +## 用户验证邮箱 +用户验证邮箱是否符合规范以及是否已被使用 + +> 示例: + +```shell +curl -X POST http://localhost:3000/api/v1/yystopf/check_email.json +``` + +```javascript +await octokit.request('POST /api/v1/:login/check_email.json') +``` + +### HTTP 请求 +`POST /api/v1/:login/check_email.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|email |string |邮箱地址| + +### 返回字段说明: + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} +``` + + +## 用户更改邮箱 +用户更改一个新的邮箱 + +> 示例: + +```shell +curl -X PATCH http://localhost:3000/api/v1/yystopf/update_email.json +``` + +```javascript +await octokit.request('PATCH /api/v1/:login/update_email.json') +``` + +### HTTP 请求 +`PATCH /api/v1/:login/update_email.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|password |string |用户密码| +|email |string |邮箱地址| +|code |string |邮箱验证码| + + +> 请求的JSON示例: + +```json +{ + "password": "Aa19960425.", + "code": "657134", + "email": "yystopf@163.com" +} +``` + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} ``` \ No newline at end of file diff --git a/app/mailers/user_mailer.rb b/app/mailers/user_mailer.rb index acd34fbbd..21ed5b0d5 100644 --- a/app/mailers/user_mailer.rb +++ b/app/mailers/user_mailer.rb @@ -8,4 +8,8 @@ class UserMailer < ApplicationMailer mail(to: mail, subject: 'Gitink | 注册验证码') end + def update_email(mail, code) + @code = code + mail(to: mail, subject: 'Gitink | 更改邮箱验证码') + end end diff --git a/app/services/api/v1/users/update_email_service.rb b/app/services/api/v1/users/update_email_service.rb new file mode 100644 index 000000000..e11dd2f61 --- /dev/null +++ b/app/services/api/v1/users/update_email_service.rb @@ -0,0 +1,68 @@ +class Api::V1::Users::UpdateEmailService < ApplicationService + include ActiveModel::Model + + attr_reader :user, :token, :password, :mail, :old_mail, :code, :verify_code + attr_accessor :gitea_data + + validates :password, :code, presence: true + validates :mail, presence: true, format: { with: CustomRegexp::EMAIL } + + def initialize(user, params, token =nil) + @user = user + @token = token + @password = params[:password] + @mail = params[:email] + @old_mail = user.mail + @code = params[:code] + @verify_code = VerificationCode.where(email: @mail, code: @code, code_type: 10).last + end + + def call + raise Error, errors.full_messages.join(",") unless valid? + raise Error, "密码不正确." unless @user.check_password?(@password) + raise Error, "验证码不正确." if @verify_code&.code != @code + raise Error, "验证码已失效." if !@verify_code&.effective? + + # begin + ActiveRecord::Base.transaction do + change_user_email + excute_data_to_gitea + excute_change_email_from_gitea + end + + return gitea_data + + # rescue + # raise Error, "服务器错误,请联系系统管理员!" + # end + end + + private + def request_params + { + access_token: token + } + end + + def request_body + { + email: @mail, + login_name: @user.login, + source_id: 0 + } + end + + def change_user_email + @user.update_attributes!({mail: @mail}) + end + + def excute_data_to_gitea + Rails.logger.info request_body + @gitea_data = $gitea_client.patch_admin_users_by_username(@user.login, {body: request_body.to_json}) + end + + def excute_change_email_from_gitea + $gitea_client.delete_user_emails({body: {emails: [@old_mail]}.to_json, query: request_params}) + $gitea_client.post_user_emails({body: {emails: [@mail]}.to_json, query: request_params}) + end +end \ No newline at end of file diff --git a/app/views/user_mailer/update_email.html.erb b/app/views/user_mailer/update_email.html.erb new file mode 100644 index 000000000..c93366e4a --- /dev/null +++ b/app/views/user_mailer/update_email.html.erb @@ -0,0 +1,61 @@ + +
+ ++ 您好! +
++ 你正在进行GitLink邮箱更改操作,如非本人操作,请忽略。 +
+<%= @code %>
++ 如果您并未发过此请求,则可能是因为其他用户在注册时误输了您的邮件地址,而使您收到了这封邮件,那么您可以放心的忽略此邮件,无需进一步采取任何操作。 +
+用户发送邮件验证码
+ +++示例:
+
curl -X GET http://localhost:3000/api/v1/yystopf/send_email_vefify_code.json
+
await octokit.request('GET /api/v1/:login/send_email_vefify_code.json')
+
GET /api/v1/:login/send_email_vefify_code.json
参数 | +类型 | +字段说明 | +
---|---|---|
login | +string | +用户标识 | +
code_type | +int | +10: 更新邮箱 | +
string | +邮箱 | +|
smscode | +string | +邮箱md5加密值 | +
++返回的JSON示例:
+
{
+ "status": 0,
+ "message": "success"
+}
+
用户验证邮件验证码
+ +++示例:
+
curl -X POST http://localhost:3000/api/v1/yystopf/check_email_verify_code.json
+
await octokit.request('POST /api/v1/:login/check_email_verify_code.json')
+
POST /api/v1/:login/check_email_verify_code.json
参数 | +类型 | +字段说明 | +
---|---|---|
login | +string | +用户标识 | +
code_type | +int | +10: 更新邮箱 | +
string | +邮箱 | +|
code | +string | +邮箱验证码 | +
++返回的JSON示例:
+
{
+ "status": 0,
+ "message": "success"
+}
+
用户验证密码,检查是否和用户密码一致
+ +++示例:
+
curl -X POST http://localhost:3000/api/v1/yystopf/check_password.json
+
await octokit.request('POST /api/v1/:login/check_password.json')
+
POST /api/v1/:login/check_password.json
参数 | +类型 | +字段说明 | +
---|---|---|
login | +string | +用户标识 | +
password | +string | +用户密码 | +
++返回的JSON示例:
+
{
+ "status": 0,
+ "message": "success"
+}
+
用户验证邮箱是否符合规范以及是否已被使用
+ +++示例:
+
curl -X POST http://localhost:3000/api/v1/yystopf/check_email.json
+
await octokit.request('POST /api/v1/:login/check_email.json')
+
POST /api/v1/:login/check_email.json
参数 | +类型 | +字段说明 | +
---|---|---|
login | +string | +用户标识 | +
string | +邮箱地址 | +
++返回的JSON示例:
+
{
+ "status": 0,
+ "message": "success"
+}
+
用户更改一个新的邮箱
+ +++示例:
+
curl -X PATCH http://localhost:3000/api/v1/yystopf/update_email.json
+
await octokit.request('PATCH /api/v1/:login/update_email.json')
+
PATCH /api/v1/:login/update_email.json
参数 | +类型 | +字段说明 | +
---|---|---|
login | +string | +用户标识 | +
password | +string | +用户密码 | +
string | +邮箱地址 | +|
code | +string | +邮箱验证码 | +
++请求的JSON示例:
+
{
+ "password": "Aa19960425.",
+ "code": "657134",
+ "email": "yystopf@163.com"
+}
+
++返回的JSON示例:
+
{
+ "status": 0,
+ "message": "success"
+}
当前登录(管理员)用户获取项目邀请链接的接口(第一次请求会默认生成role类型为developer和is_apply为true的链接)