implement admin panel
This commit is contained in:
+121
-2
@@ -261,12 +261,12 @@ def get_users(db_path: str) -> dict:
|
||||
cursor = connection.cursor()
|
||||
|
||||
cursor.execute('''
|
||||
SELECT userid, username, is_admin FROM Users
|
||||
SELECT userid, username, is_admin, email FROM Users
|
||||
''')
|
||||
|
||||
users = cursor.fetchall()
|
||||
|
||||
users = list(map(lambda x: {"userid": x[0], "username": x[1], "domains": [], "is_admin": bool(x[2])}, users))
|
||||
users = list(map(lambda x: {"userid": x[0], "username": x[1], "domains": [], "email": x[3], "is_admin": bool(x[2])}, users))
|
||||
|
||||
for user in users:
|
||||
cursor.execute('''
|
||||
@@ -281,3 +281,122 @@ def get_users(db_path: str) -> dict:
|
||||
user['domains'] = domains
|
||||
|
||||
return users
|
||||
|
||||
def create_user(db_path: str, username: str, password: str, domains: list = [], is_admin: bool = False, email: str = None):
|
||||
with sqlite3.connect(db_path) as connection:
|
||||
cursor = connection.cursor()
|
||||
|
||||
username.strip()
|
||||
email.strip()
|
||||
|
||||
cursor.execute('''
|
||||
SELECT COUNT(*) FROM Users
|
||||
WHERE username = ?
|
||||
''', (username, ))
|
||||
|
||||
if cursor.fetchone()[0] != 0:
|
||||
return "Username exists"
|
||||
|
||||
if username == "":
|
||||
return "Username is empty"
|
||||
|
||||
if not username.isalnum():
|
||||
return "Username is not alphanumeric"
|
||||
|
||||
if password == "":
|
||||
return "Password empty"
|
||||
|
||||
if len(password) < 8:
|
||||
return "Password is shorter than 8 characters"
|
||||
|
||||
salt = urandom(16).hex()
|
||||
password_hash = sha256( (salt + password).encode('utf-8')).hexdigest()
|
||||
|
||||
cursor.execute('''
|
||||
INSERT INTO Users (username, pwsalt, pwhash, email, is_admin) VALUES (?, ?, ?, ?, ?)
|
||||
''', (username, salt, password_hash, email, is_admin))
|
||||
|
||||
cursor.execute('''
|
||||
SELECT userid FROM Users
|
||||
WHERE username = ?
|
||||
''', (username, ))
|
||||
|
||||
userid = cursor.fetchone()[0]
|
||||
|
||||
for domain in domains:
|
||||
domain = domain.strip()
|
||||
|
||||
if domain == "":
|
||||
continue
|
||||
|
||||
cursor.execute('''
|
||||
SELECT COUNT(*) FROM Domains
|
||||
WHERE domain = ?
|
||||
''', (domain, ))
|
||||
|
||||
if cursor.fetchone()[0] != 0:
|
||||
continue
|
||||
|
||||
cursor.execute('''
|
||||
INSERT INTO Domains (userid, domain) VALUES (?, ?)
|
||||
''', (userid, domain))
|
||||
|
||||
def update_user(db_path: str, userid: int, domains: list[str] = None, password: str = None, is_admin: bool = None, email: str = None) -> tuple[bool, str]:
|
||||
with sqlite3.connect(db_path) as connection:
|
||||
cursor = connection.cursor()
|
||||
|
||||
cursor.execute('''
|
||||
SELECT COUNT(*) FROM Users
|
||||
WHERE userid = ?
|
||||
''', (userid, ))
|
||||
|
||||
if cursor.fetchone()[0] != 1:
|
||||
return False, "Uerid not found"
|
||||
|
||||
if domains is not None:
|
||||
# crude check if domains is iterable
|
||||
for domain in domains:
|
||||
break
|
||||
|
||||
cursor.execute('''
|
||||
DELETE FROM Domains
|
||||
WHERE userid = ?
|
||||
''', (userid, ))
|
||||
|
||||
for domain in domains:
|
||||
cursor.execute('''
|
||||
INSERT INTO Domains (userid, domain) VALUES (?, ?)
|
||||
''', (userid, domain))
|
||||
|
||||
if password is not None:
|
||||
set_user_password(db_path, userid, password)
|
||||
|
||||
if is_admin is not None:
|
||||
cursor.execute('''
|
||||
UPDATE Users
|
||||
SET
|
||||
is_admin = ?
|
||||
WHERE userid = ?
|
||||
''', (is_admin, userid))
|
||||
|
||||
|
||||
if email is not None:
|
||||
if email == "":
|
||||
email = None
|
||||
|
||||
cursor.execute('''
|
||||
UPDATE Users
|
||||
SET
|
||||
email = ?
|
||||
WHERE userid = ?
|
||||
''', (email, userid))
|
||||
|
||||
|
||||
|
||||
def delete_user(db_path: str, userid: int):
|
||||
with sqlite3.connect(db_path) as connection:
|
||||
cursor = connection.cursor()
|
||||
|
||||
cursor.execute('DELETE FROM Domains WHERE userid = ?', (userid,))
|
||||
cursor.execute('DELETE FROM Tokens WHERE userid = ?', (userid,))
|
||||
cursor.execute('DELETE FROM Users WHERE userid = ?', (userid,))
|
||||
|
||||
Reference in New Issue
Block a user