auth

Paddy 2015-05-17 Parent:6f473576c6ae

172:8ecb60d29b0d Go to Latest

auth/session_postgres.go

Support email verification. The bulk of this commit is auto-modifying files to export variables (mostly our request error types and our response type) so that they can be reused in a Go client for that API. We also implement the beginnings of a Go client for that API, implementing the bare minimum we need for our immediate purposes: the ability to retrieve information about a Login. This, of course, means we need an API endpoint that will return information about a Login, which in turn required us to implement a GetLogin method in our profileStore. Which got in-memory and postgres implementations. That done, we could add the Verification field and Verified field to the Login type, to keep track of whether we've verified the user's ownership of those communication methods (if the Login is, in fact, a communication method). This required us to update sql/postgres_init.sql to account for the new fields we're tracking. It also means that when creating a Login, we had to generate a UUID to use as the Verification field. To make things complete, we needed a verifyLogin method on the profileStore to mark a Login as verified. That, in turn, required an endpoint to control this through the API. While doing so, I lumped things together in an UpdateLogin handler just so we could reuse the endpoint and logic when resending a verification email that may have never reached the user, for whatever reason (the quintessential "send again" button). Finally, we implemented an email_verification listener that will pull email_verification events off NSQ, check for the requisite data integrity, and use mailgun to email out a verification/welcome email.

History
1 package auth
3 import (
4 "time"
6 "code.secondbit.org/uuid.hg"
8 "github.com/lib/pq"
9 "github.com/secondbit/pan"
10 )
12 func (s Session) GetSQLTableName() string {
13 return "sessions"
14 }
16 func (p *postgres) createSessionSQL(session Session) *pan.Query {
17 fields, values := pan.GetFields(session)
18 query := pan.New(pan.POSTGRES, "INSERT INTO "+pan.GetTableName(session))
19 query.Include("(" + pan.QueryList(fields) + ")")
20 query.Include("VALUES")
21 query.Include("("+pan.VariableList(len(values))+")", values...)
22 return query.FlushExpressions(" ")
23 }
25 func (p *postgres) createSession(session Session) error {
26 query := p.createSessionSQL(session)
27 _, err := p.db.Exec(query.String(), query.Args...)
28 if e, ok := err.(*pq.Error); ok && e.Constraint == "sessions_pkey" {
29 err = ErrSessionAlreadyExists
30 }
31 return err
32 }
34 func (p *postgres) getSessionSQL(id string) *pan.Query {
35 var session Session
36 fields, _ := pan.GetFields(session)
37 query := pan.New(pan.POSTGRES, "SELECT "+pan.QueryList(fields)+" FROM "+pan.GetTableName(session))
38 query.IncludeWhere()
39 query.Include(pan.GetUnquotedColumn(session, "ID")+" = ?", id)
40 return query.FlushExpressions(" ")
41 }
43 func (p *postgres) getSession(id string) (Session, error) {
44 query := p.getSessionSQL(id)
45 rows, err := p.db.Query(query.String(), query.Args...)
46 if err != nil {
47 return Session{}, err
48 }
49 var session Session
50 var found bool
51 for rows.Next() {
52 err := pan.Unmarshal(rows, &session)
53 if err != nil {
54 return session, err
55 }
56 found = true
57 }
58 if err = rows.Err(); err != nil {
59 return session, err
60 }
61 if !found {
62 return session, ErrSessionNotFound
63 }
64 return session, nil
65 }
67 func (p *postgres) terminateSessionSQL(id string) *pan.Query {
68 var session Session
69 query := pan.New(pan.POSTGRES, "UPDATE "+pan.GetTableName(session)+" SET")
70 query.Include(pan.GetUnquotedColumn(session, "Active")+" = ?", false)
71 query.IncludeWhere()
72 query.Include(pan.GetUnquotedColumn(session, "ID")+" = ?", id)
73 return query.FlushExpressions(" ")
74 }
76 func (p *postgres) terminateSession(id string) error {
77 query := p.terminateSessionSQL(id)
78 res, err := p.db.Exec(query.String(), query.Args...)
79 if err != nil {
80 return err
81 }
82 rows, err := res.RowsAffected()
83 if err != nil {
84 return err
85 }
86 if rows < 1 {
87 return ErrSessionNotFound
88 }
89 return nil
90 }
92 func (p *postgres) terminateSessionsByProfileSQL(profile uuid.ID) *pan.Query {
93 var session Session
94 query := pan.New(pan.POSTGRES, "UPDATE "+pan.GetTableName(session)+" SET")
95 query.Include(pan.GetUnquotedColumn(session, "Active")+" = ?", false)
96 query.IncludeWhere()
97 query.Include(pan.GetUnquotedColumn(session, "ProfileID")+" = ?", profile)
98 return query.FlushExpressions(" ")
99 }
101 func (p *postgres) terminateSessionsByProfile(profile uuid.ID) error {
102 query := p.terminateSessionsByProfileSQL(profile)
103 res, err := p.db.Exec(query.String(), query.Args...)
104 if err != nil {
105 return err
106 }
107 rows, err := res.RowsAffected()
108 if err != nil {
109 return err
110 }
111 if rows < 1 {
112 return ErrProfileNotFound
113 }
114 return nil
115 }
117 func (p *postgres) removeSessionSQL(id string) *pan.Query {
118 var session Session
119 query := pan.New(pan.POSTGRES, "DELETE FROM "+pan.GetTableName(session))
120 query.IncludeWhere()
121 query.Include(pan.GetUnquotedColumn(session, "ID")+" = ?", id)
122 return query.FlushExpressions(" ")
123 }
125 func (p *postgres) removeSession(id string) error {
126 query := p.removeSessionSQL(id)
127 res, err := p.db.Exec(query.String(), query.Args...)
128 if err != nil {
129 return err
130 }
131 rows, err := res.RowsAffected()
132 if err != nil {
133 return err
134 }
135 if rows < 1 {
136 return ErrSessionNotFound
137 }
138 return nil
139 }
141 func (p *postgres) listSessionsSQL(profile uuid.ID, before time.Time, num int64) *pan.Query {
142 var session Session
143 fields, _ := pan.GetFields(session)
144 query := pan.New(pan.POSTGRES, "SELECT "+pan.QueryList(fields)+" FROM "+pan.GetTableName(session))
145 query.IncludeWhere()
146 query.Include(pan.GetUnquotedColumn(session, "ProfileID")+" = ?", profile)
147 if !before.IsZero() {
148 query.Include(pan.GetUnquotedColumn(session, "Created")+" < ?", before)
149 }
150 query.FlushExpressions(" AND ")
151 if num > 0 {
152 query.IncludeLimit(num)
153 }
154 return query.FlushExpressions(" ")
155 }
157 func (p *postgres) listSessions(profile uuid.ID, before time.Time, num int64) ([]Session, error) {
158 query := p.listSessionsSQL(profile, before, num)
159 rows, err := p.db.Query(query.String(), query.Args...)
160 if err != nil {
161 return []Session{}, err
162 }
163 var sessions []Session
164 for rows.Next() {
165 var session Session
166 err := pan.Unmarshal(rows, &session)
167 if err != nil {
168 return sessions, err
169 }
170 sessions = append(sessions, session)
171 }
172 if err = rows.Err(); err != nil {
173 return sessions, err
174 }
175 return sessions, nil
176 }