Fixed anonymous access mode, Closes #1586

This commit is contained in:
Torkel Ödegaard
2015-03-11 17:34:11 +01:00
parent f3d4d2782f
commit 477e035f2e
6 changed files with 25 additions and 31 deletions
+2 -2
View File
@@ -23,7 +23,7 @@ func getRequestUserId(c *Context) int64 {
}
// TODO: figure out a way to secure this
if c.Query("render") == "1" {
if c.Req.URL.Query().Get("render") == "1" {
userId := c.QueryInt64(SESS_KEY_USERID)
c.Session.Set(SESS_KEY_USERID, userId)
return userId
@@ -75,7 +75,7 @@ func Auth(options *AuthOptions) macaron.Handler {
return
}
if !c.IsSignedIn && options.ReqSignedIn && !c.HasAnonymousAccess {
if !c.IsSignedIn && options.ReqSignedIn && !c.AllowAnonymous {
c.SetCookie("redirect_to", url.QueryEscape(setting.AppSubUrl+c.Req.RequestURI), 0, setting.AppSubUrl+"/")
authDenied(c)
return
+9 -18
View File
@@ -1,7 +1,6 @@
package middleware
import (
"encoding/json"
"strconv"
"strings"
@@ -21,18 +20,18 @@ type Context struct {
Session session.Store
IsSignedIn bool
HasAnonymousAccess bool
IsSignedIn bool
AllowAnonymous bool
}
func GetContextHandler() macaron.Handler {
return func(c *macaron.Context, sess session.Store) {
ctx := &Context{
Context: c,
Session: sess,
SignedInUser: &m.SignedInUser{},
IsSignedIn: false,
HasAnonymousAccess: false,
Context: c,
Session: sess,
SignedInUser: &m.SignedInUser{},
IsSignedIn: false,
AllowAnonymous: false,
}
// try get account id from request
@@ -76,12 +75,10 @@ func GetContextHandler() macaron.Handler {
} else if setting.AnonymousEnabled {
orgQuery := m.GetOrgByNameQuery{Name: setting.AnonymousOrgName}
if err := bus.Dispatch(&orgQuery); err != nil {
if err == m.ErrOrgNotFound {
log.Error(3, "Anonymous access organization name does not exist", nil)
}
log.Error(3, "Anonymous access organization error", nil)
} else {
ctx.IsSignedIn = false
ctx.HasAnonymousAccess = true
ctx.AllowAnonymous = true
ctx.SignedInUser = &m.SignedInUser{}
ctx.OrgRole = m.RoleType(setting.AnonymousOrgRole)
ctx.OrgId = orgQuery.Result.Id
@@ -141,9 +138,3 @@ func (ctx *Context) JsonApiErr(status int, message string, err error) {
ctx.JSON(status, resp)
}
func (ctx *Context) JsonBody(model interface{}) bool {
b, _ := ctx.Req.Body().Bytes()
err := json.Unmarshal(b, &model)
return err == nil
}