generated from uberswe/golang-base-project
/
register.go
161 lines (137 loc) · 4.47 KB
/
register.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
package routes
import (
"fmt"
email2 "github.com/ahamtat/go-url-shortener/email"
"github.com/ahamtat/go-url-shortener/models"
"github.com/ahamtat/go-url-shortener/util"
"github.com/gin-gonic/gin"
"github.com/go-playground/validator/v10"
"golang.org/x/crypto/bcrypt"
"gorm.io/gorm"
"log"
"net/http"
"net/url"
"path"
"time"
)
func (controller Controller) Register(c *gin.Context) {
pd := PageData{
Title: "Register",
IsAuthenticated: isAuthenticated(c),
CacheParameter: controller.config.CacheParameter,
}
c.HTML(http.StatusOK, "register.html", pd)
}
func (controller Controller) RegisterPost(c *gin.Context) {
passwordError := "Your password must be 8 characters in length or longer"
registerError := "Could not register, please make sure the details you have provided are correct and that you do not already have an existing account."
registerSuccess := "Thank you for registering. An activation email has been sent with steps describing how to activate your account."
pd := PageData{
Title: "Register",
IsAuthenticated: isAuthenticated(c),
CacheParameter: controller.config.CacheParameter,
}
password := c.PostForm("password")
if len(password) < 8 {
pd.Messages = append(pd.Messages, Message{
Type: "error",
Content: passwordError,
})
c.HTML(http.StatusBadRequest, "register.html", pd)
return
}
// The password is hashed as early as possible to make timing attacks that reveal registered users harder
hashedPassword, err := bcrypt.GenerateFromPassword([]byte(password), bcrypt.DefaultCost)
if err != nil {
pd.Messages = append(pd.Messages, Message{
Type: "error",
Content: registerError,
})
log.Println(err)
c.HTML(http.StatusInternalServerError, "register.html", pd)
return
}
email := c.PostForm("email")
// Validate the email
validate := validator.New()
err = validate.Var(email, "required,email")
if err != nil {
pd.Messages = append(pd.Messages, Message{
Type: "error",
Content: registerError,
})
log.Println(err)
c.HTML(http.StatusInternalServerError, "register.html", pd)
return
}
user := models.User{Email: email}
res := controller.db.Where(&user).First(&user)
if (res.Error != nil && res.Error != gorm.ErrRecordNotFound) || res.RowsAffected > 0 {
pd.Messages = append(pd.Messages, Message{
Type: "error",
Content: registerError,
})
log.Println(res.Error)
c.HTML(http.StatusInternalServerError, "register.html", pd)
return
}
if err != nil {
pd.Messages = append(pd.Messages, Message{
Type: "error",
Content: registerError,
})
log.Println(err)
c.HTML(http.StatusInternalServerError, "register.html", pd)
return
}
user.Password = string(hashedPassword)
res = controller.db.Save(&user)
if res.Error != nil || res.RowsAffected == 0 {
pd.Messages = append(pd.Messages, Message{
Type: "error",
Content: registerError,
})
log.Println(res.Error)
c.HTML(http.StatusInternalServerError, "register.html", pd)
return
}
// Generate activation token and send activation email
go controller.activationEmailHandler(user.ID, email)
pd.Messages = append(pd.Messages, Message{
Type: "success",
Content: registerSuccess,
})
c.HTML(http.StatusOK, "register.html", pd)
}
func (controller Controller) activationEmailHandler(userID uint, email string) {
activationToken := models.Token{
Value: util.GenerateULID(),
Type: models.TokenUserActivation,
}
res := controller.db.Where(&activationToken).First(&activationToken)
if (res.Error != nil && res.Error != gorm.ErrRecordNotFound) || res.RowsAffected > 0 {
// If the activation token already exists we try to generate it again
controller.activationEmailHandler(userID, email)
return
}
activationToken.ModelID = int(userID)
activationToken.ModelType = "User"
activationToken.ExpiresAt = time.Now().Add(time.Minute * 10)
res = controller.db.Save(&activationToken)
if res.Error != nil || res.RowsAffected == 0 {
log.Println(res.Error)
return
}
controller.sendActivationEmail(activationToken.Value, email)
}
func (controller Controller) sendActivationEmail(token string, email string) {
u, err := url.Parse(controller.config.BaseURL)
if err != nil {
log.Println(err)
return
}
u.Path = path.Join(u.Path, "/activate/", token)
activationURL := u.String()
emailService := email2.New(controller.config)
emailService.Send(email, "User Activation", fmt.Sprintf("Use the following link to activate your account. If this was not requested by you, please ignore this email.\n%s", activationURL))
}