users_controller.rb 7.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355
  1. class UsersController < ApplicationController
  2. before_filter :authentication_check, :except => [:create, :password_reset_send, :password_reset_verify]
  3. =begin
  4. Format:
  5. JSON
  6. Example:
  7. {
  8. "id":2,
  9. "organization_id":null,
  10. "login":"m@edenhofer.de",
  11. "firstname":"Marti",
  12. "lastname":"Ede",
  13. "email":"m@edenhofer.de",
  14. "image":"http://www.gravatar.com/avatar/1c38b099f2344976005de69965733465?s=48",
  15. "web":"http://127.0.0.1",
  16. "password":"123",
  17. "phone":"112",
  18. "fax":"211",
  19. "mobile":"",
  20. "street":"",
  21. "zip":"",
  22. "city":"",
  23. "country":null,
  24. "verified":false,
  25. "active":true,
  26. "note":"some note",
  27. "source":null,
  28. "role_ids":[1,2],
  29. "group_ids":[1,2,3,4],
  30. }
  31. =end
  32. =begin
  33. Resource:
  34. GET /api/users.json
  35. Response:
  36. [
  37. {
  38. "id": 1,
  39. "login": "some_login1",
  40. ...
  41. },
  42. {
  43. "id": 2,
  44. "login": "some_login2",
  45. ...
  46. }
  47. ]
  48. Test:
  49. curl http://localhost/api/users.json -v -u #{login}:#{password}
  50. =end
  51. def index
  52. users = User.all
  53. users_all = []
  54. users.each {|user|
  55. users_all.push User.user_data_full( user.id )
  56. }
  57. render :json => users_all
  58. end
  59. =begin
  60. Resource:
  61. GET /api/users/1.json
  62. Response:
  63. {
  64. "id": 1,
  65. "login": "some_login1",
  66. ...
  67. },
  68. Test:
  69. curl http://localhost/api/users/#{id}.json -v -u #{login}:#{password}
  70. =end
  71. def show
  72. user = User.user_data_full( params[:id] )
  73. render :json => user
  74. end
  75. =begin
  76. Resource:
  77. POST /api/users.json
  78. Payload:
  79. {
  80. "login": "some_login",
  81. "firstname": "some firstname",
  82. "lastname": "some lastname",
  83. "email": "some@example.com"
  84. }
  85. Response:
  86. {
  87. "id": 1,
  88. "login": "some_login",
  89. ...
  90. },
  91. Test:
  92. curl http://localhost/api/users.json -v -u #{login}:#{password} -H "Content-Type: application/json" -X POST -d '{"login": "some_login","firstname": "some firstname","lastname": "some lastname","email": "some@example.com"}'
  93. =end
  94. def create
  95. user = User.new( User.param_cleanup(params) )
  96. user.updated_by_id = (current_user && current_user.id) || 1
  97. user.created_by_id = (current_user && current_user.id) || 1
  98. begin
  99. # if it's a signup, add user to customer role
  100. if user.created_by_id == 1
  101. # check if it's first user
  102. count = User.all.count()
  103. group_ids = []
  104. role_ids = []
  105. # add first user as admin/agent and to all groups
  106. if count <= 2
  107. Role.where( :name => [ 'Admin', 'Agent'] ).each { |role|
  108. role_ids.push role.id
  109. }
  110. Group.all().each { |group|
  111. group_ids.push group.id
  112. }
  113. # everybody else will go as customer per default
  114. else
  115. role_ids.push Role.where( :name => 'Customer' ).first.id
  116. end
  117. user.role_ids = role_ids
  118. user.group_ids = group_ids
  119. # else do assignment as defined
  120. else
  121. if params[:role_ids]
  122. user.role_ids = params[:role_ids]
  123. end
  124. if params[:group_ids]
  125. user.group_ids = params[:group_ids]
  126. end
  127. end
  128. user.save
  129. # send inviteation if needed / only if session exists
  130. if params[:invite] && current_user
  131. # generate token
  132. token = Token.create( :action => 'PasswordReset', :user_id => user.id )
  133. # send mail
  134. data = {}
  135. data[:subject] = 'Invitation to #{config.product_name} at #{config.fqdn}'
  136. data[:body] = 'Hi {user.firstname},
  137. I (#{current_user.firstname} #{current_user.lastname}) invite you to #{config.product_name} - a customer support / ticket system platform.
  138. Click on the following link and set your password:
  139. #{config.http_type}://#{config.fqdn}/#password_reset_verify/#{token.name}
  140. Enjoy,
  141. #{current_user.firstname} #{current_user.lastname}
  142. Your #{config.product_name} Team
  143. '
  144. # prepare subject & body
  145. [:subject, :body].each { |key|
  146. data[key.to_sym] = NotificationFactory.build(
  147. :string => data[key.to_sym],
  148. :objects => {
  149. :token => token,
  150. :user => user,
  151. :current_user => current_user,
  152. }
  153. )
  154. }
  155. # send notification
  156. NotificationFactory.send(
  157. :recipient => user,
  158. :subject => data[:subject],
  159. :body => data[:body]
  160. )
  161. end
  162. user_new = User.user_data_full( user.id )
  163. render :json => user_new, :status => :created
  164. rescue Exception => e
  165. render :json => { :error => e.message }, :status => :unprocessable_entity
  166. end
  167. end
  168. =begin
  169. Resource:
  170. PUT /api/users/#{id}.json
  171. Payload:
  172. {
  173. "login": "some_login",
  174. "firstname": "some firstname",
  175. "lastname": "some lastname",
  176. "email": "some@example.com"
  177. }
  178. Response:
  179. {
  180. "id": 2,
  181. "login": "some_login",
  182. ...
  183. },
  184. Test:
  185. curl http://localhost/api/users/2.json -v -u #{login}:#{password} -H "Content-Type: application/json" -X PUT -d '{"login": "some_login","firstname": "some firstname","lastname": "some lastname","email": "some@example.com"}'
  186. =end
  187. def update
  188. user = User.find(params[:id])
  189. begin
  190. user.update_attributes( User.param_cleanup(params) )
  191. if params[:role_ids]
  192. user.role_ids = params[:role_ids]
  193. end
  194. if params[:group_ids]
  195. user.group_ids = params[:group_ids]
  196. end
  197. if params[:organization_ids]
  198. user.organization_ids = params[:organization_ids]
  199. end
  200. user_new = User.user_data_full( params[:id] )
  201. render :json => user_new, :status => :ok
  202. rescue Exception => e
  203. render :json => { :error => e.message }, :status => :unprocessable_entity
  204. end
  205. end
  206. # DELETE /api/users/1
  207. def destroy
  208. model_destory_render(User, params)
  209. end
  210. # GET /api/users/search
  211. def search
  212. # get params
  213. query = params[:term]
  214. limit = params[:limit] || 18
  215. # do query
  216. user_all = User.find(
  217. :all,
  218. :limit => limit,
  219. :conditions => ['firstname LIKE ? or lastname LIKE ? or email LIKE ?', "%#{query}%", "%#{query}%", "%#{query}%"],
  220. :order => 'firstname'
  221. )
  222. # build result list
  223. users = []
  224. user_all.each do |user|
  225. realname = user.firstname.to_s + ' ' + user.lastname.to_s
  226. if user.email && user.email.to_s != ''
  227. realname = realname + ' <' + user.email.to_s + '>'
  228. end
  229. a = { :id => user.id, :label => realname, :value => realname }
  230. users.push a
  231. end
  232. # return result
  233. render :json => users
  234. end
  235. =begin
  236. Resource:
  237. POST /api/users/password_reset
  238. Payload:
  239. {
  240. "username": "some user name"
  241. }
  242. Response:
  243. {
  244. :message => 'ok'
  245. }
  246. Test:
  247. curl http://localhost/api/users/password_reset.json -v -u #{login}:#{password} -H "Content-Type: application/json" -X POST -d '{"username": "some_username"}'
  248. =end
  249. def password_reset_send
  250. success = User.password_reset_send( params[:username] )
  251. if success
  252. render :json => { :message => 'ok' }, :status => :ok
  253. else
  254. render :json => { :message => 'failed' }, :status => :unprocessable_entity
  255. end
  256. end
  257. =begin
  258. Resource:
  259. POST /api/users/password_reset_verify
  260. Payload:
  261. {
  262. "token": "SoMeToKeN",
  263. "password" "new_password"
  264. }
  265. Response:
  266. {
  267. :message => 'ok'
  268. }
  269. Test:
  270. curl http://localhost/api/users/password_reset_verify.json -v -u #{login}:#{password} -H "Content-Type: application/json" -X POST -d '{"token": "SoMeToKeN", "password" "new_password"}'
  271. =end
  272. def password_reset_verify
  273. if params[:password]
  274. success = User.password_reset_via_token( params[:token], params[:password] )
  275. else
  276. success = User.password_reset_check( params[:token] )
  277. end
  278. if success
  279. render :json => { :message => 'ok' }, :status => :ok
  280. else
  281. render :json => { :message => 'failed' }, :status => :unprocessable_entity
  282. end
  283. end
  284. end