mirror of
https://github.com/Floriansylvain/RenewCMS.git
synced 2026-08-19 11:43:22 +02:00
Added auth check on all routes
This commit is contained in:
+3
-3
@@ -20,9 +20,9 @@ func initGin() {
|
|||||||
|
|
||||||
r.GET("/ping", internal.Ping)
|
r.GET("/ping", internal.Ping)
|
||||||
|
|
||||||
r.GET("/get-all-articles", internal.GetAllArticles)
|
r.GET("/get-all-articles", internal.AuthCheck, internal.GetAllArticles)
|
||||||
r.POST("/add-article", internal.AddArticle)
|
r.POST("/add-article", internal.AuthCheck, internal.AddArticle)
|
||||||
r.DELETE("/delete-article", internal.DeleteArticle)
|
r.DELETE("/delete-article", internal.AuthCheck, internal.DeleteArticle)
|
||||||
|
|
||||||
r.POST("/login", internal.LoginUser)
|
r.POST("/login", internal.LoginUser)
|
||||||
r.POST("/logout", internal.LogoutUser)
|
r.POST("/logout", internal.LogoutUser)
|
||||||
|
|||||||
@@ -78,3 +78,23 @@ func LogoutUser(c *gin.Context) {
|
|||||||
removeSession(user)
|
removeSession(user)
|
||||||
SendOkMessageToClient(c, "User successfully logged out.")
|
SendOkMessageToClient(c, "User successfully logged out.")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func AuthCheck(c *gin.Context) {
|
||||||
|
var user User
|
||||||
|
username, password, isOk := c.Request.BasicAuth()
|
||||||
|
if !isOk {
|
||||||
|
SendErrorMessageToClient(c, "Incorrect or missing user credentials.")
|
||||||
|
c.Abort()
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
user.Email = username
|
||||||
|
user.Password = password
|
||||||
|
user.Password = getUserHashedPassword(user)
|
||||||
|
|
||||||
|
if !isUserLoggedIn(user) {
|
||||||
|
SendErrorMessageToClient(c, "Authentification failed, credentials could be wrong, user may not be logged in, session may have expired.")
|
||||||
|
c.Abort()
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ onMounted(async function() {
|
|||||||
function addArticle() {
|
function addArticle() {
|
||||||
fetch("http://localhost:8080/add-article", {
|
fetch("http://localhost:8080/add-article", {
|
||||||
method: "POST",
|
method: "POST",
|
||||||
|
headers: {"Authorization" : `Basic ${btoa(`${username.value}:${password.value}`)}`},
|
||||||
body: JSON.stringify({
|
body: JSON.stringify({
|
||||||
id_name: `${Math.random() * 100}`,
|
id_name: `${Math.random() * 100}`,
|
||||||
content: {},
|
content: {},
|
||||||
@@ -27,7 +28,7 @@ function addArticle() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function logArticles() {
|
function logArticles() {
|
||||||
fetch("http://localhost:8080/get-all-articles")
|
fetch("http://localhost:8080/get-all-articles", {headers: {"Authorization" : `Basic ${btoa(`${username.value}:${password.value}`)}`}})
|
||||||
.then(response => response.json())
|
.then(response => response.json())
|
||||||
.then(result => console.log(result))
|
.then(result => console.log(result))
|
||||||
}
|
}
|
||||||
@@ -35,6 +36,7 @@ function logArticles() {
|
|||||||
function deleteArticle(articleID: String) {
|
function deleteArticle(articleID: String) {
|
||||||
fetch("http://localhost:8080/delete-article", {
|
fetch("http://localhost:8080/delete-article", {
|
||||||
method: "DELETE",
|
method: "DELETE",
|
||||||
|
headers: {"Authorization" : `Basic ${btoa(`${username.value}:${password.value}`)}`},
|
||||||
body: JSON.stringify({
|
body: JSON.stringify({
|
||||||
id_name: articleID
|
id_name: articleID
|
||||||
})
|
})
|
||||||
|
|||||||
Reference in New Issue
Block a user