feat: env variables introduction

This commit is contained in:
Florian Sylvain
2023-08-11 04:02:18 +02:00
parent 4b918aa2fa
commit d953a66f22
7 changed files with 44 additions and 20 deletions
+6 -4
View File
@@ -7,6 +7,7 @@ import (
"github.com/go-chi/jwtauth/v5"
"golang.org/x/crypto/bcrypt"
"net/http"
"os"
"time"
)
@@ -21,6 +22,7 @@ type UserLogin struct {
Password string `json:"password" validate:"required,min=8"`
}
var shouldCookieBeSecure = os.Getenv("ENVIRONMENT") == "production"
var TokenAuth *jwtauth.JWTAuth
// TODO Move into its own file or package that handles api errors
@@ -36,14 +38,14 @@ func SetJwtCookie(w *http.ResponseWriter, userId uint32) error {
Name: "jwt",
Value: tokenString,
Expires: time.Now().Add(24 * time.Hour),
Secure: false, // TODO false in dev, true in prod
Secure: shouldCookieBeSecure,
HttpOnly: true,
Path: "/",
})
return nil
}
func isAllowedToCreateUser() bool {
func isUserTableEmpty() bool {
users := container.ListUsersUseCase.ListUsers()
return len(users) == 0
}
@@ -92,7 +94,7 @@ func login(w http.ResponseWriter, r *http.Request) {
}
func register(w http.ResponseWriter, r *http.Request) {
if !IsLoggedIn(r) && !isAllowedToCreateUser() {
if !IsLoggedIn(r) && !isUserTableEmpty() {
http.Error(w, "You are not allowed to create a user. Log in or reset database.", http.StatusForbidden)
return
}
@@ -132,7 +134,7 @@ func removeJwtCookie(w http.ResponseWriter) {
Value: "",
Expires: time.Now(),
MaxAge: -1,
Secure: false, // TODO false in dev, true in prod
Secure: shouldCookieBeSecure,
HttpOnly: true,
Path: "/",
})
+6 -3
View File
@@ -6,6 +6,7 @@ import (
"github.com/go-chi/chi/v5"
"html/template"
"net/http"
"os"
"path/filepath"
"strings"
)
@@ -78,9 +79,11 @@ func postLoginPage(w http.ResponseWriter, r *http.Request) {
return
}
// TODO replace url with som env variable
response, err := http.Post("http://localhost:8080/v1/auth/login", "application/json", bytes.NewBuffer(credentials))
// TODO handle possible errors in separate file (api package)
response, err := http.Post(
"http://localhost:"+os.Getenv("PORT")+"/v1/auth/login",
"application/json",
bytes.NewBuffer(credentials))
if err != nil || response.StatusCode != http.StatusOK {
r.Method = http.MethodGet
getLoginPageHandler(NewLoginPage("Invalid username or password.", r.FormValue("username")))(w, r)