Fork 0

334 Zeilen
10 KiB

2018-02-15 00:53:11 +01:00
use chrono::{NaiveDateTime, Utc};
use serde_json::Value;
2018-02-10 01:00:55 +01:00
2018-12-07 02:05:45 +01:00
use crate::crypto;
use crate::CONFIG;
2018-02-10 01:00:55 +01:00
db_object! {
#[derive(Debug, Identifiable, Queryable, Insertable, AsChangeset)]
#[table_name = "users"]
pub struct User {
pub uuid: String,
pub created_at: NaiveDateTime,
pub updated_at: NaiveDateTime,
pub verified_at: Option<NaiveDateTime>,
pub last_verifying_at: Option<NaiveDateTime>,
pub login_verify_count: i32,
pub email: String,
pub email_new: Option<String>,
pub email_new_token: Option<String>,
pub name: String,
pub password_hash: Vec<u8>,
pub salt: Vec<u8>,
pub password_iterations: i32,
pub password_hint: Option<String>,
pub akey: String,
pub private_key: Option<String>,
pub public_key: Option<String>,
#[column_name = "totp_secret"] // Note, this is only added to the UserDb structs, not to User
_totp_secret: Option<String>,
pub totp_recover: Option<String>,
pub security_stamp: String,
pub equivalent_domains: String,
pub excluded_globals: String,
pub client_kdf_type: i32,
pub client_kdf_iter: i32,
#[derive(Debug, Identifiable, Queryable, Insertable)]
#[table_name = "invitations"]
pub struct Invitation {
pub email: String,
2018-02-10 01:00:55 +01:00
enum UserStatus {
Enabled = 0,
Invited = 1,
_Disabled = 2,
2018-02-10 01:00:55 +01:00
/// Local methods
impl User {
pub const CLIENT_KDF_TYPE_DEFAULT: i32 = 0; // PBKDF2: 0
pub const CLIENT_KDF_ITER_DEFAULT: i32 = 100_000;
pub fn new(mail: String) -> Self {
2018-02-10 01:00:55 +01:00
let now = Utc::now().naive_utc();
let email = mail.to_lowercase();
Self {
uuid: crate::util::get_uuid(),
2018-02-10 01:00:55 +01:00
created_at: now,
updated_at: now,
verified_at: None,
last_verifying_at: None,
login_verify_count: 0,
2018-02-10 01:00:55 +01:00
name: email.clone(),
2019-05-20 21:12:41 +02:00
akey: String::new(),
email_new: None,
email_new_token: None,
2018-02-10 01:00:55 +01:00
password_hash: Vec::new(),
salt: crypto::get_random_64(),
password_iterations: CONFIG.password_iterations(),
2018-02-10 01:00:55 +01:00
security_stamp: crate::util::get_uuid(),
2018-02-10 01:00:55 +01:00
password_hint: None,
private_key: None,
public_key: None,
_totp_secret: None,
2018-02-10 01:00:55 +01:00
totp_recover: None,
equivalent_domains: "[]".to_string(),
excluded_globals: "[]".to_string(),
client_kdf_type: Self::CLIENT_KDF_TYPE_DEFAULT,
client_kdf_iter: Self::CLIENT_KDF_ITER_DEFAULT,
2018-02-10 01:00:55 +01:00
pub fn check_valid_password(&self, password: &str) -> bool {
self.password_iterations as u32,
2018-02-10 01:00:55 +01:00
pub fn check_valid_recovery_code(&self, recovery_code: &str) -> bool {
if let Some(ref totp_recover) = self.totp_recover {
crate::crypto::ct_eq(recovery_code, totp_recover.to_lowercase())
} else {
2018-02-10 01:00:55 +01:00
pub fn set_password(&mut self, password: &str) {
self.password_hash = crypto::hash_password(password.as_bytes(), &self.salt, self.password_iterations as u32);
2018-02-10 01:00:55 +01:00
pub fn reset_security_stamp(&mut self) {
self.security_stamp = crate::util::get_uuid();
2018-02-10 01:00:55 +01:00
use super::{Cipher, Device, Folder, TwoFactor, UserOrgType, UserOrganization};
use crate::db::DbConn;
use crate::api::EmptyResult;
use crate::error::MapResult;
/// Database methods
impl User {
pub fn to_json(&self, conn: &DbConn) -> Value {
let orgs = UserOrganization::find_by_user(&self.uuid, conn);
let orgs_json: Vec<Value> = orgs.iter().map(|c| c.to_json(&conn)).collect();
2018-09-13 21:55:23 +02:00
let twofactor_enabled = !TwoFactor::find_by_user(&self.uuid, conn).is_empty();
// TODO: Might want to save the status field in the DB
let status = if self.password_hash.is_empty() {
} else {
2018-02-10 01:00:55 +01:00
"_Status": status as i32,
2018-02-10 01:00:55 +01:00
"Id": self.uuid,
"Name": self.name,
"Email": self.email,
"EmailVerified": !CONFIG.mail_enabled() || self.verified_at.is_some(),
2018-02-10 01:00:55 +01:00
"Premium": true,
"MasterPasswordHint": self.password_hint,
"Culture": "en-US",
"TwoFactorEnabled": twofactor_enabled,
2019-05-20 21:12:41 +02:00
"Key": self.akey,
2018-02-10 01:00:55 +01:00
"PrivateKey": self.private_key,
"SecurityStamp": self.security_stamp,
"Organizations": orgs_json,
2018-02-10 01:00:55 +01:00
"Object": "profile"
pub fn save(&mut self, conn: &DbConn) -> EmptyResult {
if self.email.trim().is_empty() {
err!("User email can't be empty")
self.updated_at = Utc::now().naive_utc();
db_run! {conn:
sqlite, mysql {
diesel::replace_into(users::table) // Insert or update
.map_res("Error saving user")
postgresql {
let value = UserDb::to_db(self);
diesel::insert_into(users::table) // Insert or update
.map_res("Error saving user")
2019-01-22 17:26:17 +01:00
2018-02-10 01:00:55 +01:00
pub fn delete(self, conn: &DbConn) -> EmptyResult {
for user_org in UserOrganization::find_by_user(&self.uuid, conn) {
if user_org.atype == UserOrgType::Owner {
let owner_type = UserOrgType::Owner as i32;
if UserOrganization::find_by_org_and_type(&user_org.org_uuid, owner_type, conn).len() <= 1 {
err!("Can't delete last owner")
2018-10-12 16:20:10 +02:00
2018-10-12 16:20:10 +02:00
UserOrganization::delete_all_by_user(&self.uuid, conn)?;
Cipher::delete_all_by_user(&self.uuid, conn)?;
Folder::delete_all_by_user(&self.uuid, conn)?;
Device::delete_all_by_user(&self.uuid, conn)?;
TwoFactor::delete_all_by_user(&self.uuid, conn)?;
Invitation::take(&self.email, conn); // Delete invitation if any
db_run! {conn: {
.map_res("Error deleting user")
pub fn update_uuid_revision(uuid: &str, conn: &DbConn) {
if let Err(e) = Self::_update_revision(uuid, &Utc::now().naive_utc(), conn) {
warn!("Failed to update revision for {}: {:#?}", uuid, e);
pub fn update_all_revisions(conn: &DbConn) -> EmptyResult {
let updated_at = Utc::now().naive_utc();
db_run! {conn: {
crate::util::retry(|| {
}, 10)
.map_res("Error updating revision date for all users")
pub fn update_revision(&mut self, conn: &DbConn) -> EmptyResult {
self.updated_at = Utc::now().naive_utc();
Self::_update_revision(&self.uuid, &self.updated_at, conn)
fn _update_revision(uuid: &str, date: &NaiveDateTime, conn: &DbConn) -> EmptyResult {
db_run! {conn: {
crate::util::retry(|| {
}, 10)
.map_res("Error updating user revision")
2018-08-13 11:58:39 +02:00
pub fn find_by_mail(mail: &str, conn: &DbConn) -> Option<Self> {
2018-02-10 01:00:55 +01:00
let lower_mail = mail.to_lowercase();
db_run! {conn: {
2018-02-10 01:00:55 +01:00
pub fn find_by_uuid(uuid: &str, conn: &DbConn) -> Option<Self> {
db_run! {conn: {
2018-02-10 01:00:55 +01:00
2018-10-12 16:20:10 +02:00
pub fn get_all(conn: &DbConn) -> Vec<Self> {
db_run! {conn: {
users::table.load::<UserDb>(conn).expect("Error loading users").from_db()
2018-10-12 16:20:10 +02:00
2018-02-10 01:00:55 +01:00
impl Invitation {
pub const fn new(email: String) -> Self {
Self { email }
pub fn save(&self, conn: &DbConn) -> EmptyResult {
if self.email.trim().is_empty() {
err!("Invitation email can't be empty")
db_run! {conn:
sqlite, mysql {
.map_res("Error saving invitation")
postgresql {
.map_res("Error saving invitation")
2019-01-22 17:26:17 +01:00
pub fn delete(self, conn: &DbConn) -> EmptyResult {
db_run! {conn: {
.map_res("Error deleting invitation")
pub fn find_by_mail(mail: &str, conn: &DbConn) -> Option<Self> {
let lower_mail = mail.to_lowercase();
db_run! {conn: {
pub fn take(mail: &str, conn: &DbConn) -> bool {
match Self::find_by_mail(mail, &conn) {
Some(invitation) => invitation.delete(&conn).is_ok(),
None => false,