Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
C
canifa_note
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Vũ Hoàng Anh
canifa_note
Commits
c2670748
Commit
c2670748
authored
Dec 23, 2023
by
Steven
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
chore: prevent archive/delete current user
parent
21874d05
Changes
1
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
6 additions
and
0 deletions
+6
-0
user.go
api/v1/user.go
+6
-0
No files found.
api/v1/user.go
View file @
c2670748
...
@@ -312,6 +312,9 @@ func (s *APIV1Service) DeleteUser(c echo.Context) error {
...
@@ -312,6 +312,9 @@ func (s *APIV1Service) DeleteUser(c echo.Context) error {
if
err
!=
nil
{
if
err
!=
nil
{
return
echo
.
NewHTTPError
(
http
.
StatusBadRequest
,
fmt
.
Sprintf
(
"ID is not a number: %s"
,
c
.
Param
(
"id"
)))
.
SetInternal
(
err
)
return
echo
.
NewHTTPError
(
http
.
StatusBadRequest
,
fmt
.
Sprintf
(
"ID is not a number: %s"
,
c
.
Param
(
"id"
)))
.
SetInternal
(
err
)
}
}
if
currentUserID
==
userID
{
return
echo
.
NewHTTPError
(
http
.
StatusBadRequest
,
"Cannot delete current user"
)
}
if
err
:=
s
.
Store
.
DeleteUser
(
ctx
,
&
store
.
DeleteUser
{
if
err
:=
s
.
Store
.
DeleteUser
(
ctx
,
&
store
.
DeleteUser
{
ID
:
userID
,
ID
:
userID
,
...
@@ -371,6 +374,9 @@ func (s *APIV1Service) UpdateUser(c echo.Context) error {
...
@@ -371,6 +374,9 @@ func (s *APIV1Service) UpdateUser(c echo.Context) error {
if
request
.
RowStatus
!=
nil
{
if
request
.
RowStatus
!=
nil
{
rowStatus
:=
store
.
RowStatus
(
request
.
RowStatus
.
String
())
rowStatus
:=
store
.
RowStatus
(
request
.
RowStatus
.
String
())
userUpdate
.
RowStatus
=
&
rowStatus
userUpdate
.
RowStatus
=
&
rowStatus
if
rowStatus
==
store
.
Archived
&&
currentUserID
==
userID
{
return
echo
.
NewHTTPError
(
http
.
StatusBadRequest
,
"Cannot archive current user"
)
}
}
}
if
request
.
Username
!=
nil
{
if
request
.
Username
!=
nil
{
if
!
usernameMatcher
.
MatchString
(
strings
.
ToLower
(
*
request
.
Username
))
{
if
!
usernameMatcher
.
MatchString
(
strings
.
ToLower
(
*
request
.
Username
))
{
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment