DocSpace-buildtools/products/ASC.People/Server/Controllers/PeopleController.cs

1517 lines
61 KiB
C#
Raw Normal View History

2019-09-09 12:56:33 +00:00

using System;
2019-05-27 09:46:04 +00:00
using System.Collections.Generic;
using System.Drawing;
using System.Drawing.Imaging;
using System.IO;
2019-05-27 09:46:04 +00:00
using System.Linq;
using System.Net;
using System.Net.Mail;
2019-06-17 11:57:07 +00:00
using System.Security;
2019-06-14 08:15:28 +00:00
using ASC.Api.Core;
2019-10-10 08:52:21 +00:00
using ASC.Common.Data;
2019-10-17 15:55:35 +00:00
using ASC.Common.Logging;
2019-10-09 15:04:46 +00:00
using ASC.Common.Utils;
2019-06-13 15:01:29 +00:00
using ASC.Common.Web;
2019-05-27 09:46:04 +00:00
using ASC.Core;
2019-10-31 13:54:43 +00:00
using ASC.Core.Common.Settings;
2019-11-25 09:49:12 +00:00
using ASC.Core.Data;
using ASC.Core.Tenants;
2019-05-27 09:46:04 +00:00
using ASC.Core.Users;
2019-06-21 10:42:16 +00:00
using ASC.Data.Reassigns;
2019-06-17 11:57:07 +00:00
using ASC.FederatedLogin;
using ASC.FederatedLogin.Profile;
using ASC.MessagingSystem;
using ASC.People;
using ASC.People.Models;
2019-08-13 13:05:36 +00:00
using ASC.People.Resources;
2019-10-09 15:04:46 +00:00
using ASC.Security.Cryptography;
using ASC.Web.Api.Models;
2019-05-27 12:49:48 +00:00
using ASC.Web.Api.Routing;
2019-06-14 08:15:28 +00:00
using ASC.Web.Core;
2019-06-17 11:57:07 +00:00
using ASC.Web.Core.PublicResources;
2019-06-14 08:15:28 +00:00
using ASC.Web.Core.Users;
using ASC.Web.Studio.Core;
2019-06-17 11:57:07 +00:00
using ASC.Web.Studio.Core.Notify;
using ASC.Web.Studio.UserControls.Statistics;
using ASC.Web.Studio.Utility;
2019-07-19 08:38:31 +00:00
2019-06-17 11:57:07 +00:00
using Microsoft.AspNetCore.Authorization;
2019-07-02 15:30:31 +00:00
using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Http.Extensions;
using Microsoft.AspNetCore.Mvc;
2019-10-31 11:28:30 +00:00
using Microsoft.Extensions.DependencyInjection;
2019-10-17 15:55:35 +00:00
using Microsoft.Extensions.Options;
2019-06-17 11:57:07 +00:00
using SecurityContext = ASC.Core.SecurityContext;
namespace ASC.Employee.Core.Controllers
{
2019-05-27 12:49:48 +00:00
[DefaultRoute]
[ApiController]
public class PeopleController : ControllerBase
{
2019-08-09 12:28:19 +00:00
public Tenant Tenant { get { return ApiContext.Tenant; } }
2019-07-29 10:51:14 +00:00
public ApiContext ApiContext { get; }
2019-06-17 13:53:10 +00:00
public MessageService MessageService { get; }
2019-06-21 12:42:27 +00:00
public QueueWorkerReassign QueueWorkerReassign { get; }
public QueueWorkerRemove QueueWorkerRemove { get; }
2019-08-01 08:47:15 +00:00
public StudioNotifyService StudioNotifyService { get; }
public UserManagerWrapper UserManagerWrapper { get; }
2019-09-09 12:56:33 +00:00
public UserManager UserManager { get; }
public TenantExtra TenantExtra { get; }
public TenantStatisticsProvider TenantStatisticsProvider { get; }
public UserPhotoManager UserPhotoManager { get; }
public SecurityContext SecurityContext { get; }
public CookiesManager CookiesManager { get; }
public WebItemSecurity WebItemSecurity { get; }
public PermissionContext PermissionContext { get; }
public AuthContext AuthContext { get; }
public WebItemManager WebItemManager { get; }
public CustomNamingPeople CustomNamingPeople { get; }
2019-09-17 12:42:32 +00:00
public TenantUtil TenantUtil { get; }
2019-09-18 15:19:30 +00:00
public CoreBaseSettings CoreBaseSettings { get; }
2019-09-23 12:20:08 +00:00
public SetupInfo SetupInfo { get; }
public FileSizeComment FileSizeComment { get; }
public DisplayUserSettingsHelper DisplayUserSettingsHelper { get; }
2019-10-09 15:04:46 +00:00
public Signature Signature { get; }
public InstanceCrypto InstanceCrypto { get; }
2019-10-11 15:03:03 +00:00
public WebItemSecurityCache WebItemSecurityCache { get; }
2019-10-22 11:21:44 +00:00
public MessageTarget MessageTarget { get; }
public SettingsManager SettingsManager { get; }
2019-12-04 10:39:18 +00:00
public IOptionsSnapshot<AccountLinker> AccountLinker { get; }
public EmployeeWraperFullHelper EmployeeWraperFullHelper { get; }
public EmployeeWraperHelper EmployeeWraperHelper { get; }
2019-11-25 09:49:12 +00:00
public EFUserService EFUserService { get; }
2019-10-17 15:55:35 +00:00
public ILog Log { get; }
2019-08-01 08:47:15 +00:00
2019-10-17 15:55:35 +00:00
public PeopleController(
2019-08-01 08:47:15 +00:00
MessageService messageService,
QueueWorkerReassign queueWorkerReassign,
QueueWorkerRemove queueWorkerRemove,
StudioNotifyService studioNotifyService,
UserManagerWrapper userManagerWrapper,
2019-09-09 12:56:33 +00:00
ApiContext apiContext,
UserManager userManager,
TenantExtra tenantExtra,
TenantStatisticsProvider tenantStatisticsProvider,
UserPhotoManager userPhotoManager,
SecurityContext securityContext,
CookiesManager cookiesManager,
WebItemSecurity webItemSecurity,
PermissionContext permissionContext,
AuthContext authContext,
2019-09-13 11:18:27 +00:00
WebItemManager webItemManager,
2019-09-17 12:42:32 +00:00
CustomNamingPeople customNamingPeople,
2019-09-17 15:38:06 +00:00
TenantUtil tenantUtil,
2019-10-09 15:04:46 +00:00
CoreBaseSettings coreBaseSettings,
2019-09-23 12:20:08 +00:00
SetupInfo setupInfo,
2019-09-24 10:32:12 +00:00
FileSizeComment fileSizeComment,
DisplayUserSettingsHelper displayUserSettingsHelper,
2019-10-09 15:04:46 +00:00
Signature signature,
2019-10-10 08:52:21 +00:00
InstanceCrypto instanceCrypto,
2019-10-17 15:55:35 +00:00
WebItemSecurityCache webItemSecurityCache,
2019-10-22 11:21:44 +00:00
MessageTarget messageTarget,
SettingsManager settingsManager,
IOptionsMonitor<ILog> option,
2019-12-04 10:39:18 +00:00
IOptionsSnapshot<AccountLinker> accountLinker,
EmployeeWraperFullHelper employeeWraperFullHelper,
2019-11-15 15:04:05 +00:00
EmployeeWraperHelper employeeWraperHelper,
2019-11-25 09:49:12 +00:00
EFUserService eFUserService)
2019-06-13 15:01:29 +00:00
{
2019-10-17 15:55:35 +00:00
Log = option.Get("ASC.Api");
2019-06-17 13:53:10 +00:00
MessageService = messageService;
2019-06-21 12:42:27 +00:00
QueueWorkerReassign = queueWorkerReassign;
QueueWorkerRemove = queueWorkerRemove;
2019-08-01 08:47:15 +00:00
StudioNotifyService = studioNotifyService;
UserManagerWrapper = userManagerWrapper;
2019-07-29 10:51:14 +00:00
ApiContext = apiContext;
2019-09-09 12:56:33 +00:00
UserManager = userManager;
TenantExtra = tenantExtra;
TenantStatisticsProvider = tenantStatisticsProvider;
UserPhotoManager = userPhotoManager;
SecurityContext = securityContext;
CookiesManager = cookiesManager;
WebItemSecurity = webItemSecurity;
PermissionContext = permissionContext;
AuthContext = authContext;
WebItemManager = webItemManager;
CustomNamingPeople = customNamingPeople;
2019-09-17 12:42:32 +00:00
TenantUtil = tenantUtil;
2019-09-18 15:19:30 +00:00
CoreBaseSettings = coreBaseSettings;
2019-09-23 12:20:08 +00:00
SetupInfo = setupInfo;
FileSizeComment = fileSizeComment;
DisplayUserSettingsHelper = displayUserSettingsHelper;
2019-10-09 15:04:46 +00:00
Signature = signature;
InstanceCrypto = instanceCrypto;
2019-10-11 15:03:03 +00:00
WebItemSecurityCache = webItemSecurityCache;
2019-10-22 11:21:44 +00:00
MessageTarget = messageTarget;
SettingsManager = settingsManager;
2019-12-04 10:39:18 +00:00
AccountLinker = accountLinker;
EmployeeWraperFullHelper = employeeWraperFullHelper;
EmployeeWraperHelper = employeeWraperHelper;
2019-11-25 09:49:12 +00:00
EFUserService = eFUserService;
2019-06-13 15:01:29 +00:00
}
[Read("info")]
public Module GetModule()
{
var product = new PeopleProduct();
product.Init();
return new Module(product, true);
}
2019-06-25 10:46:10 +00:00
[Read]
public IQueryable<EmployeeWraper> GetAll()
2019-05-27 09:46:04 +00:00
{
return GetByStatus(EmployeeStatus.Active);
}
2019-06-14 08:15:28 +00:00
[Read("status/{status}")]
public IQueryable<EmployeeWraper> GetByStatus(EmployeeStatus status)
2019-05-27 09:46:04 +00:00
{
2019-09-18 15:19:30 +00:00
if (CoreBaseSettings.Personal) throw new Exception("Method not available");
Guid? groupId = null;
if ("group".Equals(ApiContext.FilterBy, StringComparison.OrdinalIgnoreCase) && !string.IsNullOrEmpty(ApiContext.FilterValue))
{
groupId = new Guid(ApiContext.FilterValue);
ApiContext.SetDataFiltered();
}
return GetFullByFilter(status, groupId, null, null, null);
2019-05-27 09:46:04 +00:00
}
2019-05-27 12:49:48 +00:00
2019-06-25 10:46:10 +00:00
[Read("@self")]
2019-05-27 12:49:48 +00:00
public EmployeeWraper Self()
{
return EmployeeWraperFullHelper.GetFull(UserManager.GetUsers(SecurityContext.CurrentAccount.ID));
2019-05-27 12:49:48 +00:00
}
2019-06-13 15:01:29 +00:00
2019-06-25 10:46:10 +00:00
[Read("email")]
2019-06-14 08:15:28 +00:00
public EmployeeWraperFull GetByEmail([FromQuery]string email)
{
2019-09-18 15:19:30 +00:00
if (CoreBaseSettings.Personal && !UserManager.GetUsers(SecurityContext.CurrentAccount.ID).IsOwner(Tenant))
2019-06-14 08:15:28 +00:00
throw new MethodAccessException("Method not available");
var user = UserManager.GetUserByEmail(email);
2019-06-14 08:15:28 +00:00
if (user.ID == Constants.LostUser.ID)
{
throw new ItemNotFoundException("User not found");
}
return EmployeeWraperFullHelper.GetFull(user);
2019-06-14 08:15:28 +00:00
}
2019-06-25 10:46:10 +00:00
[Read("{username}", order: int.MaxValue)]
2019-06-13 15:01:29 +00:00
public EmployeeWraperFull GetById(string username)
{
2019-09-18 15:19:30 +00:00
if (CoreBaseSettings.Personal) throw new MethodAccessException("Method not available");
var user = UserManager.GetUserByUserName(username);
2019-06-13 15:01:29 +00:00
if (user.ID == Constants.LostUser.ID)
{
2019-06-14 08:15:28 +00:00
if (Guid.TryParse(username, out var userId))
2019-06-13 15:01:29 +00:00
{
user = UserManager.GetUsers(userId);
2019-06-13 15:01:29 +00:00
}
else
{
2019-10-17 15:55:35 +00:00
Log.Error(string.Format("Account {0} сould not get user by name {1}", SecurityContext.CurrentAccount.ID, username));
2019-06-13 15:01:29 +00:00
}
}
if (user.ID == Constants.LostUser.ID)
{
throw new ItemNotFoundException("User not found");
}
return EmployeeWraperFullHelper.GetFull(user);
2019-06-13 15:01:29 +00:00
}
2019-06-14 08:15:28 +00:00
[Read("@search/{query}")]
public IEnumerable<EmployeeWraperFull> GetSearch(string query)
{
2019-09-18 15:19:30 +00:00
if (CoreBaseSettings.Personal) throw new MethodAccessException("Method not available");
2019-06-14 08:15:28 +00:00
try
{
var groupId = Guid.Empty;
if ("group".Equals(ApiContext.FilterBy, StringComparison.OrdinalIgnoreCase) && !string.IsNullOrEmpty(ApiContext.FilterValue))
{
groupId = new Guid(ApiContext.FilterValue);
}
return UserManager.Search(query, EmployeeStatus.Active, groupId).Select(EmployeeWraperFullHelper.GetFull);
2019-06-14 08:15:28 +00:00
}
catch (Exception error)
{
2019-10-17 15:55:35 +00:00
Log.Error(error);
2019-06-14 08:15:28 +00:00
}
return null;
}
2019-06-25 10:46:10 +00:00
[Read("search")]
2019-06-14 08:15:28 +00:00
public IEnumerable<EmployeeWraperFull> GetPeopleSearch([FromQuery]string query)
{
return GetSearch(query);
}
2019-06-25 10:46:10 +00:00
[Read("status/{status}/search")]
2019-06-14 08:15:28 +00:00
public IEnumerable<EmployeeWraperFull> GetAdvanced(EmployeeStatus status, [FromQuery]string query)
{
2019-09-18 15:19:30 +00:00
if (CoreBaseSettings.Personal) throw new MethodAccessException("Method not available");
2019-06-14 08:15:28 +00:00
try
{
var list = UserManager.GetUsers(status).AsEnumerable();
2019-06-14 08:15:28 +00:00
if ("group".Equals(ApiContext.FilterBy, StringComparison.OrdinalIgnoreCase) && !string.IsNullOrEmpty(ApiContext.FilterValue))
{
var groupId = new Guid(ApiContext.FilterValue);
//Filter by group
list = list.Where(x => UserManager.IsUserInGroup(x.ID, groupId));
2019-06-14 08:15:28 +00:00
ApiContext.SetDataFiltered();
}
list = list.Where(x => x.FirstName != null && x.FirstName.IndexOf(query, StringComparison.OrdinalIgnoreCase) > -1 || (x.LastName != null && x.LastName.IndexOf(query, StringComparison.OrdinalIgnoreCase) != -1) ||
2019-11-25 09:49:12 +00:00
(x.UserName != null && x.UserName.IndexOf(query, StringComparison.OrdinalIgnoreCase) != -1) || (x.Email != null && x.Email.IndexOf(query, StringComparison.OrdinalIgnoreCase) != -1) || (x.ContactsList != null && x.ContactsList.Any(y => y.IndexOf(query, StringComparison.OrdinalIgnoreCase) != -1)));
2019-06-14 08:15:28 +00:00
return list.Select(EmployeeWraperFullHelper.GetFull);
2019-06-14 08:15:28 +00:00
}
catch (Exception error)
{
2019-10-17 15:55:35 +00:00
Log.Error(error);
2019-06-14 08:15:28 +00:00
}
return null;
}
///// <summary>
///// Adds a new portal user from import with the first and last name, email address
///// </summary>
///// <short>
///// Add new import user
///// </short>
///// <param name="userList">The list of users to add</param>
///// <param name="importUsersAsCollaborators" optional="true">Add users as guests (bool type: false|true)</param>
///// <returns>Newly created users</returns>
//[Create("import/save")]
//public void SaveUsers(string userList, bool importUsersAsCollaborators)
//{
// lock (progressQueue.SynchRoot)
// {
// var task = progressQueue.GetItems().OfType<ImportUsersTask>().FirstOrDefault(t => (int)t.Id == TenantProvider.CurrentTenantID);
// if (task != null && task.IsCompleted)
// {
// progressQueue.Remove(task);
// task = null;
// }
// if (task == null)
// {
// progressQueue.Add(new ImportUsersTask(userList, importUsersAsCollaborators, GetHttpHeaders(HttpContext.Current.Request))
// {
// Id = TenantProvider.CurrentTenantID,
// UserId = SecurityContext.CurrentAccount.ID,
// Percentage = 0
// });
// }
// }
//}
//[Read("import/status")]
//public object GetStatus()
//{
// lock (progressQueue.SynchRoot)
// {
// var task = progressQueue.GetItems().OfType<ImportUsersTask>().FirstOrDefault(t => (int)t.Id == TenantProvider.CurrentTenantID);
// if (task == null) return null;
// return new
// {
// Completed = task.IsCompleted,
// Percents = (int)task.Percentage,
// UserCounter = task.GetUserCounter,
// Status = (int)task.Status,
// Error = (string)task.Error,
// task.Data
// };
// }
//}
2019-06-25 10:46:10 +00:00
[Read("filter")]
public IQueryable<EmployeeWraperFull> GetFullByFilter(EmployeeStatus? employeeStatus, Guid? groupId, EmployeeActivationStatus? activationStatus, EmployeeType? employeeType, bool? isAdministrator)
2019-06-14 08:15:28 +00:00
{
var users = GetByFilter(employeeStatus, groupId, activationStatus, employeeType, isAdministrator);
return users.Select(r => EmployeeWraperFullHelper.GetFull(r));
2019-06-14 08:15:28 +00:00
}
2019-06-25 10:46:10 +00:00
[Read("simple/filter")]
2019-06-14 08:15:28 +00:00
public IEnumerable<EmployeeWraper> GetSimpleByFilter(EmployeeStatus? employeeStatus, Guid? groupId, EmployeeActivationStatus? activationStatus, EmployeeType? employeeType, bool? isAdministrator)
{
var users = GetByFilter(employeeStatus, groupId, activationStatus, employeeType, isAdministrator);
return users.Select(EmployeeWraperHelper.Get);
2019-06-14 08:15:28 +00:00
}
2019-11-25 09:49:12 +00:00
private IQueryable<UserInfo> GetByFilter(EmployeeStatus? employeeStatus, Guid? groupId, EmployeeActivationStatus? activationStatus, EmployeeType? employeeType, bool? isAdministrator)
2019-06-14 08:15:28 +00:00
{
2019-09-18 15:19:30 +00:00
if (CoreBaseSettings.Personal) throw new MethodAccessException("Method not available");
var isAdmin = UserManager.GetUsers(SecurityContext.CurrentAccount.ID).IsAdmin(UserManager) ||
WebItemSecurity.IsProductAdministrator(WebItemManager.PeopleProductID, SecurityContext.CurrentAccount.ID);
2019-06-14 08:15:28 +00:00
2019-08-08 14:42:29 +00:00
var includeGroups = new List<List<Guid>>();
if (groupId.HasValue)
2019-06-14 08:15:28 +00:00
{
2019-08-08 14:42:29 +00:00
includeGroups.Add(new List<Guid> { groupId.Value });
2019-06-14 08:15:28 +00:00
}
var excludeGroups = new List<Guid>();
2019-06-14 08:15:28 +00:00
if (employeeType != null)
{
switch (employeeType)
{
case EmployeeType.User:
excludeGroups.Add(Constants.GroupVisitor.ID);
2019-06-14 08:15:28 +00:00
break;
case EmployeeType.Visitor:
2019-08-08 14:42:29 +00:00
includeGroups.Add(new List<Guid> { Constants.GroupVisitor.ID });
2019-06-14 08:15:28 +00:00
break;
}
}
if (isAdministrator.HasValue && isAdministrator.Value)
{
2019-08-08 14:42:29 +00:00
var adminGroups = new List<Guid>
{
Constants.GroupAdmin.ID
};
2019-06-14 08:15:28 +00:00
var products = WebItemManager.GetItemsAll().Where(i => i is IProduct || i.ID == WebItemManager.MailProductID);
2019-08-15 12:04:42 +00:00
adminGroups.AddRange(products.Select(r => r.ID));
2019-06-14 08:15:28 +00:00
2019-08-08 14:42:29 +00:00
includeGroups.Add(adminGroups);
2019-06-14 08:15:28 +00:00
}
2019-11-25 09:49:12 +00:00
var users = UserManager.GetUsers(isAdmin, employeeStatus, includeGroups, excludeGroups, activationStatus, ApiContext.FilterValue, ApiContext.SortBy, !ApiContext.SortDescending, ApiContext.Count, ApiContext.StartIndex, out var total, out var count);
2019-06-14 08:15:28 +00:00
2019-11-25 09:49:12 +00:00
ApiContext.SetTotalCount(total).SetCount(count);
2019-06-14 08:15:28 +00:00
return users;
}
2019-06-25 10:46:10 +00:00
[Create]
2019-09-23 15:36:22 +00:00
[Authorize(AuthenticationSchemes = "confirm", Roles = "LinkInvite,Administrators")]
public EmployeeWraperFull AddMember(MemberModel memberModel)
{
2019-09-16 09:21:10 +00:00
ApiContext.AuthByClaim();
PermissionContext.DemandPermissions(Constants.Action_AddRemoveUser);
if (string.IsNullOrEmpty(memberModel.Password))
memberModel.Password = UserManagerWrapper.GeneratePassword();
memberModel.Password = memberModel.Password.Trim();
var user = new UserInfo();
//Validate email
var address = new MailAddress(memberModel.Email);
user.Email = address.Address;
//Set common fields
user.FirstName = memberModel.Firstname;
user.LastName = memberModel.Lastname;
user.Title = memberModel.Title;
user.Location = memberModel.Location;
user.Notes = memberModel.Comment;
user.Sex = "male".Equals(memberModel.Sex, StringComparison.OrdinalIgnoreCase)
? true
: ("female".Equals(memberModel.Sex, StringComparison.OrdinalIgnoreCase) ? (bool?)false : null);
2019-09-20 11:07:57 +00:00
user.BirthDate = memberModel.Birthday != null && memberModel.Birthday != DateTime.MinValue ? TenantUtil.DateTimeFromUtc(Convert.ToDateTime(memberModel.Birthday)) : (DateTime?)null;
user.WorkFromDate = memberModel.Worksfrom != null && memberModel.Worksfrom != DateTime.MinValue ? TenantUtil.DateTimeFromUtc(Convert.ToDateTime(memberModel.Worksfrom)) : DateTime.UtcNow.Date;
UpdateContacts(memberModel.Contacts, user);
user = UserManagerWrapper.AddUser(user, memberModel.Password, false, true, memberModel.IsVisitor);
var messageAction = memberModel.IsVisitor ? MessageAction.GuestCreated : MessageAction.UserCreated;
MessageService.Send(messageAction, MessageTarget.Create(user.ID), user.DisplayUserName(false, DisplayUserSettingsHelper));
UpdateDepartments(memberModel.Department, user);
if (memberModel.Files != UserPhotoManager.GetDefaultPhotoAbsoluteWebPath())
{
UpdatePhotoUrl(memberModel.Files, user);
}
return EmployeeWraperFullHelper.GetFull(user);
}
2019-06-25 10:46:10 +00:00
[Create("active")]
2019-06-17 11:57:07 +00:00
public EmployeeWraperFull AddMemberAsActivated(MemberModel memberModel)
{
PermissionContext.DemandPermissions(Constants.Action_AddRemoveUser);
2019-06-17 11:57:07 +00:00
var user = new UserInfo();
2019-06-17 11:57:07 +00:00
if (string.IsNullOrEmpty(memberModel.Password))
memberModel.Password = UserManagerWrapper.GeneratePassword();
2019-06-17 11:57:07 +00:00
//Validate email
var address = new MailAddress(memberModel.Email);
user.Email = address.Address;
//Set common fields
user.FirstName = memberModel.Firstname;
user.LastName = memberModel.Lastname;
user.Title = memberModel.Title;
user.Location = memberModel.Location;
user.Notes = memberModel.Comment;
user.Sex = "male".Equals(memberModel.Sex, StringComparison.OrdinalIgnoreCase)
? true
: ("female".Equals(memberModel.Sex, StringComparison.OrdinalIgnoreCase) ? (bool?)false : null);
2019-06-17 11:57:07 +00:00
user.BirthDate = memberModel.Birthday != null ? TenantUtil.DateTimeFromUtc(Convert.ToDateTime(memberModel.Birthday)) : (DateTime?)null;
user.WorkFromDate = memberModel.Worksfrom != null ? TenantUtil.DateTimeFromUtc(Convert.ToDateTime(memberModel.Worksfrom)) : DateTime.UtcNow.Date;
2019-06-17 11:57:07 +00:00
UpdateContacts(memberModel.Contacts, user);
user = UserManagerWrapper.AddUser(user, memberModel.Password, false, false, memberModel.IsVisitor);
2019-06-17 11:57:07 +00:00
user.ActivationStatus = EmployeeActivationStatus.Activated;
2019-06-17 11:57:07 +00:00
UpdateDepartments(memberModel.Department, user);
2019-06-17 11:57:07 +00:00
if (memberModel.Files != UserPhotoManager.GetDefaultPhotoAbsoluteWebPath())
{
2019-06-17 11:57:07 +00:00
UpdatePhotoUrl(memberModel.Files, user);
}
return EmployeeWraperFullHelper.GetFull(user);
}
[Update("{userid}/culture")]
public EmployeeWraperFull UpdateMemberCulture(string userid, UpdateMemberModel memberModel)
{
var user = GetUserInfo(userid);
if (UserManager.IsSystemUser(user.ID))
throw new SecurityException();
PermissionContext.DemandPermissions(new UserSecurityProvider(user.ID), Constants.Action_EditUser);
var curLng = user.CultureName;
if (SetupInfo.EnabledCultures.Find(c => string.Equals(c.Name, memberModel.CultureName, StringComparison.InvariantCultureIgnoreCase)) != null)
{
if (curLng != memberModel.CultureName)
{
user.CultureName = memberModel.CultureName;
try
{
UserManager.SaveUserInfo(user);
}
catch (Exception ex)
{
user.CultureName = curLng;
throw ex;
}
MessageService.Send(MessageAction.UserUpdatedLanguage, MessageTarget.Create(user.ID), user.DisplayUserName(false, DisplayUserSettingsHelper));
}
}
return EmployeeWraperFullHelper.GetFull(user);
}
2019-06-17 11:57:07 +00:00
[Update("{userid}")]
public EmployeeWraperFull UpdateMember(string userid, UpdateMemberModel memberModel)
{
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
PermissionContext.DemandPermissions(new UserSecurityProvider(user.ID), Constants.Action_EditUser);
2019-06-17 11:57:07 +00:00
var self = SecurityContext.CurrentAccount.ID.Equals(user.ID);
var resetDate = new DateTime(1900, 01, 01);
2019-06-17 11:57:07 +00:00
//Update it
2019-06-17 11:57:07 +00:00
var isLdap = user.IsLDAP();
var isSso = user.IsSSO();
var isAdmin = WebItemSecurity.IsProductAdministrator(WebItemManager.PeopleProductID, SecurityContext.CurrentAccount.ID);
2019-06-17 11:57:07 +00:00
if (!isLdap && !isSso)
{
//Set common fields
2019-06-17 11:57:07 +00:00
user.FirstName = memberModel.Firstname ?? user.FirstName;
user.LastName = memberModel.Lastname ?? user.LastName;
user.Location = memberModel.Location ?? user.Location;
2019-06-17 11:57:07 +00:00
if (isAdmin)
{
user.Title = memberModel.Title ?? user.Title;
}
}
2019-06-17 11:57:07 +00:00
if (!UserFormatter.IsValidUserName(user.FirstName, user.LastName))
throw new Exception(Resource.ErrorIncorrectUserName);
2019-06-17 11:57:07 +00:00
user.Notes = memberModel.Comment ?? user.Notes;
user.Sex = ("male".Equals(memberModel.Sex, StringComparison.OrdinalIgnoreCase)
? true
: ("female".Equals(memberModel.Sex, StringComparison.OrdinalIgnoreCase) ? (bool?)false : null)) ?? user.Sex;
2019-06-17 11:57:07 +00:00
user.BirthDate = memberModel.Birthday != null ? TenantUtil.DateTimeFromUtc(Convert.ToDateTime(memberModel.Birthday)) : user.BirthDate;
2019-06-17 11:57:07 +00:00
if (user.BirthDate == resetDate)
{
user.BirthDate = null;
}
2019-06-17 11:57:07 +00:00
user.WorkFromDate = memberModel.Worksfrom != null ? TenantUtil.DateTimeFromUtc(Convert.ToDateTime(memberModel.Worksfrom)) : user.WorkFromDate;
2019-06-17 11:57:07 +00:00
if (user.WorkFromDate == resetDate)
{
user.WorkFromDate = null;
}
2019-06-17 11:57:07 +00:00
//Update contacts
UpdateContacts(memberModel.Contacts, user);
UpdateDepartments(memberModel.Department, user);
if (memberModel.Files != UserPhotoManager.GetPhotoAbsoluteWebPath(user.ID))
2019-06-17 11:57:07 +00:00
{
UpdatePhotoUrl(memberModel.Files, user);
}
if (memberModel.Disable.HasValue)
{
user.Status = memberModel.Disable.Value ? EmployeeStatus.Terminated : EmployeeStatus.Active;
user.TerminatedDate = memberModel.Disable.Value ? DateTime.UtcNow : (DateTime?)null;
}
2019-06-17 11:57:07 +00:00
if (self && !isAdmin)
{
StudioNotifyService.SendMsgToAdminAboutProfileUpdated();
2019-06-17 11:57:07 +00:00
}
2019-06-17 11:57:07 +00:00
// change user type
var canBeGuestFlag = !user.IsOwner(Tenant) && !user.IsAdmin(UserManager) && !user.GetListAdminModules(WebItemSecurity).Any() && !user.IsMe(AuthContext);
if (memberModel.IsVisitor && !user.IsVisitor(UserManager) && canBeGuestFlag)
2019-06-17 11:57:07 +00:00
{
UserManager.AddUserIntoGroup(user.ID, Constants.GroupVisitor.ID);
2019-10-11 15:03:03 +00:00
WebItemSecurityCache.ClearCache(Tenant.TenantId);
2019-06-17 11:57:07 +00:00
}
if (!self && !memberModel.IsVisitor && user.IsVisitor(UserManager))
2019-06-17 11:57:07 +00:00
{
var usersQuota = TenantExtra.GetTenantQuota().ActiveUsers;
if (TenantStatisticsProvider.GetUsersCount() < usersQuota)
2019-06-17 11:57:07 +00:00
{
UserManager.RemoveUserFromGroup(user.ID, Constants.GroupVisitor.ID);
2019-10-11 15:03:03 +00:00
WebItemSecurityCache.ClearCache(Tenant.TenantId);
2019-06-17 11:57:07 +00:00
}
else
{
throw new TenantQuotaException(string.Format("Exceeds the maximum active users ({0})", usersQuota));
}
}
UserManager.SaveUserInfo(user, memberModel.IsVisitor);
MessageService.Send(MessageAction.UserUpdated, MessageTarget.Create(user.ID), user.DisplayUserName(false, DisplayUserSettingsHelper));
2019-06-17 11:57:07 +00:00
if (memberModel.Disable.HasValue && memberModel.Disable.Value)
{
2019-09-20 15:53:27 +00:00
CookiesManager.ResetUserCookie(user.ID);
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.CookieSettingsUpdated);
2019-06-17 11:57:07 +00:00
}
return EmployeeWraperFullHelper.GetFull(user);
2019-06-17 11:57:07 +00:00
}
2019-06-17 11:57:07 +00:00
[Delete("{userid}")]
public EmployeeWraperFull DeleteMember(string userid)
{
PermissionContext.DemandPermissions(Constants.Action_AddRemoveUser);
2019-06-17 11:57:07 +00:00
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID) || user.IsLDAP())
2019-06-17 11:57:07 +00:00
throw new SecurityException();
2019-06-17 11:57:07 +00:00
if (user.Status != EmployeeStatus.Terminated)
throw new Exception("The user is not suspended");
2019-06-21 10:42:16 +00:00
CheckReassignProccess(new[] { user.ID });
var userName = user.DisplayUserName(false, DisplayUserSettingsHelper);
UserPhotoManager.RemovePhoto(user.ID);
UserManager.DeleteUser(user.ID);
2019-08-12 10:53:12 +00:00
QueueWorkerRemove.Start(Tenant.TenantId, user, SecurityContext.CurrentAccount.ID, false);
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.UserDeleted, MessageTarget.Create(user.ID), userName);
return EmployeeWraperFullHelper.GetFull(user);
2019-06-17 11:57:07 +00:00
}
[Delete("@self")]
[Authorize(AuthenticationSchemes = "confirm", Roles = "ProfileRemove")]
public EmployeeWraperFull DeleteProfile()
{
ApiContext.AuthByClaim();
if (UserManager.IsSystemUser(SecurityContext.CurrentAccount.ID))
throw new SecurityException();
var user = GetUserInfo(SecurityContext.CurrentAccount.ID.ToString());
if (!UserManager.UserExists(user))
throw new Exception(Resource.ErrorUserNotFound);
if (user.IsLDAP())
throw new SecurityException();
_ = SecurityContext.AuthenticateMe(ASC.Core.Configuration.Constants.CoreSystem);
user.Status = EmployeeStatus.Terminated;
UserManager.SaveUserInfo(user);
var userName = user.DisplayUserName(false, DisplayUserSettingsHelper);
MessageService.Send(MessageAction.UsersUpdatedStatus, MessageTarget.Create(user.ID), userName);
CookiesManager.ResetUserCookie(user.ID);
MessageService.Send(MessageAction.CookieSettingsUpdated);
if (CoreBaseSettings.Personal)
{
UserPhotoManager.RemovePhoto(user.ID);
UserManager.DeleteUser(user.ID);
MessageService.Send(MessageAction.UserDeleted, MessageTarget.Create(user.ID), userName);
}
else
{
//StudioNotifyService.Instance.SendMsgProfileHasDeletedItself(user);
//StudioNotifyService.SendMsgProfileDeletion(Tenant.TenantId, user);
}
return EmployeeWraperFullHelper.GetFull(user);
2019-06-17 11:57:07 +00:00
}
2019-06-25 10:46:10 +00:00
[Update("{userid}/contacts")]
2019-06-17 11:57:07 +00:00
public EmployeeWraperFull UpdateMemberContacts(string userid, UpdateMemberModel memberModel)
{
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
2019-06-17 11:57:07 +00:00
UpdateContacts(memberModel.Contacts, user);
UserManager.SaveUserInfo(user);
return EmployeeWraperFullHelper.GetFull(user);
2019-06-17 11:57:07 +00:00
}
2019-06-25 10:46:10 +00:00
[Create("{userid}/contacts")]
2019-06-17 11:57:07 +00:00
public EmployeeWraperFull SetMemberContacts(string userid, UpdateMemberModel memberModel)
{
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
2019-06-17 11:57:07 +00:00
UpdateContacts(memberModel.Contacts, user);
UserManager.SaveUserInfo(user);
return EmployeeWraperFullHelper.GetFull(user);
2019-06-17 11:57:07 +00:00
}
2019-06-25 10:46:10 +00:00
[Delete("{userid}/contacts")]
2019-06-17 11:57:07 +00:00
public EmployeeWraperFull DeleteMemberContacts(string userid, UpdateMemberModel memberModel)
{
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
2019-06-17 11:57:07 +00:00
DeleteContacts(memberModel.Contacts, user);
UserManager.SaveUserInfo(user);
return EmployeeWraperFullHelper.GetFull(user);
2019-06-17 11:57:07 +00:00
}
2019-06-25 10:46:10 +00:00
[Read("{userid}/photo")]
2019-06-17 11:57:07 +00:00
public ThumbnailsDataWrapper GetMemberPhoto(string userid)
{
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
return new ThumbnailsDataWrapper(user.ID, UserPhotoManager);
2019-06-17 11:57:07 +00:00
}
2019-09-24 12:27:13 +00:00
[Create("{userid}/photo")]
public People.Models.FileUploadResult UploadMemberPhoto(string userid, IFormCollection model)
{
var result = new People.Models.FileUploadResult();
2019-09-24 14:07:24 +00:00
bool autosave = Boolean.Parse(model["Autosave"]);
try
{
if (model.Files.Count != 0)
{
Guid userId;
try
{
userId = new Guid(userid);
}
catch
{
userId = SecurityContext.CurrentAccount.ID;
}
PermissionContext.DemandPermissions(new UserSecurityProvider(userId), Constants.Action_EditUser);
var userPhoto = model.Files[0];
if (userPhoto.Length > SetupInfo.MaxImageUploadSize)
{
result.Success = false;
result.Message = FileSizeComment.FileImageSizeExceptionString;
return result;
}
var data = new byte[userPhoto.Length];
using var inputStream = userPhoto.OpenReadStream();
var br = new BinaryReader(inputStream);
br.Read(data, 0, (int)userPhoto.Length);
br.Close();
CheckImgFormat(data);
2019-09-24 14:07:24 +00:00
if (autosave)
{
if (data.Length > SetupInfo.MaxImageUploadSize)
throw new ImageSizeLimitException();
var mainPhoto = UserPhotoManager.SaveOrUpdatePhoto(userId, data);
result.Data =
new
{
main = mainPhoto,
retina = UserPhotoManager.GetRetinaPhotoURL(userId),
max = UserPhotoManager.GetMaxPhotoURL(userId),
big = UserPhotoManager.GetBigPhotoURL(userId),
medium = UserPhotoManager.GetMediumPhotoURL(userId),
small = UserPhotoManager.GetSmallPhotoURL(userId),
};
}
else
{
result.Data = UserPhotoManager.SaveTempPhoto(data, SetupInfo.MaxImageUploadSize, UserPhotoManager.OriginalFotoSize.Width, UserPhotoManager.OriginalFotoSize.Height);
}
result.Success = true;
}
else
{
result.Success = false;
result.Message = PeopleResource.ErrorEmptyUploadFileSelected;
}
}
catch (UnknownImageFormatException)
{
result.Success = false;
result.Message = PeopleResource.ErrorUnknownFileImageType;
}
catch (ImageWeightLimitException)
{
result.Success = false;
result.Message = PeopleResource.ErrorImageWeightLimit;
}
catch (ImageSizeLimitException)
{
result.Success = false;
result.Message = PeopleResource.ErrorImageSizetLimit;
}
catch (Exception ex)
{
result.Success = false;
result.Message = ex.Message.HtmlEncode();
}
return result;
}
2019-06-25 10:46:10 +00:00
[Update("{userid}/photo")]
2019-06-17 11:57:07 +00:00
public ThumbnailsDataWrapper UpdateMemberPhoto(string userid, UpdateMemberModel model)
{
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
if (model.Files != UserPhotoManager.GetPhotoAbsoluteWebPath(user.ID))
2019-06-17 11:57:07 +00:00
{
UpdatePhotoUrl(model.Files, user);
}
UserManager.SaveUserInfo(user);
MessageService.Send(MessageAction.UserAddedAvatar, MessageTarget.Create(user.ID), user.DisplayUserName(false, DisplayUserSettingsHelper));
return new ThumbnailsDataWrapper(user.ID, UserPhotoManager);
2019-06-17 11:57:07 +00:00
}
2019-06-25 10:46:10 +00:00
[Delete("{userid}/photo")]
2019-06-17 11:57:07 +00:00
public ThumbnailsDataWrapper DeleteMemberPhoto(string userid)
{
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
PermissionContext.DemandPermissions(new UserSecurityProvider(user.ID), Constants.Action_EditUser);
UserPhotoManager.RemovePhoto(user.ID);
UserManager.SaveUserInfo(user);
MessageService.Send(MessageAction.UserDeletedAvatar, MessageTarget.Create(user.ID), user.DisplayUserName(false, DisplayUserSettingsHelper));
return new ThumbnailsDataWrapper(user.ID, UserPhotoManager);
2019-06-17 11:57:07 +00:00
}
2019-06-25 10:46:10 +00:00
[Create("{userid}/photo/thumbnails")]
2019-06-17 11:57:07 +00:00
public ThumbnailsDataWrapper CreateMemberPhotoThumbnails(string userid, ThumbnailsModel thumbnailsModel)
{
var user = GetUserInfo(userid);
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
PermissionContext.DemandPermissions(new UserSecurityProvider(user.ID), Constants.Action_EditUser);
2019-06-17 11:57:07 +00:00
if (!string.IsNullOrEmpty(thumbnailsModel.TmpFile))
{
var fileName = Path.GetFileName(thumbnailsModel.TmpFile);
var data = UserPhotoManager.GetTempPhotoData(fileName);
2019-06-17 11:57:07 +00:00
var settings = new UserPhotoThumbnailSettings(thumbnailsModel.X, thumbnailsModel.Y, thumbnailsModel.Width, thumbnailsModel.Height);
SettingsManager.SaveForUser(settings, user.ID);
2019-12-09 12:59:34 +00:00
UserPhotoManager.RemovePhoto(user.ID);
UserPhotoManager.SaveOrUpdatePhoto(user.ID, data);
UserPhotoManager.RemoveTempPhoto(fileName);
2019-06-17 11:57:07 +00:00
}
else
{
UserPhotoThumbnailManager.SaveThumbnails(UserPhotoManager, SettingsManager, thumbnailsModel.X, thumbnailsModel.Y, thumbnailsModel.Width, thumbnailsModel.Height, user.ID);
2019-06-17 11:57:07 +00:00
}
UserManager.SaveUserInfo(user);
MessageService.Send(MessageAction.UserUpdatedAvatarThumbnails, MessageTarget.Create(user.ID), user.DisplayUserName(false, DisplayUserSettingsHelper));
return new ThumbnailsDataWrapper(user.ID, UserPhotoManager);
2019-06-17 11:57:07 +00:00
}
2019-06-17 11:57:07 +00:00
[AllowAnonymous]
2019-06-25 10:46:10 +00:00
[Create("password", false)]
2019-08-12 10:53:12 +00:00
public string SendUserPassword(MemberModel memberModel)
2019-06-17 11:57:07 +00:00
{
2019-09-13 11:18:27 +00:00
var userInfo = UserManagerWrapper.SendUserPassword(memberModel.Email);
2019-06-17 11:57:07 +00:00
return string.Format(Resource.MessageYourPasswordSuccessfullySendedToEmail, userInfo.Email);
}
2019-06-25 10:46:10 +00:00
[Update("{userid}/password")]
2019-09-27 09:20:10 +00:00
[Authorize(AuthenticationSchemes = "confirm", Roles = "PasswordChange,EmailChange,Activation,Administrators")]
2019-06-17 11:57:07 +00:00
public EmployeeWraperFull ChangeUserPassword(Guid userid, MemberModel memberModel)
{
2019-09-23 15:36:22 +00:00
ApiContext.AuthByClaim();
PermissionContext.DemandPermissions(new UserSecurityProvider(userid), Constants.Action_EditUser);
var user = UserManager.GetUsers(userid);
2019-09-09 12:56:33 +00:00
if (!UserManager.UserExists(user)) return null;
2019-08-30 12:40:57 +00:00
2019-09-09 12:56:33 +00:00
if (UserManager.IsSystemUser(user.ID))
2019-06-17 11:57:07 +00:00
throw new SecurityException();
2019-06-17 11:57:07 +00:00
if (!string.IsNullOrEmpty(memberModel.Email))
{
var address = new MailAddress(memberModel.Email);
if (!string.Equals(address.Address, user.Email, StringComparison.OrdinalIgnoreCase))
{
user.Email = address.Address.ToLowerInvariant();
user.ActivationStatus = EmployeeActivationStatus.Activated;
UserManager.SaveUserInfo(user);
2019-06-17 11:57:07 +00:00
}
}
2019-06-17 11:57:07 +00:00
if (!string.IsNullOrEmpty(memberModel.Password))
{
2019-09-20 15:53:27 +00:00
SecurityContext.SetUserPassword(userid, memberModel.Password);
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.UserUpdatedPassword);
2019-09-20 15:53:27 +00:00
CookiesManager.ResetUserCookie(userid);
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.CookieSettingsUpdated);
2019-06-17 11:57:07 +00:00
}
return EmployeeWraperFullHelper.GetFull(GetUserInfo(userid.ToString()));
2019-06-17 11:57:07 +00:00
}
[Create("email", false)]
public string SendEmailChangeInstructions(UpdateMemberModel model)
{
Guid.TryParse(model.UserId, out var userid);
if (userid == Guid.Empty) throw new ArgumentNullException("userid");
var email = (model.Email ?? "").Trim();
if (string.IsNullOrEmpty(email)) throw new Exception(Resource.ErrorEmailEmpty);
if (!email.TestEmailRegex()) throw new Exception(Resource.ErrorNotCorrectEmail);
var viewer = UserManager.GetUsers(SecurityContext.CurrentAccount.ID);
var user = UserManager.GetUsers(userid);
if (user == null)
throw new Exception(Resource.ErrorUserNotFound);
if (viewer == null || (user.IsOwner(Tenant) && viewer.ID != user.ID))
throw new Exception(Resource.ErrorAccessDenied);
var existentUser = UserManager.GetUserByEmail(email);
if (existentUser.ID != Constants.LostUser.ID)
throw new Exception(CustomNamingPeople.Substitute<Resource>("ErrorEmailAlreadyExists"));
if (!viewer.IsAdmin(UserManager))
{
2019-09-17 12:42:32 +00:00
StudioNotifyService.SendEmailChangeInstructions(user, email);
}
else
{
if (email == user.Email)
throw new Exception(Resource.ErrorEmailsAreTheSame);
user.Email = email;
user.ActivationStatus = EmployeeActivationStatus.NotActivated;
UserManager.SaveUserInfo(user);
2019-09-17 12:42:32 +00:00
StudioNotifyService.SendEmailActivationInstructions(user, email);
}
MessageService.Send(MessageAction.UserSentEmailChangeInstructions, user.DisplayUserName(false, DisplayUserSettingsHelper));
return string.Format(Resource.MessageEmailChangeInstuctionsSentOnEmail, email);
}
2019-08-08 09:26:58 +00:00
private UserInfo GetUserInfo(string userNameOrId)
2019-06-17 11:57:07 +00:00
{
UserInfo user;
try
{
var userId = new Guid(userNameOrId);
user = UserManager.GetUsers(userId);
2019-06-17 11:57:07 +00:00
}
catch (FormatException)
{
user = UserManager.GetUserByUserName(userNameOrId);
2019-06-17 11:57:07 +00:00
}
if (user == null || user.ID == Constants.LostUser.ID)
throw new ItemNotFoundException("user not found");
return user;
}
2019-06-17 11:57:07 +00:00
[Update("activationstatus/{activationstatus}")]
2019-09-27 09:20:10 +00:00
[Authorize(AuthenticationSchemes = "confirm", Roles = "Activation,Administrators")]
2019-06-17 11:57:07 +00:00
public IEnumerable<EmployeeWraperFull> UpdateEmployeeActivationStatus(EmployeeActivationStatus activationstatus, UpdateMembersModel model)
{
2019-09-27 09:20:10 +00:00
ApiContext.AuthByClaim();
2019-06-17 11:57:07 +00:00
var retuls = new List<EmployeeWraperFull>();
2019-09-09 12:56:33 +00:00
foreach (var id in model.UserIds.Where(userId => !UserManager.IsSystemUser(userId)))
2019-06-17 11:57:07 +00:00
{
PermissionContext.DemandPermissions(new UserSecurityProvider(id), Constants.Action_EditUser);
var u = UserManager.GetUsers(id);
2019-06-17 11:57:07 +00:00
if (u.ID == Constants.LostUser.ID || u.IsLDAP()) continue;
2019-06-17 11:57:07 +00:00
u.ActivationStatus = activationstatus;
UserManager.SaveUserInfo(u);
retuls.Add(EmployeeWraperFullHelper.GetFull(u));
2019-06-17 11:57:07 +00:00
}
2019-06-17 11:57:07 +00:00
return retuls;
}
2019-06-17 11:57:07 +00:00
[Update("type/{type}")]
public IEnumerable<EmployeeWraperFull> UpdateUserType(EmployeeType type, UpdateMembersModel model)
{
var users = model.UserIds
2019-09-09 12:56:33 +00:00
.Where(userId => !UserManager.IsSystemUser(userId))
.Select(userId => UserManager.GetUsers(userId))
2019-06-17 11:57:07 +00:00
.ToList();
2019-06-17 11:57:07 +00:00
foreach (var user in users)
{
if (user.IsOwner(Tenant) || user.IsAdmin(UserManager) || user.IsMe(AuthContext) || user.GetListAdminModules(WebItemSecurity).Any())
2019-06-17 11:57:07 +00:00
continue;
2019-06-17 11:57:07 +00:00
switch (type)
{
case EmployeeType.User:
if (user.IsVisitor(UserManager))
2019-06-17 11:57:07 +00:00
{
if (TenantStatisticsProvider.GetUsersCount() < TenantExtra.GetTenantQuota().ActiveUsers)
2019-06-17 11:57:07 +00:00
{
UserManager.RemoveUserFromGroup(user.ID, Constants.GroupVisitor.ID);
2019-10-11 15:03:03 +00:00
WebItemSecurityCache.ClearCache(Tenant.TenantId);
2019-06-17 11:57:07 +00:00
}
}
break;
case EmployeeType.Visitor:
UserManager.AddUserIntoGroup(user.ID, Constants.GroupVisitor.ID);
2019-10-11 15:03:03 +00:00
WebItemSecurityCache.ClearCache(Tenant.TenantId);
2019-06-17 11:57:07 +00:00
break;
}
}
MessageService.Send(MessageAction.UsersUpdatedType, MessageTarget.Create(users.Select(x => x.ID)), users.Select(x => x.DisplayUserName(false, DisplayUserSettingsHelper)));
return users.Select(EmployeeWraperFullHelper.GetFull);
2019-06-17 11:57:07 +00:00
}
2019-06-17 11:57:07 +00:00
[Update("status/{status}")]
public IEnumerable<EmployeeWraperFull> UpdateUserStatus(EmployeeStatus status, UpdateMembersModel model)
{
PermissionContext.DemandPermissions(Constants.Action_EditUser);
var users = model.UserIds.Select(userId => UserManager.GetUsers(userId))
2019-09-09 12:56:33 +00:00
.Where(u => !UserManager.IsSystemUser(u.ID) && !u.IsLDAP())
2019-06-17 11:57:07 +00:00
.ToList();
2019-06-17 11:57:07 +00:00
foreach (var user in users)
{
2019-09-09 12:56:33 +00:00
if (user.IsOwner(Tenant) || user.IsMe(AuthContext))
2019-06-17 11:57:07 +00:00
continue;
2019-06-17 11:57:07 +00:00
switch (status)
{
case EmployeeStatus.Active:
if (user.Status == EmployeeStatus.Terminated)
{
if (TenantStatisticsProvider.GetUsersCount() < TenantExtra.GetTenantQuota().ActiveUsers || user.IsVisitor(UserManager))
2019-06-17 11:57:07 +00:00
{
user.Status = EmployeeStatus.Active;
UserManager.SaveUserInfo(user);
2019-06-17 11:57:07 +00:00
}
}
break;
case EmployeeStatus.Terminated:
user.Status = EmployeeStatus.Terminated;
UserManager.SaveUserInfo(user);
2019-09-20 15:53:27 +00:00
CookiesManager.ResetUserCookie(user.ID);
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.CookieSettingsUpdated);
2019-06-17 11:57:07 +00:00
break;
}
}
MessageService.Send(MessageAction.UsersUpdatedStatus, MessageTarget.Create(users.Select(x => x.ID)), users.Select(x => x.DisplayUserName(false, DisplayUserSettingsHelper)));
return users.Select(EmployeeWraperFullHelper.GetFull);
2019-06-17 11:57:07 +00:00
}
2019-06-25 10:46:10 +00:00
[Update("invite")]
2019-06-17 11:57:07 +00:00
public IEnumerable<EmployeeWraperFull> ResendUserInvites(UpdateMembersModel model)
{
var users = model.UserIds
2019-09-09 12:56:33 +00:00
.Where(userId => !UserManager.IsSystemUser(userId))
.Select(userId => UserManager.GetUsers(userId))
2019-06-17 11:57:07 +00:00
.ToList();
2019-06-17 11:57:07 +00:00
foreach (var user in users)
{
if (user.IsActive) continue;
2019-06-17 11:57:07 +00:00
if (user.ActivationStatus == EmployeeActivationStatus.Pending)
{
if (user.IsVisitor(UserManager))
2019-06-17 11:57:07 +00:00
{
2019-09-20 15:53:27 +00:00
StudioNotifyService.GuestInfoActivation(user);
2019-06-17 11:57:07 +00:00
}
else
{
2019-09-20 15:53:27 +00:00
StudioNotifyService.UserInfoActivation(user);
2019-06-17 11:57:07 +00:00
}
}
else
{
2019-09-17 12:42:32 +00:00
StudioNotifyService.SendEmailActivationInstructions(user, user.Email);
2019-06-17 11:57:07 +00:00
}
}
MessageService.Send(MessageAction.UsersSentActivationInstructions, MessageTarget.Create(users.Select(x => x.ID)), users.Select(x => x.DisplayUserName(false, DisplayUserSettingsHelper)));
return users.Select(EmployeeWraperFullHelper.GetFull);
2019-06-17 11:57:07 +00:00
}
2019-09-03 11:10:32 +00:00
[Update("delete", Order = -1)]
2019-06-17 11:57:07 +00:00
public IEnumerable<EmployeeWraperFull> RemoveUsers(UpdateMembersModel model)
{
PermissionContext.DemandPermissions(Constants.Action_AddRemoveUser);
2019-06-21 10:42:16 +00:00
CheckReassignProccess(model.UserIds);
var users = model.UserIds.Select(userId => UserManager.GetUsers(userId))
2019-09-09 12:56:33 +00:00
.Where(u => !UserManager.IsSystemUser(u.ID) && !u.IsLDAP())
2019-06-17 11:57:07 +00:00
.ToList();
var userNames = users.Select(x => x.DisplayUserName(false, DisplayUserSettingsHelper)).ToList();
2019-06-17 11:57:07 +00:00
foreach (var user in users)
{
if (user.Status != EmployeeStatus.Terminated) continue;
UserPhotoManager.RemovePhoto(user.ID);
UserManager.DeleteUser(user.ID);
2019-08-12 10:53:12 +00:00
QueueWorkerRemove.Start(Tenant.TenantId, user, SecurityContext.CurrentAccount.ID, false);
2019-06-17 11:57:07 +00:00
}
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.UsersDeleted, MessageTarget.Create(users.Select(x => x.ID)), userNames);
return users.Select(EmployeeWraperFullHelper.GetFull);
2019-06-17 11:57:07 +00:00
}
2019-06-25 10:46:10 +00:00
[Update("self/delete")]
2019-06-17 11:57:07 +00:00
public string SendInstructionsToDelete()
{
var user = UserManager.GetUsers(SecurityContext.CurrentAccount.ID);
2019-06-17 11:57:07 +00:00
if (user.IsLDAP())
throw new SecurityException();
2019-09-17 12:42:32 +00:00
StudioNotifyService.SendMsgProfileDeletion(user);
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.UserSentDeleteInstructions);
2019-06-17 11:57:07 +00:00
return string.Format(Resource.SuccessfullySentNotificationDeleteUserInfoMessage, "<b>" + user.Email + "</b>");
}
2019-06-25 10:46:10 +00:00
[Update("thirdparty/linkaccount")]
2019-06-17 11:57:07 +00:00
public void LinkAccount(string serializedProfile)
{
2019-10-09 15:04:46 +00:00
var profile = new LoginProfile(Signature, InstanceCrypto, serializedProfile);
2019-06-17 11:57:07 +00:00
if (string.IsNullOrEmpty(profile.AuthorizationError))
{
GetLinker().AddLink(SecurityContext.CurrentAccount.ID.ToString(), profile);
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.UserLinkedSocialAccount, GetMeaningfulProviderName(profile.Provider));
2019-06-17 11:57:07 +00:00
}
else
{
// ignore cancellation
if (profile.AuthorizationError != "Canceled at provider")
{
throw new Exception(profile.AuthorizationError);
}
}
}
2019-06-25 10:46:10 +00:00
[Delete("thirdparty/unlinkaccount")]
2019-06-17 11:57:07 +00:00
public void UnlinkAccount(string provider)
{
GetLinker().RemoveProvider(SecurityContext.CurrentAccount.ID.ToString(), provider);
2019-06-17 13:53:10 +00:00
MessageService.Send(MessageAction.UserUnlinkedSocialAccount, GetMeaningfulProviderName(provider));
2019-06-17 11:57:07 +00:00
}
2019-10-09 15:04:46 +00:00
private AccountLinker GetLinker()
2019-06-17 11:57:07 +00:00
{
2019-12-04 10:39:18 +00:00
return AccountLinker.Get("webstudio");
2019-06-17 11:57:07 +00:00
}
2019-06-17 11:57:07 +00:00
private static string GetMeaningfulProviderName(string providerName)
{
switch (providerName)
{
case "google":
case "openid":
return "Google";
case "facebook":
return "Facebook";
case "twitter":
return "Twitter";
case "linkedin":
return "LinkedIn";
default:
return "Unknown Provider";
}
}
2019-06-25 10:46:10 +00:00
[Read(@"reassign/progress")]
2019-06-21 10:42:16 +00:00
public ReassignProgressItem GetReassignProgress(Guid userId)
{
PermissionContext.DemandPermissions(Constants.Action_EditUser);
2019-08-12 10:53:12 +00:00
return QueueWorkerReassign.GetProgressItemStatus(Tenant.TenantId, userId);
2019-06-21 10:42:16 +00:00
}
2019-06-25 10:46:10 +00:00
[Update(@"reassign/terminate")]
2019-06-21 10:42:16 +00:00
public void TerminateReassign(Guid userId)
{
PermissionContext.DemandPermissions(Constants.Action_EditUser);
2019-08-12 10:53:12 +00:00
QueueWorkerReassign.Terminate(Tenant.TenantId, userId);
2019-06-21 10:42:16 +00:00
}
2019-06-25 10:46:10 +00:00
[Create(@"reassign/start")]
2019-06-21 10:42:16 +00:00
public ReassignProgressItem StartReassign(Guid fromUserId, Guid toUserId, bool deleteProfile)
{
PermissionContext.DemandPermissions(Constants.Action_EditUser);
var fromUser = UserManager.GetUsers(fromUserId);
2019-06-21 10:42:16 +00:00
if (fromUser == null || fromUser.ID == Constants.LostUser.ID)
throw new ArgumentException("User with id = " + fromUserId + " not found");
2019-09-09 12:56:33 +00:00
if (fromUser.IsOwner(Tenant) || fromUser.IsMe(AuthContext) || fromUser.Status != EmployeeStatus.Terminated)
2019-06-21 10:42:16 +00:00
throw new ArgumentException("Can not delete user with id = " + fromUserId);
var toUser = UserManager.GetUsers(toUserId);
2019-06-21 10:42:16 +00:00
if (toUser == null || toUser.ID == Constants.LostUser.ID)
throw new ArgumentException("User with id = " + toUserId + " not found");
if (toUser.IsVisitor(UserManager) || toUser.Status == EmployeeStatus.Terminated)
2019-06-21 10:42:16 +00:00
throw new ArgumentException("Can not reassign data to user with id = " + toUserId);
2019-08-12 10:53:12 +00:00
return QueueWorkerReassign.Start(Tenant.TenantId, fromUserId, toUserId, SecurityContext.CurrentAccount.ID, deleteProfile);
2019-06-21 10:42:16 +00:00
}
2019-06-21 10:42:16 +00:00
private void CheckReassignProccess(IEnumerable<Guid> userIds)
{
foreach (var userId in userIds)
{
2019-08-12 10:53:12 +00:00
var reassignStatus = QueueWorkerReassign.GetProgressItemStatus(Tenant.TenantId, userId);
2019-06-21 10:42:16 +00:00
if (reassignStatus == null || reassignStatus.IsCompleted)
continue;
var userName = UserManager.GetUsers(userId).DisplayUserName(DisplayUserSettingsHelper);
2019-06-21 10:42:16 +00:00
throw new Exception(string.Format(Resource.ReassignDataRemoveUserError, userName));
}
}
//#endregion
2019-06-21 10:42:16 +00:00
#region Remove user data
2019-06-25 10:46:10 +00:00
[Read(@"remove/progress")]
2019-06-21 10:42:16 +00:00
public RemoveProgressItem GetRemoveProgress(Guid userId)
{
PermissionContext.DemandPermissions(Constants.Action_EditUser);
2019-08-12 10:53:12 +00:00
return QueueWorkerRemove.GetProgressItemStatus(Tenant.TenantId, userId);
2019-06-21 10:42:16 +00:00
}
2019-06-25 10:46:10 +00:00
[Update(@"remove/terminate")]
2019-06-21 10:42:16 +00:00
public void TerminateRemove(Guid userId)
{
PermissionContext.DemandPermissions(Constants.Action_EditUser);
2019-08-12 10:53:12 +00:00
QueueWorkerRemove.Terminate(Tenant.TenantId, userId);
2019-06-21 10:42:16 +00:00
}
2019-06-25 10:46:10 +00:00
[Create(@"remove/start")]
2019-06-21 10:42:16 +00:00
public RemoveProgressItem StartRemove(Guid userId)
{
PermissionContext.DemandPermissions(Constants.Action_EditUser);
var user = UserManager.GetUsers(userId);
2019-06-21 10:42:16 +00:00
if (user == null || user.ID == Constants.LostUser.ID)
throw new ArgumentException("User with id = " + userId + " not found");
2019-09-09 12:56:33 +00:00
if (user.IsOwner(Tenant) || user.IsMe(AuthContext) || user.Status != EmployeeStatus.Terminated)
2019-06-21 10:42:16 +00:00
throw new ArgumentException("Can not delete user with id = " + userId);
2019-08-12 10:53:12 +00:00
return QueueWorkerRemove.Start(Tenant.TenantId, user, SecurityContext.CurrentAccount.ID, true);
2019-06-21 10:42:16 +00:00
}
#endregion
2019-06-17 11:57:07 +00:00
2019-08-08 09:26:58 +00:00
private void UpdateDepartments(IEnumerable<Guid> department, UserInfo user)
2019-06-17 11:57:07 +00:00
{
if (!PermissionContext.CheckPermissions(Constants.Action_EditGroups)) return;
2019-06-17 11:57:07 +00:00
if (department == null) return;
var groups = UserManager.GetUserGroups(user.ID);
2019-06-17 11:57:07 +00:00
var managerGroups = new List<Guid>();
foreach (var groupInfo in groups)
{
UserManager.RemoveUserFromGroup(user.ID, groupInfo.ID);
var managerId = UserManager.GetDepartmentManager(groupInfo.ID);
2019-06-17 11:57:07 +00:00
if (managerId == user.ID)
{
managerGroups.Add(groupInfo.ID);
UserManager.SetDepartmentManager(groupInfo.ID, Guid.Empty);
2019-06-17 11:57:07 +00:00
}
}
foreach (var guid in department)
{
var userDepartment = UserManager.GetGroupInfo(guid);
2019-06-17 11:57:07 +00:00
if (userDepartment != Constants.LostGroupInfo)
{
UserManager.AddUserIntoGroup(user.ID, guid);
2019-06-17 11:57:07 +00:00
if (managerGroups.Contains(guid))
{
UserManager.SetDepartmentManager(guid, user.ID);
2019-06-17 11:57:07 +00:00
}
}
}
}
2019-08-08 09:26:58 +00:00
private void UpdateContacts(IEnumerable<Contact> contacts, UserInfo user)
2019-06-17 11:57:07 +00:00
{
PermissionContext.DemandPermissions(new UserSecurityProvider(user.ID), Constants.Action_EditUser);
2019-09-02 15:09:45 +00:00
2019-06-17 11:57:07 +00:00
if (contacts == null) return;
2019-11-25 09:49:12 +00:00
if (user.ContactsList == null)
2019-09-02 15:09:45 +00:00
{
2019-11-25 09:49:12 +00:00
user.ContactsList = new List<string>();
2019-09-02 15:09:45 +00:00
}
else
{
2019-11-25 09:49:12 +00:00
user.ContactsList.Clear();
2019-09-02 15:09:45 +00:00
}
foreach (var contact in contacts.Where(c => !string.IsNullOrEmpty(c.Value)))
2019-06-17 11:57:07 +00:00
{
2019-11-25 09:49:12 +00:00
user.ContactsList.Add(contact.Type);
user.ContactsList.Add(contact.Value);
2019-06-17 11:57:07 +00:00
}
}
2019-08-08 09:26:58 +00:00
private void DeleteContacts(IEnumerable<Contact> contacts, UserInfo user)
2019-06-17 11:57:07 +00:00
{
PermissionContext.DemandPermissions(new UserSecurityProvider(user.ID), Constants.Action_EditUser);
2019-06-17 11:57:07 +00:00
if (contacts == null) return;
2019-11-25 09:49:12 +00:00
if (user.ContactsList == null)
2019-09-02 15:09:45 +00:00
{
2019-11-25 09:49:12 +00:00
user.ContactsList = new List<string>();
2019-09-02 15:09:45 +00:00
}
2019-06-17 11:57:07 +00:00
foreach (var contact in contacts)
{
2019-11-25 09:49:12 +00:00
var index = user.ContactsList.IndexOf(contact.Type);
2019-06-17 11:57:07 +00:00
if (index != -1)
{
//Remove existing
2019-11-25 09:49:12 +00:00
user.ContactsList.RemoveRange(index, 2);
2019-06-17 11:57:07 +00:00
}
}
}
private void UpdatePhotoUrl(string files, UserInfo user)
{
if (string.IsNullOrEmpty(files))
{
return;
}
PermissionContext.DemandPermissions(new UserSecurityProvider(user.ID), Constants.Action_EditUser);
2019-06-17 11:57:07 +00:00
if (!files.StartsWith("http://") && !files.StartsWith("https://"))
{
files = new Uri(ApiContext.HttpContext.Request.GetDisplayUrl()).GetLeftPart(UriPartial.Scheme | UriPartial.Authority) + "/" + files.TrimStart('/');
}
var request = WebRequest.Create(files);
using var response = (HttpWebResponse)request.GetResponse();
using var inputStream = response.GetResponseStream();
using var br = new BinaryReader(inputStream);
var imageByteArray = br.ReadBytes((int)response.ContentLength);
UserPhotoManager.SaveOrUpdatePhoto(user.ID, imageByteArray);
2019-06-17 11:57:07 +00:00
}
private static void CheckImgFormat(byte[] data)
{
ImageFormat imgFormat;
try
{
2019-08-15 15:08:40 +00:00
using var stream = new MemoryStream(data);
using var img = new Bitmap(stream);
imgFormat = img.RawFormat;
}
catch (OutOfMemoryException)
{
throw new ImageSizeLimitException();
}
catch (ArgumentException error)
{
throw new UnknownImageFormatException(error);
}
if (!imgFormat.Equals(ImageFormat.Png) && !imgFormat.Equals(ImageFormat.Jpeg))
{
throw new UnknownImageFormatException();
}
}
}
2019-10-31 11:28:30 +00:00
public static class PeopleControllerExtention
2019-10-31 11:28:30 +00:00
{
public static IServiceCollection AddPeopleController(this IServiceCollection services)
{
return services
2019-12-04 10:39:18 +00:00
.AddAccountLinker()
2019-10-31 11:28:30 +00:00
.AddMessageTargetService()
.AddAccountLinkerStorageService()
.AddFileSizeCommentService()
.AddCookiesManagerService()
.AddUserPhotoManagerService()
.AddCustomNamingPeopleService()
.AddSignatureService()
.AddApiContextService()
.AddUserManagerWrapperService()
.AddInstanceCryptoService()
.AddTenantUtilService()
.AddSecurityContextService()
.AddWebItemSecurityCache()
.AddDbManagerService()
.AddDisplayUserSettingsService()
.AddTenantManagerService()
.AddSetupInfo()
.AddCommonLinkUtilityService()
.AddCoreBaseSettingsService()
.AddWebItemManager()
.AddAuthContextService()
.AddWebItemSecurity()
.AddPermissionContextService()
.AddTenantStatisticsProviderService()
.AddTenantExtraService()
.AddMessageServiceService()
.AddQueueWorkerRemoveService()
.AddQueueWorkerReassignService()
.AddStudioNotifyServiceService()
.AddUserManagerService()
.AddSettingsManagerService()
.AddEmployeeWraperFull()
.AddEmployeeWraper();
2019-10-31 11:28:30 +00:00
}
}
}