diff --git a/backend/app/cmd/backup.go b/backend/app/cmd/backup.go index 5e1a3984..7d3047df 100644 --- a/backend/app/cmd/backup.go +++ b/backend/app/cmd/backup.go @@ -13,7 +13,7 @@ import ( ) // BackupCommand set of flags and command for export -// ExportPath used as a separate element to leverage BACKUP_PATH. If ExportFile has a path (i.e. /) BACKUP_PATH ignored. +// ExportPath used as a separate element to leverage BACKUP_PATH. If ExportFile has a path (i.e. with /) BACKUP_PATH ignored. type BackupCommand struct { ExportPath string `short:"p" long:"path" env:"BACKUP_PATH" default:"./var/backup" description:"export path"` ExportFile string `short:"f" long:"file" default:"userbackup-{{.SITE}}-{{.TS}}.gz" description:"file name"` diff --git a/backend/app/cmd/cmd.go b/backend/app/cmd/cmd.go index 9407f2ed..cb1d2c2f 100644 --- a/backend/app/cmd/cmd.go +++ b/backend/app/cmd/cmd.go @@ -29,6 +29,7 @@ type fileParser struct { // parse apply template and also concat path and file. In case if file contains path separator path will be ignored func (p *fileParser) parse(now time.Time) (string, error) { + // file/location paramaters my have template masks fileTemplate := struct { YYYYMMDD string YYYY string diff --git a/backend/app/cmd/server.go b/backend/app/cmd/server.go index 7f9f4314..249f52de 100644 --- a/backend/app/cmd/server.go +++ b/backend/app/cmd/server.go @@ -14,7 +14,6 @@ import ( "github.com/coreos/bbolt" "github.com/go-pkgz/mongo" "github.com/pkg/errors" - "github.com/umputun/remark/backend/app/store/admin" "github.com/umputun/remark/backend/app/migrator" "github.com/umputun/remark/backend/app/rest/api" @@ -22,6 +21,7 @@ import ( "github.com/umputun/remark/backend/app/rest/cache" "github.com/umputun/remark/backend/app/rest/proxy" "github.com/umputun/remark/backend/app/store" + "github.com/umputun/remark/backend/app/store/admin" "github.com/umputun/remark/backend/app/store/avatar" "github.com/umputun/remark/backend/app/store/engine" "github.com/umputun/remark/backend/app/store/keys" diff --git a/backend/app/rest/auth/auth.go b/backend/app/rest/auth/auth.go index e6ff1d56..e71ce422 100644 --- a/backend/app/rest/auth/auth.go +++ b/backend/app/rest/auth/auth.go @@ -28,7 +28,7 @@ var devUser = store.User{ Admin: true, } -// PermissionChecker defines interface to get user flags +// PermissionChecker defines interface to check user flags type PermissionChecker interface { IsVerified(siteID, userID string) bool IsBlocked(siteID, userID string) bool @@ -41,7 +41,7 @@ func (a *Authenticator) Auth(reqAuth bool) func(http.Handler) http.Handler { f := func(h http.Handler) http.Handler { fn := func(w http.ResponseWriter, r *http.Request) { - if a.basicDevUser(w, r) { // fail-back to dev user if enabled + if a.basicDevUser(w, r) { // use dev user basic auth if enabled user := devUser r = rest.SetUserInfo(r, user) h.ServeHTTP(w, r) @@ -49,13 +49,13 @@ func (a *Authenticator) Auth(reqAuth bool) func(http.Handler) http.Handler { } claims, err := a.JWTService.Get(r) - if err != nil && reqAuth { // in full auth lack of session causes Unauthorized - log.Printf("[DEBUG] failed auth, %s", err) - http.Error(w, "Unauthorized", http.StatusUnauthorized) - return - } - - if err != nil { // in anonymous mode just pass it to the next handler + if err != nil { + if reqAuth { // in full auth lack of token causes Unauthorized + log.Printf("[DEBUG] failed auth, %s", err) + http.Error(w, "Unauthorized", http.StatusUnauthorized) + return + } + // in anonymous mode just pass it to the next handler h.ServeHTTP(w, r) return } @@ -74,7 +74,7 @@ func (a *Authenticator) Auth(reqAuth bool) func(http.Handler) http.Handler { return } - if a.JWTService.HasFlags(claims) { + if a.JWTService.HasFlags(claims) { // flags in token indicate special use cases, not for login log.Printf("[DEBUG] invalid token flags for %s/%s", claims.User.Name, claims.User.ID) http.Error(w, "Unauthorized", http.StatusUnauthorized) return @@ -97,6 +97,7 @@ func (a *Authenticator) Auth(reqAuth bool) func(http.Handler) http.Handler { return f } +// refreshExpiredToken makes new token with passed claims, but only if permission allowed func (a *Authenticator) refreshExpiredToken(w http.ResponseWriter, claims *CustomClaims) (*CustomClaims, error) { if a.PermissionChecker != nil { claims.User.Admin = a.PermissionChecker.IsAdmin(claims.SiteID, claims.User.ID) @@ -110,7 +111,7 @@ func (a *Authenticator) refreshExpiredToken(w http.ResponseWriter, claims *Custo return claims, nil } -// AdminOnly allows access to admins +// AdminOnly middleware allows access for admins only func (a *Authenticator) AdminOnly(next http.Handler) http.Handler { fn := func(w http.ResponseWriter, r *http.Request) {