2022-02-05 11:23:20 +01:00

38 lines
868 B
Go

package api
import (
"errors"
"net/http"
"strings"
"github.com/gin-gonic/gin"
"gitlab.celogeek.com/photos/api/internal/photos/models"
"gorm.io/gorm"
)
func (s *Service) RequireSession(c *gin.Context) {
token := c.GetHeader("Authorization")
if !strings.HasPrefix(token, "Private ") {
s.Error(c, http.StatusForbidden, ErrTokenMissing)
return
}
token = token[8:]
c.Set("token", token)
sess := &models.Session{}
if err := s.DB.Preload("Account").Where("token = ?", token).First(sess).Error; err != nil {
if errors.Is(err, gorm.ErrRecordNotFound) {
s.Error(c, http.StatusForbidden, ErrSessionNotFound)
} else {
s.Error(c, http.StatusForbidden, err)
}
return
}
if sess.Account == nil {
s.Error(c, http.StatusInternalServerError, ErrSessionInvalid)
return
}
s.Logger.Printf("User: %s", sess.Account.Login)
c.Set("session", sess)
}