2017-09-06 19:06:25 +02:00
|
|
|
defmodule Pleroma.Plugs.OAuthPlug do
|
|
|
|
import Plug.Conn
|
|
|
|
alias Pleroma.User
|
|
|
|
alias Pleroma.Repo
|
|
|
|
alias Pleroma.Web.OAuth.Token
|
|
|
|
|
|
|
|
def init(options) do
|
|
|
|
options
|
|
|
|
end
|
|
|
|
|
|
|
|
def call(%{assigns: %{user: %User{}}} = conn, _), do: conn
|
2018-03-30 15:01:53 +02:00
|
|
|
|
2017-11-19 02:22:07 +01:00
|
|
|
def call(conn, _) do
|
2018-03-30 15:01:53 +02:00
|
|
|
token =
|
|
|
|
case get_req_header(conn, "authorization") do
|
|
|
|
["Bearer " <> header] -> header
|
|
|
|
_ -> get_session(conn, :oauth_token)
|
|
|
|
end
|
|
|
|
|
2017-11-12 14:23:05 +01:00
|
|
|
with token when not is_nil(token) <- token,
|
|
|
|
%Token{user_id: user_id} <- Repo.get_by(Token, token: token),
|
2017-12-07 17:41:34 +01:00
|
|
|
%User{} = user <- Repo.get(User, user_id),
|
2018-11-20 19:47:00 +01:00
|
|
|
false <- !!user.info.deactivated do
|
2017-09-06 19:06:25 +02:00
|
|
|
conn
|
|
|
|
|> assign(:user, user)
|
|
|
|
else
|
|
|
|
_ -> conn
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|