From 2baa74d5204a29150767cb090937e54620ec7b83 Mon Sep 17 00:00:00 2001 From: Andrey Chervyakov Date: Thu, 18 Mar 2021 23:17:18 +0600 Subject: [PATCH 1/4] Fix links retrieval handler allowing negative limit and offset values --- link/handlers.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/link/handlers.go b/link/handlers.go index aa7c178..912372d 100644 --- a/link/handlers.go +++ b/link/handlers.go @@ -53,7 +53,7 @@ func allRetrievalHandler(ctx echo.Context, serv Service) error { limit := 20 if v := ctx.QueryParam("limit"); v != "" { num, err := strconv.Atoi(v) - if err != nil { + if err != nil || num < 0 { return echo.NewHTTPError(http.StatusBadRequest, "Invalid limit value.") } @@ -63,7 +63,7 @@ func allRetrievalHandler(ctx echo.Context, serv Service) error { offset := 0 if v := ctx.QueryParam("offset"); v != "" { num, err := strconv.Atoi(v) - if err != nil { + if err != nil || num < 0 { return echo.NewHTTPError(http.StatusBadRequest, "Invalid offset value.") } From a01f540a296203497126b0828f9311c9c7b2dc5a Mon Sep 17 00:00:00 2001 From: Andrey Chervyakov Date: Sat, 3 Apr 2021 22:25:11 +0600 Subject: [PATCH 2/4] Add password protected links --- link/dto.go | 5 ++++ link/entity.go | 1 + link/handlers.go | 5 ++-- link/repository.go | 20 ++++++------- link/service.go | 51 ++++++++++++++++++++++----------- migrations/002_add_password.sql | 13 +++++++++ 6 files changed, 67 insertions(+), 28 deletions(-) create mode 100644 migrations/002_add_password.sql diff --git a/link/dto.go b/link/dto.go index d8b2e68..511f174 100644 --- a/link/dto.go +++ b/link/dto.go @@ -9,18 +9,21 @@ type CreationModel struct { Id string `json:"id"` Name string `json:"name"` RedirectURL string `json:"redirectUrl"` + Password string `json:"password"` } type ResourceModel struct { Id string `json:"id"` Name string `json:"name"` RedirectURL string `json:"redirectUrl"` + Password string `json:"password"` CreationTime int64 `json:"creationTime"` } type UpdateModel struct { Name string `json:"name,omitempty"` RedirectURL string `json:"redirectUrl,omitempty"` + Password string `json:"password"` } func (m *CreationModel) MapModelToEntity() (*Link, error) { @@ -33,6 +36,7 @@ func (m *CreationModel) MapModelToEntity() (*Link, error) { Id: m.Id, Name: m.Name, RedirectURL: *u, + Password: m.Password, CreationTime: time.Now().UTC(), }, nil } @@ -42,6 +46,7 @@ func MapEntityToModel(entity *Link) ResourceModel { Id: entity.Id, Name: entity.Name, RedirectURL: entity.RedirectURL.String(), + Password: entity.Password, CreationTime: entity.CreationTime.Unix(), } } diff --git a/link/entity.go b/link/entity.go index 50f6521..343743e 100644 --- a/link/entity.go +++ b/link/entity.go @@ -9,6 +9,7 @@ type Link struct { Id string Name string RedirectURL url.URL + Password string CreationTime time.Time } diff --git a/link/handlers.go b/link/handlers.go index 912372d..be10ada 100644 --- a/link/handlers.go +++ b/link/handlers.go @@ -11,13 +11,14 @@ import ( func redirectHandler(ctx echo.Context, serv Service) error { linkId := ctx.Param("id") + linkPassword := ctx.QueryParam("password") - link, err := serv.GetById(linkId) + redirectUrl, err := serv.AccessLink(linkId, linkPassword) if err != nil { return err } - return ctx.Redirect(http.StatusSeeOther, link.RedirectURL.String()) + return ctx.Redirect(http.StatusSeeOther, redirectUrl.String()) } func creationHandler(ctx echo.Context, serv Service) error { diff --git a/link/repository.go b/link/repository.go index 8751b3a..f8149d6 100644 --- a/link/repository.go +++ b/link/repository.go @@ -34,12 +34,12 @@ func (r *PgRepository) Save(link *Link) error { defer cancel() sql := ` - INSERT INTO links (id, name, redirect_url, creation_time) - VALUES ($1, $2, $3, $4::timestamp) + INSERT INTO links (id, name, redirect_url, password, creation_time) + VALUES ($1, $2, $3, $4, $5::timestamp) ` database.LogPoolState(r.pool, "Saving link") - _, err := r.pool.Exec(ctx, sql, link.Id, link.Name, link.RedirectURL.String(), link.CreationTime.Format("2006-01-02 15:04:05")) + _, err := r.pool.Exec(ctx, sql, link.Id, link.Name, link.RedirectURL.String(), link.Password, link.CreationTime.Format("2006-01-02 15:04:05")) if err != nil { return err } @@ -52,7 +52,7 @@ func (r *PgRepository) FindById(id string) (*Link, error) { defer cancel() sql := ` - SELECT id, name, redirect_url, creation_time + SELECT id, name, redirect_url, password, creation_time FROM links WHERE id = $1 ` @@ -82,7 +82,7 @@ func (r *PgRepository) GetAll(limit int, offset int) (Links, error) { defer cancel() sql := ` - SELECT id, name, redirect_url, creation_time + SELECT id, name, redirect_url, password, creation_time FROM links LIMIT $1 OFFSET $2 @@ -122,12 +122,12 @@ func (r *PgRepository) Update(link *Link) error { sql := ` UPDATE links - SET name = $1, redirect_url = $2 - WHERE id = $3 + SET name = $1, redirect_url = $2, password = $3 + WHERE id = $4 ` database.LogPoolState(r.pool, "Updating link") - _, err := r.pool.Exec(ctx, sql, link.Name, link.RedirectURL.String(), link.Id) + _, err := r.pool.Exec(ctx, sql, link.Name, link.RedirectURL.String(), link.Password, link.Id) if err != nil { return err } @@ -159,11 +159,11 @@ func mapRowToEntity(r interface{}) (*Link, error) { switch v := r.(type) { case pgx.Row: - if err := v.Scan(&entity.Id, &entity.Name, &urlStr, &t); err != nil { + if err := v.Scan(&entity.Id, &entity.Name, &urlStr, &entity.Password, &t); err != nil { return nil, err } case pgx.Rows: - if err := v.Scan(&entity.Id, &entity.Name, &urlStr, &t); err != nil { + if err := v.Scan(&entity.Id, &entity.Name, &urlStr, &entity.Password, &t); err != nil { return nil, err } default: diff --git a/link/service.go b/link/service.go index b35d7d5..5c4b092 100644 --- a/link/service.go +++ b/link/service.go @@ -3,11 +3,15 @@ package link import ( apperrors "cgnolink/errors" "github.com/patrickmn/go-cache" + "net/url" ) +var linkNotFoundError = apperrors.NotFoundError{Message: "Link with given ID was not found."} + type Service interface { Create(link *Link) error GetById(id string) (*Link, error) + AccessLink(id string, password string) (*url.URL, error) GetAll(limit int, offset int) (Links, error) Update(data *Link) error DeleteById(id string) error @@ -18,6 +22,21 @@ type PgService struct { cache *cache.Cache } +func (service *PgService) AccessLink(id string, password string) (*url.URL, error) { + link, err := service.GetById(id) + if err != nil { + return nil, err + } + + if link.Password != "" { + if password == "" || link.Password != password { + return nil, linkNotFoundError + } + } + + return &link.RedirectURL, nil +} + func NewService(rep Repository) Service { return &PgService{ rep: rep, @@ -25,8 +44,8 @@ func NewService(rep Repository) Service { } } -func (s *PgService) Create(link *Link) error { - existingLink, err := s.rep.FindById(link.Id) +func (service *PgService) Create(link *Link) error { + existingLink, err := service.rep.FindById(link.Id) if err != nil { return apperrors.UnknownError{Err: err} } @@ -35,36 +54,36 @@ func (s *PgService) Create(link *Link) error { return apperrors.AlreadyExistsError{Message: "Link with given ID already exists."} } - if err = s.rep.Save(link); err != nil { + if err = service.rep.Save(link); err != nil { return apperrors.UnknownError{Err: err} } return nil } -func (s *PgService) GetById(id string) (*Link, error) { - if v, found := s.cache.Get(id); found { +func (service *PgService) GetById(id string) (*Link, error) { + if v, found := service.cache.Get(id); found { if link, ok := v.(*Link); ok { return link, nil } } - link, err := s.rep.FindById(id) + link, err := service.rep.FindById(id) if err != nil { return nil, apperrors.UnknownError{Err: err} } if link == nil { - return nil, apperrors.NotFoundError{Message: "Link with given ID was not found."} + return nil, linkNotFoundError } - s.cache.Set(id, link, cache.DefaultExpiration) + service.cache.Set(id, link, cache.DefaultExpiration) return link, nil } -func (s *PgService) GetAll(limit int, offset int) (Links, error) { - links, err := s.rep.GetAll(limit, offset) +func (service *PgService) GetAll(limit int, offset int) (Links, error) { + links, err := service.rep.GetAll(limit, offset) if err != nil { return nil, apperrors.UnknownError{Err: err} } @@ -72,20 +91,20 @@ func (s *PgService) GetAll(limit int, offset int) (Links, error) { return links, nil } -func (s *PgService) Update(data *Link) error { - if err := s.rep.Update(data); err != nil { +func (service *PgService) Update(data *Link) error { + if err := service.rep.Update(data); err != nil { return apperrors.UnknownError{Err: err} } + service.cache.Delete(data.Id) return nil } -func (s *PgService) DeleteById(id string) error { - s.cache.Delete(id) - - if err := s.rep.DeleteById(id); err != nil { +func (service *PgService) DeleteById(id string) error { + if err := service.rep.DeleteById(id); err != nil { return apperrors.UnknownError{Err: err} } + service.cache.Delete(id) return nil } diff --git a/migrations/002_add_password.sql b/migrations/002_add_password.sql new file mode 100644 index 0000000..715fffb --- /dev/null +++ b/migrations/002_add_password.sql @@ -0,0 +1,13 @@ +ALTER TABLE links +ADD COLUMN password varchar; + +UPDATE links +SET password = ''; + +ALTER TABLE links +ALTER COLUMN password SET not null; + +---- create above / drop below ---- + +ALTER TABLE links +DROP COLUMN password; From f4684be37d13a93b103d7ed3652d89cbd7388bf1 Mon Sep 17 00:00:00 2001 From: Andrey Chervyakov Date: Sun, 4 Apr 2021 16:36:13 +0600 Subject: [PATCH 3/4] Add hashing for link password and update link update service method --- go.mod | 3 +- link/dto.go | 2 -- link/handlers.go | 33 +++++++--------------- link/service.go | 73 ++++++++++++++++++++++++++++++++++++++++++++---- 4 files changed, 79 insertions(+), 32 deletions(-) diff --git a/go.mod b/go.mod index ab59fcd..96d31a5 100644 --- a/go.mod +++ b/go.mod @@ -13,8 +13,9 @@ require ( github.com/knadh/koanf v0.15.0 github.com/labstack/echo/v4 v4.2.1 github.com/mitchellh/copystructure v1.1.1 // indirect - github.com/patrickmn/go-cache v2.1.0+incompatible // indirect + github.com/patrickmn/go-cache v2.1.0+incompatible github.com/rs/zerolog v1.20.0 + golang.org/x/crypto v0.0.0-20210220033148-5ea612d1eb83 golang.org/x/sys v0.0.0-20210309074719-68d13333faf2 // indirect golang.org/x/text v0.3.5 // indirect golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect diff --git a/link/dto.go b/link/dto.go index 511f174..c811153 100644 --- a/link/dto.go +++ b/link/dto.go @@ -16,7 +16,6 @@ type ResourceModel struct { Id string `json:"id"` Name string `json:"name"` RedirectURL string `json:"redirectUrl"` - Password string `json:"password"` CreationTime int64 `json:"creationTime"` } @@ -46,7 +45,6 @@ func MapEntityToModel(entity *Link) ResourceModel { Id: entity.Id, Name: entity.Name, RedirectURL: entity.RedirectURL.String(), - Password: entity.Password, CreationTime: entity.CreationTime.Unix(), } } diff --git a/link/handlers.go b/link/handlers.go index be10ada..10a25c6 100644 --- a/link/handlers.go +++ b/link/handlers.go @@ -92,33 +92,20 @@ func updateHandler(ctx echo.Context, serv Service) error { return echo.NewHTTPError(http.StatusBadRequest, "Invalid data format.") } - updatingLink, err := serv.GetById(linkId) + var parsedUrl *url.URL + parsedUrl, err := url.Parse(model.RedirectURL) if err != nil { + return echo.NewHTTPError(http.StatusBadRequest, "Invalid URL value.") + } + + if err := serv.UpdateById(linkId, struct { + Name string + Password string + RedirectURL *url.URL + }{Name: model.Name, Password: model.Password, RedirectURL: parsedUrl}); err != nil { return err } - hasChanges := false - switch { - case model.Name != "" && model.Name != updatingLink.Name: - updatingLink.Name = model.Name - - hasChanges = true - case model.RedirectURL != "" && model.RedirectURL != updatingLink.RedirectURL.String(): - if parsedUrl, err := url.Parse(model.RedirectURL); err != nil { - return echo.NewHTTPError(http.StatusBadRequest, "Invalid URL value.") - } else { - updatingLink.RedirectURL = *parsedUrl - } - - hasChanges = true - } - - if hasChanges { - if err = serv.Update(updatingLink); err != nil { - return err - } - } - return ctx.NoContent(http.StatusOK) } diff --git a/link/service.go b/link/service.go index 5c4b092..26f048f 100644 --- a/link/service.go +++ b/link/service.go @@ -3,6 +3,7 @@ package link import ( apperrors "cgnolink/errors" "github.com/patrickmn/go-cache" + "golang.org/x/crypto/bcrypt" "net/url" ) @@ -13,7 +14,14 @@ type Service interface { GetById(id string) (*Link, error) AccessLink(id string, password string) (*url.URL, error) GetAll(limit int, offset int) (Links, error) - Update(data *Link) error + UpdateById( + id string, + data struct { + Name string + Password string + RedirectURL *url.URL + }, + ) error DeleteById(id string) error } @@ -29,7 +37,7 @@ func (service *PgService) AccessLink(id string, password string) (*url.URL, erro } if link.Password != "" { - if password == "" || link.Password != password { + if password == "" || bcrypt.CompareHashAndPassword([]byte(link.Password), []byte(password)) != nil { return nil, linkNotFoundError } } @@ -54,6 +62,15 @@ func (service *PgService) Create(link *Link) error { return apperrors.AlreadyExistsError{Message: "Link with given ID already exists."} } + if link.Password != "" { + hashedPassword, err := HashPassword(link.Password) + if err != nil { + return err + } + + link.Password = hashedPassword + } + if err = service.rep.Save(link); err != nil { return apperrors.UnknownError{Err: err} } @@ -91,11 +108,46 @@ func (service *PgService) GetAll(limit int, offset int) (Links, error) { return links, nil } -func (service *PgService) Update(data *Link) error { - if err := service.rep.Update(data); err != nil { - return apperrors.UnknownError{Err: err} +func (service *PgService) UpdateById( + id string, + data struct { + Name string + Password string + RedirectURL *url.URL + }, +) error { + link, err := service.GetById(id) + if err != nil { + return err + } + + hasChanges := false + switch { + case data.Name != "": + link.Name = data.Name + + hasChanges = true + case data.RedirectURL != nil: + link.RedirectURL = *data.RedirectURL + + hasChanges = true + case data.Password != "": + hashedPw, err := HashPassword(data.Password) + if err != nil { + return err + } + + link.Password = hashedPw + + hasChanges = true + } + + if hasChanges { + if err := service.rep.Update(link); err != nil { + return apperrors.UnknownError{Err: err} + } + service.cache.Delete(link.Id) } - service.cache.Delete(data.Id) return nil } @@ -108,3 +160,12 @@ func (service *PgService) DeleteById(id string) error { return nil } + +func HashPassword(password string) (string, error) { + hashedPw, err := bcrypt.GenerateFromPassword([]byte(password), bcrypt.DefaultCost) + if err != nil { + return "", apperrors.UnknownError{Err: err} + } + + return string(hashedPw), nil +} From e1516e450b03a53878a63f911612a2a3195c06ea Mon Sep 17 00:00:00 2001 From: Andrey Chervyakov Date: Mon, 12 Apr 2021 17:17:09 +0600 Subject: [PATCH 4/4] Put project modules under pkg directory --- cmd/cgnolink/main.go | 6 +++--- config.go => pkg/cgnolink/config.go | 0 {database => pkg/cgnolink/database}/database.go | 0 {database => pkg/cgnolink/database}/migrate.go | 0 {database => pkg/cgnolink/database}/util.go | 0 {errors => pkg/cgnolink/errors}/errors.go | 0 {link => pkg/cgnolink/link}/dto.go | 0 {link => pkg/cgnolink/link}/entity.go | 0 {link => pkg/cgnolink/link}/handlers.go | 0 {link => pkg/cgnolink/link}/repository.go | 2 +- {link => pkg/cgnolink/link}/service.go | 2 +- {server => pkg/cgnolink/server}/middleware.go | 0 {server => pkg/cgnolink/server}/server.go | 4 ++-- 13 files changed, 7 insertions(+), 7 deletions(-) rename config.go => pkg/cgnolink/config.go (100%) rename {database => pkg/cgnolink/database}/database.go (100%) rename {database => pkg/cgnolink/database}/migrate.go (100%) rename {database => pkg/cgnolink/database}/util.go (100%) rename {errors => pkg/cgnolink/errors}/errors.go (100%) rename {link => pkg/cgnolink/link}/dto.go (100%) rename {link => pkg/cgnolink/link}/entity.go (100%) rename {link => pkg/cgnolink/link}/handlers.go (100%) rename {link => pkg/cgnolink/link}/repository.go (99%) rename {link => pkg/cgnolink/link}/service.go (98%) rename {server => pkg/cgnolink/server}/middleware.go (100%) rename {server => pkg/cgnolink/server}/server.go (95%) diff --git a/cmd/cgnolink/main.go b/cmd/cgnolink/main.go index 4a72941..45ce28a 100644 --- a/cmd/cgnolink/main.go +++ b/cmd/cgnolink/main.go @@ -1,9 +1,9 @@ package main import ( - "cgnolink" - "cgnolink/database" - appserver "cgnolink/server" + "cgnolink/pkg/cgnolink" + "cgnolink/pkg/cgnolink/database" + appserver "cgnolink/pkg/cgnolink/server" "github.com/rs/zerolog" "github.com/rs/zerolog/log" "os" diff --git a/config.go b/pkg/cgnolink/config.go similarity index 100% rename from config.go rename to pkg/cgnolink/config.go diff --git a/database/database.go b/pkg/cgnolink/database/database.go similarity index 100% rename from database/database.go rename to pkg/cgnolink/database/database.go diff --git a/database/migrate.go b/pkg/cgnolink/database/migrate.go similarity index 100% rename from database/migrate.go rename to pkg/cgnolink/database/migrate.go diff --git a/database/util.go b/pkg/cgnolink/database/util.go similarity index 100% rename from database/util.go rename to pkg/cgnolink/database/util.go diff --git a/errors/errors.go b/pkg/cgnolink/errors/errors.go similarity index 100% rename from errors/errors.go rename to pkg/cgnolink/errors/errors.go diff --git a/link/dto.go b/pkg/cgnolink/link/dto.go similarity index 100% rename from link/dto.go rename to pkg/cgnolink/link/dto.go diff --git a/link/entity.go b/pkg/cgnolink/link/entity.go similarity index 100% rename from link/entity.go rename to pkg/cgnolink/link/entity.go diff --git a/link/handlers.go b/pkg/cgnolink/link/handlers.go similarity index 100% rename from link/handlers.go rename to pkg/cgnolink/link/handlers.go diff --git a/link/repository.go b/pkg/cgnolink/link/repository.go similarity index 99% rename from link/repository.go rename to pkg/cgnolink/link/repository.go index f8149d6..aa19b82 100644 --- a/link/repository.go +++ b/pkg/cgnolink/link/repository.go @@ -1,7 +1,7 @@ package link import ( - "cgnolink/database" + "cgnolink/pkg/cgnolink/database" "context" "errors" "github.com/jackc/pgtype" diff --git a/link/service.go b/pkg/cgnolink/link/service.go similarity index 98% rename from link/service.go rename to pkg/cgnolink/link/service.go index 26f048f..b7f00f6 100644 --- a/link/service.go +++ b/pkg/cgnolink/link/service.go @@ -1,7 +1,7 @@ package link import ( - apperrors "cgnolink/errors" + apperrors "cgnolink/pkg/cgnolink/errors" "github.com/patrickmn/go-cache" "golang.org/x/crypto/bcrypt" "net/url" diff --git a/server/middleware.go b/pkg/cgnolink/server/middleware.go similarity index 100% rename from server/middleware.go rename to pkg/cgnolink/server/middleware.go diff --git a/server/server.go b/pkg/cgnolink/server/server.go similarity index 95% rename from server/server.go rename to pkg/cgnolink/server/server.go index 11e23de..254116b 100644 --- a/server/server.go +++ b/pkg/cgnolink/server/server.go @@ -1,8 +1,8 @@ package server import ( - apperrors "cgnolink/errors" - "cgnolink/link" + apperrors "cgnolink/pkg/cgnolink/errors" + "cgnolink/pkg/cgnolink/link" "github.com/jackc/pgx/v4/pgxpool" "github.com/knadh/koanf" "github.com/labstack/echo/v4"