internal/httpd/accountdelete.go

v1.43.1
gitbay/internal/httpd/accountdelete.go history · blame · raw

40 lines · 1447 bytes

 1package httpd
 2
 3import (
 4	"net/http"
 5	"time"
 6
 7	"gitbay.org/gitbay/internal/control"
 8	"gitbay.org/gitbay/internal/store"
 9)
10
11// accountDeletePage is where the mailed deletion link lands. The token
12// is the authority, as a login link's is, so no session is needed; like
13// the login token it rides the query string. The GET changes nothing; the
14// button posts back to the same URL.
15type accountDeletePage struct {
16	basePage
17	User      string
18	Scheduled string
19}
20
21func (s *Server) accountDeleteForm(w http.ResponseWriter, r *http.Request) {
22	w.Header().Set("Cache-Control", "no-store")
23	page := accountDeletePage{basePage: s.base(r)}
24	if u, err := s.st.AccountDeletionUser(store.HashToken(r.URL.Query().Get("token"))); err == nil {
25		page.User = u.Username
26	}
27	s.render(w, "accountdelete.html", page)
28}
29
30func (s *Server) accountDeleteConfirm(w http.ResponseWriter, r *http.Request) {
31	w.Header().Set("Cache-Control", "no-store")
32	u, err := s.st.ConfirmAccountDeletion(store.HashToken(r.URL.Query().Get("token")), time.Now().Add(control.DeletionGrace))
33	if err != nil {
34		s.render(w, "accountdelete.html", accountDeletePage{basePage: s.base(r)})
35		return
36	}
37	s.st.Audit(u.ID, "account.delete.scheduled", map[string]any{"user": u.Username, "after": u.DeleteAfter})
38	http.SetCookie(w, s.clearCookie(sessionCookie, sessionSameSite))
39	s.render(w, "accountdelete.html", accountDeletePage{basePage: s.base(r), User: u.Username, Scheduled: u.DeleteAfter})
40}