internal/httpd/accountdelete.go
40 lines · 1447 bytes
1package httpd
2
3import (
4 "net/http"
5 "time"
6
7 "gitbay.org/gitbay/internal/control"
8 "gitbay.org/gitbay/internal/store"
9)
10
11// accountDeletePage is where the mailed deletion link lands. The token
12// is the authority, as a login link's is, so no session is needed; like
13// the login token it rides the query string. The GET changes nothing; the
14// button posts back to the same URL.
15type accountDeletePage struct {
16 basePage
17 User string
18 Scheduled string
19}
20
21func (s *Server) accountDeleteForm(w http.ResponseWriter, r *http.Request) {
22 w.Header().Set("Cache-Control", "no-store")
23 page := accountDeletePage{basePage: s.base(r)}
24 if u, err := s.st.AccountDeletionUser(store.HashToken(r.URL.Query().Get("token"))); err == nil {
25 page.User = u.Username
26 }
27 s.render(w, "accountdelete.html", page)
28}
29
30func (s *Server) accountDeleteConfirm(w http.ResponseWriter, r *http.Request) {
31 w.Header().Set("Cache-Control", "no-store")
32 u, err := s.st.ConfirmAccountDeletion(store.HashToken(r.URL.Query().Get("token")), time.Now().Add(control.DeletionGrace))
33 if err != nil {
34 s.render(w, "accountdelete.html", accountDeletePage{basePage: s.base(r)})
35 return
36 }
37 s.st.Audit(u.ID, "account.delete.scheduled", map[string]any{"user": u.Username, "after": u.DeleteAfter})
38 http.SetCookie(w, s.clearCookie(sessionCookie, sessionSameSite))
39 s.render(w, "accountdelete.html", accountDeletePage{basePage: s.base(r), User: u.Username, Scheduled: u.DeleteAfter})
40}