2022-03-24 08:43:55 +00:00
|
|
|
package resolvers
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"fmt"
|
|
|
|
"time"
|
|
|
|
|
2022-05-24 07:12:29 +00:00
|
|
|
log "github.com/sirupsen/logrus"
|
|
|
|
|
2022-03-24 08:43:55 +00:00
|
|
|
"github.com/authorizerdev/authorizer/server/db"
|
|
|
|
"github.com/authorizerdev/authorizer/server/graph/model"
|
|
|
|
"github.com/authorizerdev/authorizer/server/sessionstore"
|
|
|
|
"github.com/authorizerdev/authorizer/server/token"
|
|
|
|
"github.com/authorizerdev/authorizer/server/utils"
|
|
|
|
)
|
|
|
|
|
|
|
|
// RevokeAccessResolver is a resolver for revoking user access
|
|
|
|
func RevokeAccessResolver(ctx context.Context, params model.UpdateAccessInput) (*model.Response, error) {
|
|
|
|
var res *model.Response
|
2022-05-24 07:12:29 +00:00
|
|
|
|
|
|
|
gc, err := utils.GinContextFromContext(ctx)
|
2022-03-24 08:43:55 +00:00
|
|
|
if err != nil {
|
2022-05-24 07:12:29 +00:00
|
|
|
log.Debug("Failed to get GinContext", err)
|
2022-03-24 08:43:55 +00:00
|
|
|
return res, err
|
|
|
|
}
|
|
|
|
|
|
|
|
if !token.IsSuperAdmin(gc) {
|
2022-05-24 07:12:29 +00:00
|
|
|
log.Debug("Not logged in as super admin.")
|
2022-03-24 08:43:55 +00:00
|
|
|
return res, fmt.Errorf("unauthorized")
|
|
|
|
}
|
|
|
|
|
2022-05-24 07:12:29 +00:00
|
|
|
log := log.WithFields(log.Fields{
|
|
|
|
"user_id": params.UserID,
|
|
|
|
})
|
2022-03-24 08:43:55 +00:00
|
|
|
user, err := db.Provider.GetUserByID(params.UserID)
|
|
|
|
if err != nil {
|
2022-05-24 07:12:29 +00:00
|
|
|
log.Debug("Failed to get user by ID", err)
|
2022-03-24 08:43:55 +00:00
|
|
|
return res, err
|
|
|
|
}
|
|
|
|
|
|
|
|
now := time.Now().Unix()
|
|
|
|
user.RevokedTimestamp = &now
|
|
|
|
|
|
|
|
user, err = db.Provider.UpdateUser(user)
|
|
|
|
if err != nil {
|
2022-05-24 07:12:29 +00:00
|
|
|
log.Debug("Failed to update user", err)
|
2022-03-24 08:43:55 +00:00
|
|
|
return res, err
|
|
|
|
}
|
|
|
|
|
|
|
|
go sessionstore.DeleteAllUserSession(fmt.Sprintf("%x", user.ID))
|
|
|
|
|
|
|
|
res = &model.Response{
|
|
|
|
Message: `user access revoked successfully`,
|
|
|
|
}
|
|
|
|
|
|
|
|
return res, nil
|
|
|
|
}
|