diff --git a/controllers/authController.go b/controllers/authController.go index c7808d2..c188f8f 100644 --- a/controllers/authController.go +++ b/controllers/authController.go @@ -198,6 +198,7 @@ func Enroll(c *fiber.Ctx) error { // Disable login block student.AccountData.AccountDisabled = false + student.AccountData.Alerted = false student.AccountData.Attempts = 0 // Generate temporary password @@ -210,12 +211,11 @@ func Enroll(c *fiber.Ctx) error { receiver := student.PersonalData.Email r := NewRequest([]string{receiver}, subject) - if err := r.Send("./templates/passwordChanged.html", map[string]string{"username": student.PersonalData.FirstName, "password": tempPass}); err { + if sent := r.Send("./templates/passwordChanged.html", map[string]string{"username": student.PersonalData.FirstName, "password": tempPass}); !sent { cancel() return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ "success": false, "message": "Could not send password to students email", - "error": err, }) } @@ -345,12 +345,11 @@ func RegisterTeacher(c *fiber.Ctx) error { receiver := teacher.PersonalData.Email r := NewRequest([]string{receiver}, subject) - if err := r.Send("./templates/passwordChanged.html", map[string]string{"username": teacher.PersonalData.FirstName, "password": tempPass}); err { + if sent := r.Send("./templates/passwordChanged.html", map[string]string{"username": teacher.PersonalData.FirstName, "password": tempPass}); !sent { cancel() return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ "success": false, "message": "Could not send password to teachers email", - "error": err, }) } @@ -433,12 +432,11 @@ func CreateAdmin(c *fiber.Ctx) error { receiver := admin.Email r := NewRequest([]string{receiver}, subject) - if err := r.Send("./templates/passwordChanged.html", map[string]string{"username": admin.FirstName, "password": tempPass}); err { + if sent := r.Send("./templates/passwordChanged.html", map[string]string{"username": admin.FirstName, "password": tempPass}); !sent { cancel() return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ "success": false, "message": "Could not send password to students email", - "error": err, }) } @@ -496,7 +494,6 @@ func StudentLogin(c *fiber.Ctx) error { var student models.Student err := studentCollection.FindOne(ctx, bson.M{"schooldata.sid": data["sid"]}).Decode(&student) - defer cancel() if err != nil { cancel() @@ -507,21 +504,29 @@ func StudentLogin(c *fiber.Ctx) error { }) } - var localAccountDisabled = false - if student.AccountData.Attempts >= 5 { + var verified bool = student.ComparePasswords(data["password"]) + var localAccountDisabled bool = false + var localAttempts int = student.AccountData.Attempts + + if !verified { + localAttempts += 1 + } + + if student.AccountData.Attempts >= 5 || localAttempts >= 5 { localAccountDisabled = true // Catches newly disbaled account before student obj is updated update_time, _ := time.Parse(time.RFC3339, time.Now().Format(time.RFC3339)) update := bson.M{ "$set": bson.M{ - "AccountData.accountdisabled": true, - "AccountData.attempts": 0, + "accountdata.accountdisabled": true, + "accountdata.alerted": true, + "accountdata.attempts": 0, "updated_at": update_time, }, } _, updateErr := studentCollection.UpdateOne( ctx, - bson.M{"sid": data["sid"]}, + bson.M{"schooldata.sid": data["sid"]}, update, ) if updateErr != nil { @@ -535,41 +540,42 @@ func StudentLogin(c *fiber.Ctx) error { } if localAccountDisabled || student.AccountData.AccountDisabled { + + if !student.AccountData.Alerted { + // Send student email warning of disabled account + subject := "Account Disabled" + receiver := student.PersonalData.Email + r := NewRequest([]string{receiver}, subject) + + if sent := r.Send("./templates/accountDisabled.html", map[string]string{"username": student.PersonalData.FirstName}); !sent { + cancel() + return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ + "success": false, + "message": "Could not send password to students email", + "error": err, + }) + } + } cancel() - // Send student email warning of disabled account - subject := "Account Disabled" - receiver := student.PersonalData.Email - r := NewRequest([]string{receiver}, subject) - - if err := r.Send("./templates/accountDisabled.html", map[string]string{"username": student.PersonalData.FirstName}); err { - cancel() - return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ - "success": false, - "message": "Could not send password to students email", - "error": err, - }) - } - - return c.Status(fiber.StatusUnauthorized).JSON(fiber.Map{ + return c.Status(fiber.StatusOK).JSON(fiber.Map{ "success": false, "message": "Account is Disabled, contact an Admin", }) } - var verified bool = student.ComparePasswords(data["password"]) - if verified == false { + if !verified { update_time, _ := time.Parse(time.RFC3339, time.Now().Format(time.RFC3339)) update := bson.M{ "$set": bson.M{ - "AccountData.attempts": student.AccountData.Attempts + 1, + "accountdata.attempts": (student.AccountData.Attempts + 1), "updated_at": update_time, }, } _, updateErr := studentCollection.UpdateOne( ctx, - bson.M{"sid": data["sid"]}, + bson.M{"schooldata.sid": data["sid"]}, update, ) cancel() @@ -580,10 +586,33 @@ func StudentLogin(c *fiber.Ctx) error { "error": updateErr, }) } + return c.Status(fiber.StatusOK).JSON(fiber.Map{ "success": false, "message": "incorrect password", }) + } else { + update_time, _ := time.Parse(time.RFC3339, time.Now().Format(time.RFC3339)) + update := bson.M{ + "$set": bson.M{ + "accountdata.attempts": 0, + "updated_at": update_time, + }, + } + + _, updateErr := studentCollection.UpdateOne( + ctx, + bson.M{"schooldata.sid": data["sid"]}, + update, + ) + if updateErr != nil { + cancel() + return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ + "success": false, + "message": "the student could not be updated", + "error": updateErr, + }) + } } defer cancel() diff --git a/controllers/updateController.go b/controllers/updateController.go index b5b2d2c..d2ea1d3 100644 --- a/controllers/updateController.go +++ b/controllers/updateController.go @@ -342,7 +342,13 @@ func UpdateStudentPassword(c *fiber.Ctx) error { subject := "Password Changed" receiver := student.PersonalData.Email r := NewRequest([]string{receiver}, subject) - r.Send("./templates/selfPasswordChanged.html", map[string]string{"username": student.PersonalData.FirstName}) + + if sent := r.Send("./templates/selfPasswordChanged.html", map[string]string{"username": student.PersonalData.FirstName}); !sent { + return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ + "success": false, + "message": "failed to send email to student", + }) + } return c.Status(fiber.StatusOK).JSON(fiber.Map{ "success": true, @@ -422,11 +428,10 @@ func ResetStudentPassword(c *fiber.Ctx) error { receiver := student.PersonalData.Email r := NewRequest([]string{receiver}, subject) - if err := r.Send("./templates/passwordChanged.html", map[string]string{"username": student.PersonalData.FirstName, "password": tempPass}); err { + if sent := r.Send("./templates/passwordChanged.html", map[string]string{"username": student.PersonalData.FirstName, "password": tempPass}); !sent { return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ "success": false, "message": "Could not send password to students email", - "error": err, }) } @@ -1008,6 +1013,7 @@ func RemoveStudentsDisabled(c *fiber.Ctx) error { update := bson.M{ "$set": bson.M{ "accountdata.accountdisabled": false, + "accountdata.alerted": false, "accountdata.attempts": 0, "updated_at": update_time, }, @@ -1022,7 +1028,7 @@ func RemoveStudentsDisabled(c *fiber.Ctx) error { cancel() return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ "success": false, - "message": "the student account could not be re-enabled", + "message": "the student account could not be enabled", "error": updateErr, }) } @@ -1271,11 +1277,10 @@ func UpdateTeacherPassword(c *fiber.Ctx) error { receiver := teacher.PersonalData.Email r := NewRequest([]string{receiver}, subject) - if err := r.Send("./templates/selfPasswordChanged.html", map[string]string{"username": teacher.PersonalData.FirstName}); err { + if sent := r.Send("./templates/selfPasswordChanged.html", map[string]string{"username": teacher.PersonalData.FirstName}); !sent { return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ "success": false, "message": "Could not send password to teachers email", - "error": err, }) } @@ -1356,11 +1361,10 @@ func ResetTeacherPassword(c *fiber.Ctx) error { receiver := teacher.PersonalData.Email r := NewRequest([]string{receiver}, subject) - if err := r.Send("./templates/passwordChanged.html", map[string]string{"username": teacher.PersonalData.FirstName, "password": tempPass}); err { + if sent := r.Send("./templates/passwordChanged.html", map[string]string{"username": teacher.PersonalData.FirstName, "password": tempPass}); !sent { return c.Status(fiber.StatusInternalServerError).JSON(fiber.Map{ "success": false, "message": "Could not send password to teachers email", - "error": err, }) } diff --git a/models/studentModel.go b/models/studentModel.go index e4bef65..474ecf7 100644 --- a/models/studentModel.go +++ b/models/studentModel.go @@ -48,6 +48,7 @@ type Student struct { SchoolEmail string `json:"schoolemail"` Password string `json:"-" validate:"min=10,max=32"` AccountDisabled bool `bson:"accountdisabled"` + Alerted bool `bson:"alerted"` TempPassword bool `json:"temppassword"` Attempts int `json:"attempts"` // login attempts max 5 HashHistory []string `json:"-"` // List of old hashed passwords (not including auto generated passwords) diff --git a/routes/routes.go b/routes/routes.go index 582b358..0eaa759 100644 --- a/routes/routes.go +++ b/routes/routes.go @@ -74,8 +74,8 @@ func Setup(app *fiber.App) { // General Command Handling app.Post(routerPrefix+"/admin/updateLockerCombo", controllers.UpdateLockerCombo) - app.Post(routerPrefix+"/admin/renableStudent", controllers.RemoveStudentsDisabled) - app.Post(routerPrefix+"/admin/renableTeacher", controllers.RemoveTeachersDisabled) + app.Post(routerPrefix+"/admin/enableStudent", controllers.RemoveStudentsDisabled) + app.Post(routerPrefix+"/admin/enableTeacher", controllers.RemoveTeachersDisabled) // Delete Handler app.Post(routerPrefix+"/remove/student", controllers.RemoveStudent)