Backend Frontend Merge
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
package com.example.backend;
|
||||
|
||||
import org.springframework.boot.SpringApplication;
|
||||
import org.springframework.boot.autoconfigure.SpringBootApplication;
|
||||
|
||||
@SpringBootApplication
|
||||
public class BackendApplication
|
||||
{
|
||||
|
||||
public static void main(String[] args)
|
||||
{
|
||||
SpringApplication.run(BackendApplication.class, args);
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,461 @@
|
||||
package com.example.backend.anwprj;
|
||||
|
||||
import com.example.backend.anwprj.Encryption.RSA;
|
||||
import com.example.backend.anwprj.Days.Day;
|
||||
import com.example.backend.anwprj.Entries.Entry;
|
||||
import com.example.backend.anwprj.Semesters.Semester;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
|
||||
import java.sql.*;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
public class DataBaseHandler
|
||||
{
|
||||
//singleton instance of database handler
|
||||
private static DataBaseHandler instance = null;
|
||||
|
||||
public static DataBaseHandler getInstance()
|
||||
{
|
||||
if (instance == null)
|
||||
{
|
||||
instance = new DataBaseHandler();
|
||||
}
|
||||
|
||||
return instance;
|
||||
}
|
||||
|
||||
//connection to the database
|
||||
private Connection connection;
|
||||
//sql statement
|
||||
private Statement st;
|
||||
private boolean encrypted = false;
|
||||
|
||||
public DataBaseHandler()
|
||||
{
|
||||
try
|
||||
{
|
||||
//connect to the local database
|
||||
connection = DriverManager.getConnection("jdbc:h2:./database", "adm", "73bgjfdsfJ!934");
|
||||
st = connection.createStatement();
|
||||
} catch (SQLException e)
|
||||
{
|
||||
System.out.println("No Connection!");
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
TEMPPPPPP
|
||||
*/
|
||||
public static class Week
|
||||
{
|
||||
public int semesterid, id, weeknumber;
|
||||
|
||||
public Week(int id, int semesterid, int weeknumber)
|
||||
{
|
||||
this.semesterid = semesterid;
|
||||
this.weeknumber = weeknumber;
|
||||
this.id = id;
|
||||
}
|
||||
}
|
||||
public Week addWeek(Week week)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("insert into weeks (semesterid, weeknumber) values (" + week.semesterid + ", " + week.weeknumber + ")");
|
||||
return getWeek(week.semesterid, week.weeknumber);
|
||||
} catch (SQLException e)
|
||||
{
|
||||
throw new RuntimeException(e);
|
||||
}
|
||||
}
|
||||
|
||||
public Week getWeek(int semesterid, int weeknumber)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select w.* from weeks w, semester s where s.id=" + semesterid + " and " + "w.weeknumber=" + weeknumber);
|
||||
rs.next();
|
||||
return new Week(rs.getInt("id"), rs.getInt("semesterid"), rs.getInt("weeknumber"));
|
||||
} catch (SQLException e)
|
||||
{
|
||||
throw new RuntimeException(e);
|
||||
}
|
||||
}
|
||||
|
||||
public Week getWeekById(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from weeks where id=" + id);
|
||||
rs.next();
|
||||
return new Week(rs.getInt("id"), rs.getInt("semesterid"), rs.getInt("weeknumber"));
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
TEMP END!!!!!!!!!!!!
|
||||
*/
|
||||
/**
|
||||
DAYS
|
||||
*/
|
||||
public Day addDay(Day day)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("insert into days (dayinweek, weekid) values (" + day.getDayinweek() + ", " + day.getWeekid() + ")");
|
||||
Week w = getWeekById(day.getWeekid());
|
||||
return getDay(day.getDayinweek(), w.weeknumber, w.semesterid);
|
||||
} catch (SQLException e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Day getDay(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from days where id=" + id);
|
||||
|
||||
return resultSetToDay(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Day getDay(int dayinweek, int weeknumber, int semesterid)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select d.* from days d, weeks w, semester s " +
|
||||
"where d.weekid = w.id and " +
|
||||
"w.semesterid = s.id and " +
|
||||
"d.dayinweek = " + dayinweek + " and " +
|
||||
"w.weeknumber = " + weeknumber + " and " +
|
||||
"s.id = " + semesterid);
|
||||
|
||||
return resultSetToDay(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
private Day resultSetToDay(ResultSet rs)
|
||||
{
|
||||
try
|
||||
{
|
||||
rs.next();
|
||||
|
||||
return new Day(
|
||||
rs.getInt("id"),
|
||||
rs.getInt("dayinweek"),
|
||||
rs.getInt("weekid")
|
||||
);
|
||||
} catch (SQLException e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
ENTRIES
|
||||
*/
|
||||
//method that returns all entries of a day based on the given parameters
|
||||
public Entry[] getEntries(int dayinweek, int weeknumber, int semesterid, User user)
|
||||
{
|
||||
try
|
||||
{
|
||||
//search the correct data in the database
|
||||
ResultSet rs = st.executeQuery("select distinct e.id, e.dayid, e.usercreatedbyid, e.timestart, e.timeend, e.info " +
|
||||
"from entries e, days d, weeks w, semester s " +
|
||||
"where e.dayid = d.id and " +
|
||||
"d.weekid = w.id and " +
|
||||
"w.semesterid = s.id and " +
|
||||
"d.dayinweek = " + dayinweek + " and " +
|
||||
"w.weeknumber = " + weeknumber + " and " +
|
||||
"s.id = " + semesterid);
|
||||
|
||||
|
||||
int editable = 0;
|
||||
|
||||
//a temporary list to save entry objects in
|
||||
List<Entry> temp = new ArrayList<>();
|
||||
//while there a still entries for the day
|
||||
while(rs.next())
|
||||
{
|
||||
editable = 0;
|
||||
//if entry has been created by the requesting user set the entry to editable (or the user is admin)
|
||||
if(rs.getInt("usercreatedbyid") == user.getId() || user.getPermissions() == 1)
|
||||
{
|
||||
editable = 1;
|
||||
}
|
||||
|
||||
temp.add(
|
||||
new Entry(
|
||||
rs.getInt("id"),
|
||||
rs.getInt("dayid"),
|
||||
rs.getInt("usercreatedbyid"),
|
||||
rs.getInt("timestart"),
|
||||
rs.getInt("timeend"),
|
||||
rs.getString("info"),
|
||||
editable
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
//return the temporary list as an array
|
||||
return temp.toArray(new Entry[0]);
|
||||
|
||||
} catch (SQLException e)
|
||||
{
|
||||
throw new RuntimeException(e);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
SEMESTER
|
||||
*/
|
||||
//get a semester object by its name
|
||||
public Semester getSemester(String name)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from SEMESTER where name = '" + name + "'");
|
||||
return resultSetToSemester(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Semester getSemester(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from semester where id=" + id);
|
||||
return resultSetToSemester(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
//write a new semester to the database returns if process was successful
|
||||
public Semester addSemester(Semester s)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("insert into SEMESTER (startweeknumber, endweeknumber, name, startyear, endyear) values (" + s.getStartweeknumber() + ", " + s.getEndweeknumber() + ", '" + s.getName() + "', " + s.getStartyear() + ", " + s.getEndyear() + ")");
|
||||
return getSemester(s.getName());
|
||||
|
||||
} catch (Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Semester updateSemester(Semester semester)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("update semester set startweeknumber=" + semester.getStartweeknumber() + ", " +
|
||||
"endweeknumber=" + semester.getEndweeknumber() + ", " +
|
||||
"name='" + semester.getName() + "', " +
|
||||
"startyear=" + semester.getStartyear() + ", " +
|
||||
"endyear=" + semester.getEndyear() + " where id=" + semester.getId());
|
||||
|
||||
return getSemester(semester.getId());
|
||||
} catch (SQLException e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Semester resultSetToSemester(ResultSet rs)
|
||||
{
|
||||
try
|
||||
{
|
||||
rs.next();
|
||||
return new Semester(
|
||||
rs.getInt("id"),
|
||||
rs.getInt("startweeknumber"),
|
||||
rs.getInt("endweeknumber"),
|
||||
rs.getString("name"),
|
||||
rs.getInt("startyear"),
|
||||
rs.getInt("endyear")
|
||||
);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
USER
|
||||
*/
|
||||
//get a user object by mail and password from the database
|
||||
public User getUser(String mail, String password)
|
||||
{
|
||||
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from users where mail = '" + mail + "' and password = '" + password + "'");
|
||||
return resultSetToUser(rs);
|
||||
} catch (Exception e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
public User getUser(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from users where id=" + id);
|
||||
return resultSetToUser(rs);
|
||||
} catch (Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public User getUser(String mail)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from users where mail='" + mail + "'");
|
||||
User u = resultSetToUser(rs);
|
||||
if(u != null) u.clearOutPassword();
|
||||
|
||||
return u;
|
||||
} catch (SQLException e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public User resultSetToUser(ResultSet rs)
|
||||
{
|
||||
try
|
||||
{
|
||||
rs.next();
|
||||
return new User(
|
||||
rs.getInt("id"),
|
||||
rs.getString("firstname"),
|
||||
rs.getString("lastname"),
|
||||
rs.getString("mail"),
|
||||
rs.getString("password"),
|
||||
rs.getInt("permission")
|
||||
);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
//add a new user object to the database returns if process was successful
|
||||
public User addUser(User user)
|
||||
{
|
||||
//check if mail and passwort (key user information) is given
|
||||
if (user.getMail() == null || user.getPassword() == null)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
|
||||
try
|
||||
{
|
||||
String password = user.getPassword();
|
||||
if(encrypted)
|
||||
{
|
||||
RSA rsa = RSA.getInstance();
|
||||
byte[] psw = rsa.loadByteArray(password);
|
||||
try {
|
||||
password = rsa.decrypt(psw);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
st.executeUpdate("insert into users (firstname, lastname, mail, password, permission) values (" + "'" + user.getFirstName() + "', '" + user.getLastName() + "', '" + user.getMail() + "', '" + password + "', " + 0 + ")");
|
||||
return getUser(user.getMail(), user.getPassword());
|
||||
} catch (Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
public User updateUser(User user, int id, boolean elevationRequestByAdmin)
|
||||
{
|
||||
try
|
||||
{
|
||||
String password = user.getPassword();
|
||||
if(encrypted)
|
||||
{
|
||||
RSA rsa = RSA.getInstance();
|
||||
byte[] psw = rsa.loadByteArray(password);
|
||||
try {
|
||||
password = rsa.decrypt(psw);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
|
||||
if(!elevationRequestByAdmin)
|
||||
{
|
||||
st.executeUpdate("update users set " +
|
||||
"firstname='" + user.getFirstName() + "', " +
|
||||
"lastname='" + user.getLastName() + "', " +
|
||||
"mail='" + user.getMail() + "', " +
|
||||
"password='" + password + "' " +
|
||||
"where id=" + id);
|
||||
}
|
||||
else
|
||||
{
|
||||
st.executeUpdate("update users set " +
|
||||
"firstname='" + user.getFirstName() + "', " +
|
||||
"lastname='" + user.getLastName() + "', " +
|
||||
"mail='" + user.getMail() + "', " +
|
||||
"password='" + password + "'," +
|
||||
"permission=" + user.getPermissions() +
|
||||
"where id=" + id);
|
||||
}
|
||||
|
||||
return getUser(id);
|
||||
} catch (SQLException e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public boolean deleteUser(String mail)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("delete from users where mail='" + mail + "'");
|
||||
return true;
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,30 @@
|
||||
package com.example.backend.anwprj.Days;
|
||||
|
||||
public class Day
|
||||
{
|
||||
private int id;
|
||||
private int dayinweek;
|
||||
private int weekid;
|
||||
|
||||
public Day(int id, int dayinweek, int weekid)
|
||||
{
|
||||
this.id = id;
|
||||
this.dayinweek = dayinweek;
|
||||
this.weekid = weekid;
|
||||
}
|
||||
|
||||
public int getId()
|
||||
{
|
||||
return id;
|
||||
}
|
||||
|
||||
public int getDayinweek()
|
||||
{
|
||||
return dayinweek;
|
||||
}
|
||||
|
||||
public int getWeekid()
|
||||
{
|
||||
return weekid;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
package com.example.backend.anwprj.Encryption;
|
||||
|
||||
import javax.crypto.Cipher;
|
||||
import java.io.*;
|
||||
import java.nio.charset.StandardCharsets;
|
||||
import java.security.*;
|
||||
|
||||
public class RSA {
|
||||
|
||||
private PublicKey publicKey;
|
||||
private PrivateKey privateKey;
|
||||
|
||||
private static RSA instance = null;
|
||||
|
||||
public static RSA getInstance()
|
||||
{
|
||||
if(instance == null)
|
||||
{
|
||||
instance = new RSA();
|
||||
}
|
||||
|
||||
return instance;
|
||||
}
|
||||
|
||||
private RSA(){}
|
||||
|
||||
public String decrypt(byte[] text) throws Exception
|
||||
{
|
||||
readKeyPairs();
|
||||
var cipher = Cipher.getInstance("RSA/ECB/PKCS1Padding");
|
||||
cipher.init(Cipher.DECRYPT_MODE, privateKey);
|
||||
var plainText = cipher.doFinal(text);
|
||||
return new String(plainText, StandardCharsets.US_ASCII);
|
||||
}
|
||||
|
||||
private void readKeyPairs() throws Exception
|
||||
{
|
||||
var publicInput = new ObjectInputStream(new FileInputStream(new File("./public.kfs")));
|
||||
publicKey = (PublicKey) publicInput.readObject();
|
||||
publicInput.close();
|
||||
|
||||
var privateInput = new ObjectInputStream(new FileInputStream(new File("./private.kfs")));
|
||||
privateKey = (PrivateKey) privateInput.readObject();
|
||||
privateInput.close();
|
||||
}
|
||||
|
||||
public byte[] loadByteArray(String text)
|
||||
{
|
||||
String[] split = text.split(",");
|
||||
byte[] output = new byte[split.length];
|
||||
for(int i = 0; i < split.length; i++)
|
||||
{
|
||||
output[i] = Byte.parseByte(split[i]);
|
||||
}
|
||||
|
||||
return output;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,79 @@
|
||||
package com.example.backend.anwprj.Entries;
|
||||
|
||||
//entry data class
|
||||
public class Entry
|
||||
{
|
||||
private int id;
|
||||
private int dayid;
|
||||
private int usercreatedbyid;
|
||||
private int timestart;
|
||||
private int timeend;
|
||||
private String info;
|
||||
private int editable;
|
||||
|
||||
public Entry(int id, int dayid, int usercreatedbyid, int timestart, int timeend, String info, int editable)
|
||||
{
|
||||
this.id = id;
|
||||
this.dayid = dayid;
|
||||
this.usercreatedbyid = usercreatedbyid;
|
||||
this.timestart = timestart;
|
||||
this.timeend = timeend;
|
||||
this.info = info;
|
||||
this.editable = editable;
|
||||
}
|
||||
|
||||
public int getId()
|
||||
{
|
||||
return id;
|
||||
}
|
||||
|
||||
public int getDayid()
|
||||
{
|
||||
return dayid;
|
||||
}
|
||||
|
||||
public int getUsercreatedbyid()
|
||||
{
|
||||
return usercreatedbyid;
|
||||
}
|
||||
|
||||
public int getTimestart()
|
||||
{
|
||||
return timestart;
|
||||
}
|
||||
|
||||
public int getTimeend()
|
||||
{
|
||||
return timeend;
|
||||
}
|
||||
|
||||
public String getInfo()
|
||||
{
|
||||
return info;
|
||||
}
|
||||
|
||||
public void setDayid(int dayid)
|
||||
{
|
||||
this.dayid = dayid;
|
||||
}
|
||||
|
||||
public void setTimestart(int timestart)
|
||||
{
|
||||
this.timestart = timestart;
|
||||
}
|
||||
|
||||
public void setTimeend(int timeend)
|
||||
{
|
||||
this.timeend = timeend;
|
||||
}
|
||||
|
||||
public void setInfo(String info)
|
||||
{
|
||||
this.info = info;
|
||||
}
|
||||
|
||||
public int getEditable()
|
||||
{
|
||||
return editable;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,52 @@
|
||||
package com.example.backend.anwprj.Semesters;
|
||||
|
||||
//semester data class
|
||||
public class Semester
|
||||
{
|
||||
private int id;
|
||||
private int startweeknumber;
|
||||
private int endweeknumber;
|
||||
private String name;
|
||||
private int startyear;
|
||||
private int endyear;
|
||||
|
||||
public Semester(int id, int startweeknumber, int endweeknumber, String name, int startyear, int endyear)
|
||||
{
|
||||
this.id = id;
|
||||
this.startweeknumber = startweeknumber;
|
||||
this.endweeknumber = endweeknumber;
|
||||
this.name = name;
|
||||
this.startyear = startyear;
|
||||
this.endyear = endyear;
|
||||
}
|
||||
|
||||
public int getId()
|
||||
{
|
||||
return id;
|
||||
}
|
||||
|
||||
public int getStartweeknumber()
|
||||
{
|
||||
return startweeknumber;
|
||||
}
|
||||
|
||||
public int getEndweeknumber()
|
||||
{
|
||||
return endweeknumber;
|
||||
}
|
||||
|
||||
public String getName()
|
||||
{
|
||||
return name;
|
||||
}
|
||||
|
||||
public int getStartyear()
|
||||
{
|
||||
return startyear;
|
||||
}
|
||||
|
||||
public int getEndyear()
|
||||
{
|
||||
return endyear;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,57 @@
|
||||
package com.example.backend.anwprj.Users;
|
||||
|
||||
//user data class
|
||||
public class User
|
||||
{
|
||||
private int id;
|
||||
private String firstName;
|
||||
private String lastName;
|
||||
private String mail;
|
||||
private String password;
|
||||
private int permissions;
|
||||
|
||||
public User(int id, String firstName, String lastName, String mail, String password, int permissions)
|
||||
{
|
||||
this.id = id;
|
||||
this.firstName = firstName;
|
||||
this.lastName = lastName;
|
||||
this.mail = mail;
|
||||
this.password = password;
|
||||
this.permissions = permissions;
|
||||
}
|
||||
|
||||
public int getId()
|
||||
{
|
||||
return id;
|
||||
}
|
||||
|
||||
public String getFirstName()
|
||||
{
|
||||
return firstName;
|
||||
}
|
||||
|
||||
public String getLastName()
|
||||
{
|
||||
return lastName;
|
||||
}
|
||||
|
||||
public String getMail()
|
||||
{
|
||||
return mail;
|
||||
}
|
||||
|
||||
public String getPassword()
|
||||
{
|
||||
return password;
|
||||
}
|
||||
|
||||
public int getPermissions()
|
||||
{
|
||||
return permissions;
|
||||
}
|
||||
|
||||
public void clearOutPassword()
|
||||
{
|
||||
password = "****";
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,20 @@
|
||||
package com.example.backend.anwprj.Users;
|
||||
|
||||
//mapping of the integer rights to enum
|
||||
public enum UserPermissions
|
||||
{
|
||||
self(0),
|
||||
admin(1);
|
||||
|
||||
private final int value;
|
||||
|
||||
public int getValue()
|
||||
{
|
||||
return value;
|
||||
}
|
||||
|
||||
private UserPermissions(int value)
|
||||
{
|
||||
this.value = value;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
package com.example.backend.anwprj.Users;
|
||||
|
||||
import com.example.backend.anwprj.DataBaseHandler;
|
||||
|
||||
import java.nio.charset.StandardCharsets;
|
||||
import java.util.HashMap;
|
||||
|
||||
public class UserSessionIDHandler
|
||||
{
|
||||
//stores mapping of session ids to users
|
||||
public static HashMap<String, User> mapping = new HashMap<>();
|
||||
|
||||
//returns a user object by its session id (ONLY FOR SERVER INTERNAL USE!)
|
||||
public static User getUserBySessionID(String sessionID)
|
||||
{
|
||||
return mapping.get(sessionID);
|
||||
}
|
||||
|
||||
public static boolean removeUser(String sessionID)
|
||||
{
|
||||
try
|
||||
{
|
||||
mapping.remove(sessionID);
|
||||
return true;
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
public static String addUser(String mail, String password)
|
||||
{
|
||||
//try to get user from database
|
||||
User user = DataBaseHandler.getInstance().getUser(mail, password);
|
||||
|
||||
//if user exists
|
||||
if(user != null)
|
||||
{
|
||||
//generate random session id based on ascii table
|
||||
byte[] id = new byte[100];
|
||||
|
||||
for(int i = 0; i < id.length; i++)
|
||||
{
|
||||
id[i] = (byte) (Math.random() * 26 + 64);
|
||||
}
|
||||
|
||||
String generatedString = new String(id, StandardCharsets.US_ASCII);
|
||||
|
||||
mapping.put(generatedString, user);
|
||||
|
||||
//makes user session expire after ca. 2h
|
||||
new java.util.Timer().schedule(new java.util.TimerTask(){
|
||||
|
||||
@Override
|
||||
public void run()
|
||||
{
|
||||
mapping.remove(generatedString);
|
||||
return;
|
||||
}
|
||||
}, 7500000);
|
||||
|
||||
return generatedString;
|
||||
}
|
||||
|
||||
return "";
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,60 @@
|
||||
package com.example.backend.anwprj.controller;
|
||||
|
||||
import com.example.backend.anwprj.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Days.Day;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserPermissions;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
@RestController
|
||||
public class DayController
|
||||
{
|
||||
|
||||
private DataBaseHandler db;
|
||||
|
||||
{
|
||||
db = DataBaseHandler.getInstance();
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/days")
|
||||
public ResponseEntity<Day> getDay(
|
||||
@RequestParam(name="sessionid") String sessionID,
|
||||
@RequestParam(name="dayinweek") int dayInWeek,
|
||||
@RequestParam(name="weeknumber") int weekNumber,
|
||||
@RequestParam(name="semesterid") int semesterID)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(u != null)
|
||||
{
|
||||
Day d = db.getDay(dayInWeek, weekNumber, semesterID);
|
||||
|
||||
if (d != null)
|
||||
{
|
||||
return new ResponseEntity<>(d, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@PostMapping("/days")
|
||||
public ResponseEntity<Day> addDay(@RequestBody Day day, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(u != null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
return new ResponseEntity<>(db.addDay(day), HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(null, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
package com.example.backend.anwprj.controller;
|
||||
|
||||
import com.example.backend.anwprj.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Entries.Entry;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
@RestController
|
||||
public class EntriesController
|
||||
{
|
||||
private DataBaseHandler db;
|
||||
|
||||
{
|
||||
db = DataBaseHandler.getInstance();
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/entries")
|
||||
public ResponseEntity<Entry[]> getEntries(
|
||||
@RequestParam(name = "sessionid") String sessionID,
|
||||
@RequestParam(name = "dayinweek") int dayinweek,
|
||||
@RequestParam(name = "weeknumber") int weeknumber,
|
||||
@RequestParam(name = "semesterid") int semesterid)
|
||||
{
|
||||
User user = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(user == null)
|
||||
{
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
Entry[] entries = db.getEntries(dayinweek, weeknumber, semesterid, user);
|
||||
return new ResponseEntity<>(entries, HttpStatus.OK);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@PostMapping("/entries")
|
||||
public ResponseEntity<Entry[]> postEntries(@RequestBody Entry[] entries, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,105 @@
|
||||
package com.example.backend.anwprj.controller;
|
||||
|
||||
import com.example.backend.anwprj.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Semesters.Semester;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserPermissions;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
@RestController
|
||||
public class SemesterController
|
||||
{
|
||||
//reference to the database handler
|
||||
private DataBaseHandler db;
|
||||
|
||||
{
|
||||
db = DataBaseHandler.getInstance();
|
||||
}
|
||||
|
||||
//a new semester add is requested (only allowed for admin users)
|
||||
@CrossOrigin
|
||||
@PostMapping("/semester")
|
||||
public ResponseEntity<Semester> addSemester(@RequestBody Semester semester, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User user = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(user.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
Semester s = db.addSemester(semester);
|
||||
if(s != null)
|
||||
{
|
||||
return new ResponseEntity<>(s, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(s, HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
//get a semester object by its name
|
||||
@CrossOrigin
|
||||
@GetMapping("/semester")
|
||||
public ResponseEntity<Semester> getSemester(@RequestParam(name="name") String name, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(u != null)
|
||||
{
|
||||
Semester s = db.getSemester(name);
|
||||
if (s != null)
|
||||
{
|
||||
return new ResponseEntity<>(s, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/semester/id")
|
||||
public ResponseEntity<Semester> getSemester(@RequestParam(name="id") int id, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(u != null)
|
||||
{
|
||||
Semester s = db.getSemester(id);
|
||||
if(s != null)
|
||||
{
|
||||
return new ResponseEntity<>(s, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@PutMapping("/semester")
|
||||
public ResponseEntity<Semester> updateSemester(@RequestBody Semester semester, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
if(u != null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
System.out.println(semester.getId());
|
||||
Semester s = db.updateSemester(semester);
|
||||
|
||||
if(s != null)
|
||||
{
|
||||
return new ResponseEntity<>(s, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,154 @@
|
||||
package com.example.backend.anwprj.controller;
|
||||
|
||||
import com.example.backend.anwprj.Encryption.RSA;
|
||||
import com.example.backend.anwprj.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserPermissions;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
@RestController
|
||||
public class UserController {
|
||||
//reference to the database handler
|
||||
private DataBaseHandler db;
|
||||
|
||||
{
|
||||
db = DataBaseHandler.getInstance();
|
||||
}
|
||||
|
||||
|
||||
//adds a new user to the database (cannot create an admin user)
|
||||
@CrossOrigin
|
||||
@PostMapping("/users")
|
||||
public ResponseEntity<String> addUser(@RequestBody User user) {
|
||||
User checkUser = db.getUser(user.getMail());
|
||||
|
||||
if (checkUser != null) {
|
||||
return new ResponseEntity<>("mail", HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
//if user was successfully added to database
|
||||
User u = db.addUser(user);
|
||||
|
||||
if (u != null) {
|
||||
//generate a session id
|
||||
return new ResponseEntity<String>(UserSessionIDHandler.addUser(user.getMail(), user.getPassword()), HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<String>(HttpStatus.BAD_REQUEST);
|
||||
}
|
||||
|
||||
//a user wants to login
|
||||
@CrossOrigin
|
||||
@GetMapping("/users")
|
||||
public ResponseEntity<String> login(@RequestParam(name = "mail") String mail, @RequestParam(name = "password") String password) {
|
||||
//generate a session id for the user trying to login
|
||||
boolean isEncrypted = true;
|
||||
if(isEncrypted)
|
||||
{
|
||||
RSA rsa = RSA.getInstance();
|
||||
byte[] psw = rsa.loadByteArray(password);
|
||||
try {
|
||||
password = rsa.decrypt(psw);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
|
||||
String sessionID = UserSessionIDHandler.addUser(mail, password);
|
||||
|
||||
return new ResponseEntity<>(sessionID, HttpStatus.OK);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/users/logout")
|
||||
public ResponseEntity<Boolean> logout(@RequestParam(name = "sessionid") String sessionID) {
|
||||
boolean success = UserSessionIDHandler.removeUser(sessionID);
|
||||
return new ResponseEntity<>(success, HttpStatus.OK);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@PutMapping("/users")
|
||||
public ResponseEntity<Boolean> updateUser(@RequestParam(name = "sessionid") String sessionID, @RequestBody User u, @RequestParam(name = "mail") String mail) {
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if (sessionUser != null) {
|
||||
if (sessionUser.getMail().equals(mail) || sessionUser.getPermissions() == UserPermissions.admin.getValue()) {
|
||||
System.out.println(sessionUser.getId());
|
||||
|
||||
User resultingUser = db.updateUser(u, sessionUser.getId(), false);
|
||||
|
||||
if (resultingUser != null) {
|
||||
UserSessionIDHandler.removeUser(sessionID);
|
||||
return new ResponseEntity<>(true, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.NOT_FOUND);
|
||||
}
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@PutMapping("/users/elevate")
|
||||
public ResponseEntity<Boolean> elevateUser(
|
||||
@RequestParam(name = "sessionid") String sessionID,
|
||||
@RequestParam(name = "mail") String mail,
|
||||
@RequestParam(name = "permission") int permission)
|
||||
{
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(sessionUser != null && sessionUser.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
System.out.println("test");
|
||||
User userToUpdateTemplate = db.getUser(mail);
|
||||
User userToUpdate = new User(userToUpdateTemplate.getId(), userToUpdateTemplate.getFirstName(), userToUpdateTemplate.getLastName(),
|
||||
userToUpdateTemplate.getMail(), userToUpdateTemplate.getPassword(), permission);
|
||||
|
||||
User resultingUser = db.updateUser(userToUpdate, userToUpdate.getId(), true);
|
||||
|
||||
if(resultingUser == null)
|
||||
{
|
||||
return new ResponseEntity<>(false, HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(true, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/users/data")
|
||||
public ResponseEntity<User> getUserData(
|
||||
@RequestParam(name = "sessionid") String sessionID,
|
||||
@RequestParam(name = "mail") String mail) {
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if (sessionUser != null) {
|
||||
System.out.println(sessionUser.getMail() + " " + mail);
|
||||
|
||||
if (sessionUser.getMail().equals(mail) || sessionUser.getPermissions() == UserPermissions.admin.getValue()) {
|
||||
User searchedUser = db.getUser(mail);
|
||||
return new ResponseEntity<>(searchedUser, HttpStatus.OK);
|
||||
}
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@DeleteMapping("/users")
|
||||
public ResponseEntity<Boolean> deleteUser(@RequestParam(name = "sessionid") String sessionID, @RequestParam(name = "mail") String mail) {
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if (sessionUser != null && sessionUser.getPermissions() == UserPermissions.admin.getValue()) {
|
||||
return new ResponseEntity<>(db.deleteUser(mail), HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
|
||||
Reference in New Issue
Block a user