@@ -0,0 +1,15 @@
|
||||
package com.example.backend;
|
||||
|
||||
import org.springframework.boot.SpringApplication;
|
||||
import org.springframework.boot.autoconfigure.SpringBootApplication;
|
||||
|
||||
@SpringBootApplication
|
||||
public class BackendApplication
|
||||
{
|
||||
|
||||
public static void main(String[] args)
|
||||
{
|
||||
SpringApplication.run(BackendApplication.class, args);
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,598 @@
|
||||
package com.example.backend.anwprj.Database;
|
||||
|
||||
import com.example.backend.discard.Encryption.RSA;
|
||||
import com.example.backend.anwprj.Entries.Entry;
|
||||
import com.example.backend.anwprj.Semesters.Semester;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Module.Module;
|
||||
|
||||
import java.sql.*;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
public class DataBaseHandler
|
||||
{
|
||||
//singleton instance of database handler
|
||||
private static DataBaseHandler instance = null;
|
||||
|
||||
public static DataBaseHandler getInstance()
|
||||
{
|
||||
if (instance == null)
|
||||
{
|
||||
instance = new DataBaseHandler();
|
||||
}
|
||||
|
||||
return instance;
|
||||
}
|
||||
|
||||
//connection to the database
|
||||
private Connection connection;
|
||||
//sql statement
|
||||
private Statement st;
|
||||
private boolean encrypted = false;
|
||||
|
||||
public DataBaseHandler()
|
||||
{
|
||||
try
|
||||
{
|
||||
//connect to the local database
|
||||
connection = DriverManager.getConnection("jdbc:h2:./database", "adm", "73bgjfdsfJ!934");
|
||||
st = connection.createStatement();
|
||||
} catch (SQLException e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
ENTRIES
|
||||
*/
|
||||
public void addEntry(Entry entry)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("insert into entries (daynumber, yearnumber, semesterid, usercreatedbyid, timestart, timeend, info) values (" +
|
||||
entry.getDaynumber() + ", " + entry.getYearnumber() + ", " + entry.getSemesterid() + ", " +
|
||||
entry.getUsercreatedbyid() + ", " + entry.getTimestart() + ", " + entry.getTimeend() + ", '" + entry.getInfo() + "')"
|
||||
);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
|
||||
public Entry[][] getEntries(int semesterid, int daynumber, int yearnumber)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from entries where " +
|
||||
"semesterid=" + semesterid +
|
||||
" and yearnumber=" + yearnumber +
|
||||
" and daynumber between " + daynumber + " and " + daynumber + 6);
|
||||
|
||||
List<Entry> entryList = new ArrayList<>();
|
||||
Entry current = null;
|
||||
while((current = resultSetToEntry(rs)) != null)
|
||||
{
|
||||
entryList.add(current);
|
||||
}
|
||||
|
||||
Entry[][] entries = new Entry[6][20];
|
||||
for(int i = 0; i < 6; i++)
|
||||
{
|
||||
int f = 0;
|
||||
|
||||
for(int j = 0; j < entryList.size(); j++)
|
||||
{
|
||||
if(entryList.get(j).getDaynumber() == i + daynumber)
|
||||
{
|
||||
entries[i][f] = entryList.get(j);
|
||||
f++;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return entries;
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public void deleteEntry(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("delete from entries where id=" + id);
|
||||
}
|
||||
catch (Exception e)
|
||||
{
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
public void updateEntry(Entry entry)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("update entries set timeend=" + entry.getTimeend() + ", timestart=" + entry.getTimestart() + " where id=" + entry.getId());
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
public Entry resultSetToEntry(ResultSet rs)
|
||||
{
|
||||
try
|
||||
{
|
||||
rs.next();
|
||||
return new Entry(
|
||||
rs.getInt("id"),
|
||||
rs.getInt("daynumber"),
|
||||
rs.getInt("yearnumber"),
|
||||
rs.getInt("usercreatedbyid"),
|
||||
rs.getInt("timestart"),
|
||||
rs.getInt("timeend"),
|
||||
rs.getInt("semesterid"),
|
||||
rs.getString("info")
|
||||
);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
SEMESTER
|
||||
*/
|
||||
//get a semester object by its name
|
||||
public Semester getSemester(String name)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from SEMESTER where name = '" + name + "'");
|
||||
return resultSetToSemester(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Semester getSemester(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from semester where id=" + id);
|
||||
return resultSetToSemester(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
//write a new semester to the database returns if process was successful
|
||||
public Semester addSemester(Semester s)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("insert into SEMESTER (startday, endday, name, startyear, endyear) values (" + s.getStartday() + ", " + s.getEndday() + ", '" + s.getName() + "', " + s.getStartyear() + ", " + s.getEndyear() + ")");
|
||||
return getSemester(s.getName());
|
||||
|
||||
} catch (Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Semester[] getAllSemesters()
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from semester");
|
||||
List<Semester> semestersList = new ArrayList<>();
|
||||
Semester s = null;
|
||||
while((s = resultSetToSemester(rs)) != null)
|
||||
{
|
||||
semestersList.add(s);
|
||||
}
|
||||
|
||||
return semestersList.toArray(new Semester[0]);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Semester updateSemester(Semester semester)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("update semester set startday=" + semester.getStartday() + ", " +
|
||||
"endday=" + semester.getEndday() + ", " +
|
||||
"name='" + semester.getName() + "', " +
|
||||
"startyear=" + semester.getStartyear() + ", " +
|
||||
"endyear=" + semester.getEndyear() + " where id=" + semester.getId());
|
||||
|
||||
return getSemester(semester.getId());
|
||||
} catch (SQLException e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public void deleteSemester(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("DELETE FROM modules WHERE semesterid=" + id);
|
||||
|
||||
st.executeUpdate("delete from semester where id=" + id);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
public Semester resultSetToSemester(ResultSet rs)
|
||||
{
|
||||
try
|
||||
{
|
||||
rs.next();
|
||||
return new Semester(
|
||||
rs.getInt("id"),
|
||||
rs.getInt("startday"),
|
||||
rs.getInt("endday"),
|
||||
rs.getString("name"),
|
||||
rs.getInt("startyear"),
|
||||
rs.getInt("endyear")
|
||||
);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
MODULE
|
||||
*/
|
||||
|
||||
//get a module object by its id
|
||||
public Module getModule(int id) {
|
||||
try {
|
||||
ResultSet rs = st.executeQuery("SELECT * FROM modules WHERE id=" + id);
|
||||
return resultSetToModule(rs);
|
||||
}
|
||||
catch (Exception ex) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Module getModule(int userid, int semesterid)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from modules where userid=" + userid + " and semesterid=" + semesterid);
|
||||
|
||||
return resultSetToModule(rs);
|
||||
}
|
||||
catch (Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
//get module objects by its semester and its lecturer
|
||||
public Module[] getModules(int userid) {
|
||||
try {
|
||||
ResultSet rs = st.executeQuery("SELECT * FROM modules WHERE userid = " + userid);
|
||||
List<Module> moduleList = new ArrayList<>();
|
||||
Module m = null;
|
||||
while((m = resultSetToModule(rs)) != null)
|
||||
{
|
||||
moduleList.add(m);
|
||||
}
|
||||
|
||||
return moduleList.toArray(new Module[0]);
|
||||
|
||||
}
|
||||
catch (Exception ex){
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Module addModule(Module m)
|
||||
{
|
||||
try {
|
||||
st.executeUpdate("insert into modules (userid, semesterid, name, activated) " +
|
||||
"Values (" + m.getUserid() + ", " + m.getsemesterid() + ", '" + m.getName() + "', " + m.getActivated() + ")");
|
||||
return getModule(m.getUserid(), m.getsemesterid());
|
||||
|
||||
}
|
||||
catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Module[] getAllModules() {
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("SELECT * FROM modules");
|
||||
List<Module> moduleList = new ArrayList<>();
|
||||
Module m = null;
|
||||
while((m = resultSetToModule(rs)) != null)
|
||||
{
|
||||
moduleList.add(m);
|
||||
}
|
||||
|
||||
return moduleList.toArray(new Module[0]);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Module getModuleBySemesterUserID(int userid, int semesterid)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from modules where userid=" + userid + " and semesterid=" + semesterid);
|
||||
return resultSetToModule(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return new Module(-1, 0, 0, "", 0);
|
||||
}
|
||||
}
|
||||
|
||||
public Module updateModule(Module m)
|
||||
{
|
||||
|
||||
try {
|
||||
Module module = getModule(m.getUserid(), m.getsemesterid());
|
||||
if(module == null)
|
||||
{
|
||||
addModule(m);
|
||||
}
|
||||
else
|
||||
{
|
||||
st.executeUpdate("update modules set activated=" + m.getActivated() + ", semesterid=" + m.getsemesterid() + ", name='" + m.getName() + "' where id=" + module.getid());
|
||||
}
|
||||
|
||||
Module test = getModule(m.getUserid(), m.getsemesterid());
|
||||
System.out.println(test.getActivated());
|
||||
return test;
|
||||
}
|
||||
catch (SQLException ex) {
|
||||
ex.printStackTrace();
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public boolean deleteModule(int semesterid, int userid)
|
||||
{
|
||||
try {
|
||||
st.executeUpdate("delete from modules where semesterid=" + semesterid + " and userid=" + userid);
|
||||
return true;
|
||||
}
|
||||
catch(Exception ex) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
public Module resultSetToModule(ResultSet rs) {
|
||||
try {
|
||||
rs.next();
|
||||
return new Module(
|
||||
rs.getInt("id"),
|
||||
rs.getInt("userid"),
|
||||
rs.getInt("semesterid"),
|
||||
rs.getString("name"),
|
||||
rs.getInt("activated"));
|
||||
}
|
||||
catch (Exception ex) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
USER
|
||||
*/
|
||||
|
||||
//Alle User, die nicht admin sind
|
||||
public User[] getAllUsers()
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from users where permission=0");
|
||||
|
||||
User u = null;
|
||||
|
||||
List<User> output = new ArrayList<>();
|
||||
|
||||
while((u = resultSetToUser(rs)) != null)
|
||||
{
|
||||
u.clearOutPassword();
|
||||
output.add(u);
|
||||
}
|
||||
|
||||
return output.toArray(new User[0]);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
//einen User
|
||||
public User getUser(String mail, String password)
|
||||
{
|
||||
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from users where mail = '" + mail + "' and password = '" + password + "'");
|
||||
return resultSetToUser(rs);
|
||||
} catch (Exception e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
public User getUser(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from users where id=" + id);
|
||||
return resultSetToUser(rs);
|
||||
} catch (Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public User getUser(String mail)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from users where mail='" + mail + "'");
|
||||
User u = resultSetToUser(rs);
|
||||
if(u != null) u.clearOutPassword();
|
||||
|
||||
return u;
|
||||
} catch (SQLException e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public User resultSetToUser(ResultSet rs)
|
||||
{
|
||||
try
|
||||
{
|
||||
rs.next();
|
||||
return new User(
|
||||
rs.getInt("id"),
|
||||
rs.getString("firstname"),
|
||||
rs.getString("lastname"),
|
||||
rs.getString("mail"),
|
||||
rs.getString("password"),
|
||||
rs.getInt("permission")
|
||||
);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
//add a new user object to the database returns if process was successful
|
||||
public User addUser(User user)
|
||||
{
|
||||
//check if mail and passwort (key user information) is given
|
||||
if (user.getMail() == null || user.getPassword() == null)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
|
||||
try
|
||||
{
|
||||
String password = user.getPassword();
|
||||
if(encrypted)
|
||||
{
|
||||
RSA rsa = RSA.getInstance();
|
||||
byte[] psw = rsa.loadByteArray(password);
|
||||
try {
|
||||
password = rsa.decrypt(psw);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
st.executeUpdate("insert into users (firstname, lastname, mail, password, permission) values (" + "'" + user.getFirstName() + "', '" + user.getLastName() + "', '" + user.getMail() + "', '" + password + "', " + 0 + ")");
|
||||
return getUser(user.getMail(), user.getPassword());
|
||||
} catch (Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
public User updateUser(User user, int id, boolean elevationRequestByAdmin)
|
||||
{
|
||||
try
|
||||
{
|
||||
String password = user.getPassword();
|
||||
if(encrypted)
|
||||
{
|
||||
RSA rsa = RSA.getInstance();
|
||||
byte[] psw = rsa.loadByteArray(password);
|
||||
try {
|
||||
password = rsa.decrypt(psw);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
|
||||
if(!elevationRequestByAdmin)
|
||||
{
|
||||
st.executeUpdate("update users set " +
|
||||
"firstname='" + user.getFirstName() + "', " +
|
||||
"lastname='" + user.getLastName() + "', " +
|
||||
"mail='" + user.getMail() + "', " +
|
||||
"password='" + password + "' " +
|
||||
"where id=" + id);
|
||||
}
|
||||
else
|
||||
{
|
||||
st.executeUpdate("update users set " +
|
||||
"firstname='" + user.getFirstName() + "', " +
|
||||
"lastname='" + user.getLastName() + "', " +
|
||||
"mail='" + user.getMail() + "', " +
|
||||
"password='" + password + "'," +
|
||||
"permission=" + user.getPermissions() +
|
||||
"where id=" + id);
|
||||
}
|
||||
|
||||
return getUser(id);
|
||||
} catch (SQLException e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public boolean deleteUser(String mail)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("SELECT id FROM user WHERE mail='" + mail + "'");
|
||||
rs.next();
|
||||
int id = rs.getInt("id");
|
||||
st.executeUpdate("DELETE FROM modules WHERE lecturerId = " + id);
|
||||
|
||||
st.executeUpdate("delete from users where mail='" + mail + "'");
|
||||
return true;
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
e.printStackTrace();
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,66 @@
|
||||
package com.example.backend.anwprj.Entries;
|
||||
|
||||
//entry data class
|
||||
public class Entry
|
||||
{
|
||||
private int id;
|
||||
private int daynumber;
|
||||
private int yearnumber;
|
||||
private int usercreatedbyid;
|
||||
private int timestart;
|
||||
private int timeend;
|
||||
private int semesterid;
|
||||
private String info;
|
||||
|
||||
public Entry(int id, int daynumber, int yearnumber, int usercreatedbyid, int timestart, int timeend, int semesterid, String info)
|
||||
{
|
||||
this.id = id;
|
||||
this.daynumber = daynumber;
|
||||
this.yearnumber = yearnumber;
|
||||
this.usercreatedbyid = usercreatedbyid;
|
||||
this.timestart = timestart;
|
||||
this.timeend = timeend;
|
||||
this.semesterid = semesterid;
|
||||
this.info = info;
|
||||
}
|
||||
|
||||
public int getId()
|
||||
{
|
||||
return id;
|
||||
}
|
||||
|
||||
public int getDaynumber()
|
||||
{
|
||||
return daynumber;
|
||||
}
|
||||
|
||||
public int getYearnumber()
|
||||
{
|
||||
return yearnumber;
|
||||
}
|
||||
|
||||
public int getUsercreatedbyid()
|
||||
{
|
||||
return usercreatedbyid;
|
||||
}
|
||||
|
||||
public int getTimestart()
|
||||
{
|
||||
return timestart;
|
||||
}
|
||||
|
||||
public int getTimeend()
|
||||
{
|
||||
return timeend;
|
||||
}
|
||||
|
||||
public int getSemesterid()
|
||||
{
|
||||
return semesterid;
|
||||
}
|
||||
|
||||
public String getInfo()
|
||||
{
|
||||
return info;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
package com.example.backend.anwprj.Module;
|
||||
|
||||
//module data class
|
||||
public class Module {
|
||||
private int id;
|
||||
private int userid;
|
||||
private int semesterid;
|
||||
private String name;
|
||||
private int activated;
|
||||
|
||||
|
||||
public Module(int id, int userid, int semesterid, String name, int activated)
|
||||
{
|
||||
this.id = id;
|
||||
this.userid = userid;
|
||||
this.semesterid = semesterid;
|
||||
this.name = name;
|
||||
this.activated = activated;
|
||||
}
|
||||
|
||||
public int getid() { return id; }
|
||||
|
||||
public int getUserid() { return userid; }
|
||||
|
||||
public int getsemesterid() { return semesterid; }
|
||||
|
||||
public String getName() { return name; }
|
||||
|
||||
public int getActivated() { return activated; }
|
||||
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
package com.example.backend.anwprj.Semesters;
|
||||
|
||||
//semester data class
|
||||
public class Semester
|
||||
{
|
||||
private int id;
|
||||
private int startday;
|
||||
private int endday;
|
||||
private String name;
|
||||
private int startyear;
|
||||
private int endyear;
|
||||
|
||||
public Semester(int id, int startday, int endday, String name, int startyear, int endyear) {
|
||||
this.id = id;
|
||||
this.startday = startday;
|
||||
this.endday = endday;
|
||||
this.name = name;
|
||||
this.startyear = startyear;
|
||||
this.endyear = endyear;
|
||||
}
|
||||
|
||||
public int getId() {
|
||||
return id;
|
||||
}
|
||||
|
||||
public int getStartday() {
|
||||
return startday;
|
||||
}
|
||||
|
||||
public int getEndday() {
|
||||
return endday;
|
||||
}
|
||||
|
||||
public String getName() {
|
||||
return name;
|
||||
}
|
||||
|
||||
public int getStartyear() {
|
||||
return startyear;
|
||||
}
|
||||
|
||||
public int getEndyear() {
|
||||
return endyear;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,57 @@
|
||||
package com.example.backend.anwprj.Users;
|
||||
|
||||
//user data class
|
||||
public class User
|
||||
{
|
||||
private int id;
|
||||
private String firstName;
|
||||
private String lastName;
|
||||
private String mail;
|
||||
private String password;
|
||||
private int permissions;
|
||||
|
||||
public User(int id, String firstName, String lastName, String mail, String password, int permissions)
|
||||
{
|
||||
this.id = id;
|
||||
this.firstName = firstName;
|
||||
this.lastName = lastName;
|
||||
this.mail = mail;
|
||||
this.password = password;
|
||||
this.permissions = permissions;
|
||||
}
|
||||
|
||||
public int getId()
|
||||
{
|
||||
return id;
|
||||
}
|
||||
|
||||
public String getFirstName()
|
||||
{
|
||||
return firstName;
|
||||
}
|
||||
|
||||
public String getLastName()
|
||||
{
|
||||
return lastName;
|
||||
}
|
||||
|
||||
public String getMail()
|
||||
{
|
||||
return mail;
|
||||
}
|
||||
|
||||
public String getPassword()
|
||||
{
|
||||
return password;
|
||||
}
|
||||
|
||||
public int getPermissions()
|
||||
{
|
||||
return permissions;
|
||||
}
|
||||
|
||||
public void clearOutPassword()
|
||||
{
|
||||
password = "****";
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,20 @@
|
||||
package com.example.backend.anwprj.Users;
|
||||
|
||||
//mapping of the integer rights to enum
|
||||
public enum UserPermissions
|
||||
{
|
||||
self(0),
|
||||
admin(1);
|
||||
|
||||
private final int value;
|
||||
|
||||
public int getValue()
|
||||
{
|
||||
return value;
|
||||
}
|
||||
|
||||
private UserPermissions(int value)
|
||||
{
|
||||
this.value = value;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
package com.example.backend.anwprj.Users;
|
||||
|
||||
import com.example.backend.anwprj.Database.DataBaseHandler;
|
||||
|
||||
import java.nio.charset.StandardCharsets;
|
||||
import java.util.HashMap;
|
||||
|
||||
public class UserSessionIDHandler
|
||||
{
|
||||
//stores mapping of session ids to users
|
||||
public static HashMap<String, User> mapping = new HashMap<>();
|
||||
|
||||
//returns a user object by its session id (ONLY FOR SERVER INTERNAL USE!)
|
||||
public static User getUserBySessionID(String sessionID)
|
||||
{
|
||||
return mapping.get(sessionID);
|
||||
}
|
||||
|
||||
public static boolean removeUser(String sessionID)
|
||||
{
|
||||
try
|
||||
{
|
||||
mapping.remove(sessionID);
|
||||
return true;
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
public static String addUser(String mail, String password)
|
||||
{
|
||||
//try to get user from database
|
||||
User user = DataBaseHandler.getInstance().getUser(mail, password);
|
||||
|
||||
//if user exists
|
||||
if(user != null)
|
||||
{
|
||||
//generate random session id based on ascii table
|
||||
byte[] id = new byte[100];
|
||||
|
||||
for(int i = 0; i < id.length; i++)
|
||||
{
|
||||
id[i] = (byte) (Math.random() * 26 + 64);
|
||||
}
|
||||
|
||||
String generatedString = new String(id, StandardCharsets.US_ASCII);
|
||||
|
||||
mapping.put(generatedString, user);
|
||||
|
||||
//makes user session expire after ca. 2h
|
||||
new java.util.Timer().schedule(new java.util.TimerTask(){
|
||||
|
||||
@Override
|
||||
public void run()
|
||||
{
|
||||
mapping.remove(generatedString);
|
||||
return;
|
||||
}
|
||||
}, 7500000);
|
||||
|
||||
return generatedString;
|
||||
}
|
||||
|
||||
return "failed";
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,102 @@
|
||||
package com.example.backend.anwprj.controller;
|
||||
|
||||
import com.example.backend.anwprj.Database.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Entries.Entry;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
@RestController
|
||||
public class EntriesController
|
||||
{
|
||||
private DataBaseHandler db;
|
||||
|
||||
{
|
||||
db = DataBaseHandler.getInstance();
|
||||
}
|
||||
|
||||
/**
|
||||
GET
|
||||
a set of entries for a week, based on the semester, the startdaynumber of the week and the year
|
||||
Every user is allowed
|
||||
*/
|
||||
@CrossOrigin
|
||||
@GetMapping("/entries")
|
||||
public ResponseEntity<Entry[][]> getEntries(@RequestParam(name = "semesterid") int semesterid,
|
||||
@RequestParam(name = "daynumber") int daynumber,
|
||||
@RequestParam(name = "yearnumber") int yearnumber,
|
||||
@RequestParam(name = "sessionid") String sessionid)
|
||||
{
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
|
||||
if (sessionUser != null)
|
||||
{
|
||||
return new ResponseEntity<>(db.getEntries(semesterid, daynumber, yearnumber), HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(null, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
/**
|
||||
POST
|
||||
A new entry to the database. Every user except of admins is allowed
|
||||
*/
|
||||
|
||||
@CrossOrigin
|
||||
@PostMapping("/entries")
|
||||
public ResponseEntity<Boolean> postEntry(@RequestBody Entry entry, @RequestParam(name = "sessionid") String sessionid)
|
||||
{
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
|
||||
if (sessionUser != null)
|
||||
{
|
||||
db.addEntry(entry);
|
||||
return new ResponseEntity<>(true, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
PUT
|
||||
Update the endTime of an existing entry in the database. Every user except of admins is allowed
|
||||
*/
|
||||
|
||||
@CrossOrigin
|
||||
@PutMapping("/entries")
|
||||
public ResponseEntity<Boolean> updateEntry(@RequestParam(name="sessionid") String sessionid, @RequestBody Entry entry)
|
||||
{
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
if (sessionUser != null)
|
||||
{
|
||||
db.updateEntry(entry);
|
||||
return new ResponseEntity<>(true, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
Delete
|
||||
an existing entry from the database
|
||||
*/
|
||||
@CrossOrigin
|
||||
@DeleteMapping("/entries")
|
||||
public ResponseEntity<Boolean> deleteEntry(@RequestParam(name = "id") int id, @RequestParam(name = "sessionid") String sessionid)
|
||||
{
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
|
||||
if (sessionUser != null)
|
||||
{
|
||||
db.deleteEntry(id);
|
||||
return new ResponseEntity<>(true, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,175 @@
|
||||
package com.example.backend.anwprj.controller;
|
||||
|
||||
import com.example.backend.anwprj.Database.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Module.Module;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserPermissions;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
/**
|
||||
* Ein Modul hier entspricht nicht z.b. Analysis im Allgemeinen.
|
||||
* Es beschreibt die Verbindung zwischen einem Dozenten und Analysis in einem Speziellen Semester.
|
||||
*/
|
||||
|
||||
@RestController
|
||||
public class ModuleController
|
||||
{
|
||||
private final DataBaseHandler db;
|
||||
|
||||
{
|
||||
db = DataBaseHandler.getInstance();
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
GET
|
||||
A Module by its id
|
||||
*/
|
||||
@CrossOrigin
|
||||
@GetMapping("/module/id")
|
||||
public ResponseEntity<Module[]> getModules(
|
||||
@RequestParam(name = "sessionid") String sessionID)
|
||||
{
|
||||
|
||||
User user = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if (user != null)
|
||||
{
|
||||
Module[] modules = db.getModules(user.getId());
|
||||
if (modules != null)
|
||||
{
|
||||
return new ResponseEntity<>(modules, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
/**
|
||||
GET
|
||||
Get A Module by the matching semester and user id (important for edit function in frontend)
|
||||
*/
|
||||
@CrossOrigin
|
||||
@GetMapping("/module/suid")
|
||||
public ResponseEntity<Module[]> getModulesBySemesterUserID(@RequestParam(name = "sessionid") String sessionid, @RequestParam(name = "userid") String userid, @RequestParam(name = "semesterid") int semesterid)
|
||||
{
|
||||
User user = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
String[] userIDSSplit = userid.split("a");
|
||||
int[] userIDS = new int[userIDSSplit.length];
|
||||
for(int i = 0; i < userIDS.length; i++)
|
||||
{
|
||||
userIDS[i] = Integer.parseInt(userIDSSplit[i]);
|
||||
}
|
||||
|
||||
if(user != null && user.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
List<Module> result = new ArrayList<>();
|
||||
|
||||
for(int i = 0; i < userIDS.length; i++)
|
||||
{
|
||||
result.add(db.getModuleBySemesterUserID(userIDS[i], semesterid));
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(result.toArray(new Module[0]), HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
/**
|
||||
GET
|
||||
all modules from the database. (Not used now)
|
||||
*/
|
||||
@CrossOrigin
|
||||
@GetMapping("/module/all")
|
||||
public ResponseEntity<Module[]> getModule(@RequestParam(name = "sessionid") String sessionid)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
|
||||
if (u != null)
|
||||
{
|
||||
if (u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
return new ResponseEntity<>(db.getAllModules(), HttpStatus.OK);
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
POST
|
||||
a new module entry. (When a user is selected in a semester.)
|
||||
*/
|
||||
@CrossOrigin
|
||||
@PostMapping("/module")
|
||||
public ResponseEntity<Module> addModule(@RequestBody Module module, @RequestParam(name = "sessionid") String sessionID)
|
||||
{
|
||||
|
||||
System.out.println("test1");
|
||||
User user = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if (user.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
Module m = db.addModule(module);
|
||||
if (m != null)
|
||||
{
|
||||
return new ResponseEntity<>(m, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
/**
|
||||
PUT
|
||||
Update a Module
|
||||
*/
|
||||
@CrossOrigin
|
||||
@PutMapping("/module")
|
||||
public ResponseEntity<Module> updateModule(@RequestBody Module module, @RequestParam(name = "sessionid") String sessionID)
|
||||
{
|
||||
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
if (u != null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
Module m = db.updateModule(module);
|
||||
|
||||
if (m != null)
|
||||
{
|
||||
return new ResponseEntity<>(m, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
/**
|
||||
DELETE
|
||||
Delete A Module
|
||||
*/
|
||||
@CrossOrigin
|
||||
@DeleteMapping("/module")
|
||||
public void deleteModule(@RequestParam(name = "sessionid") String sessionid, @RequestParam(name = "semesterid") int semesterid, @RequestParam(name = "userid") int userid)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
if (u != null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
db.deleteModule(semesterid, userid);
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,136 @@
|
||||
package com.example.backend.anwprj.controller;
|
||||
|
||||
import com.example.backend.anwprj.Database.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Semesters.Semester;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserPermissions;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
@RestController
|
||||
public class SemesterController
|
||||
{
|
||||
//reference to the database handler
|
||||
private DataBaseHandler db;
|
||||
|
||||
{
|
||||
db = DataBaseHandler.getInstance();
|
||||
}
|
||||
|
||||
//get a semester object by its name
|
||||
@CrossOrigin
|
||||
@GetMapping("/semester")
|
||||
public ResponseEntity<Semester> getSemester(@RequestParam(name="name") String name, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(u != null)
|
||||
{
|
||||
Semester s = db.getSemester(name);
|
||||
if (s != null)
|
||||
{
|
||||
return new ResponseEntity<>(s, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/semester/id")
|
||||
public ResponseEntity<Semester> getSemester(@RequestParam(name="id") int id, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(u != null)
|
||||
{
|
||||
Semester s = db.getSemester(id);
|
||||
if(s != null)
|
||||
{
|
||||
return new ResponseEntity<>(s, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/semester/all")
|
||||
public ResponseEntity<Semester[]> getSemester(@RequestParam(name="sessionid") String sessionid)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
|
||||
if(u != null)
|
||||
{
|
||||
if(u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
return new ResponseEntity<>(db.getAllSemesters(), HttpStatus.OK);
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
|
||||
//a new semester add is requested (only allowed for admin users)
|
||||
@CrossOrigin
|
||||
@PostMapping("/semester")
|
||||
public ResponseEntity<Semester> addSemester(@RequestBody Semester semester, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User user = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(user.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
Semester s = db.addSemester(semester);
|
||||
if(s != null)
|
||||
{
|
||||
|
||||
return new ResponseEntity<>(s, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(null, HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
|
||||
@CrossOrigin
|
||||
@PutMapping("/semester")
|
||||
public ResponseEntity<Semester> updateSemester(@RequestBody Semester semester, @RequestParam(name="sessionid") String sessionID)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
if(u != null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
Semester s = db.updateSemester(semester);
|
||||
|
||||
if(s != null)
|
||||
{
|
||||
return new ResponseEntity<>(s, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@DeleteMapping("/semester")
|
||||
public void deleteSemester(@RequestParam(name="sessionid") String sessionid, @RequestParam(name="id") int id)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
if(u != null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
db.deleteSemester(id);
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,184 @@
|
||||
package com.example.backend.anwprj.controller;
|
||||
|
||||
import com.example.backend.discard.Encryption.RSA;
|
||||
import com.example.backend.anwprj.Database.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserPermissions;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
@RestController
|
||||
public class UserController {
|
||||
//reference to the database handler
|
||||
private DataBaseHandler db;
|
||||
|
||||
{
|
||||
db = DataBaseHandler.getInstance();
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/users/all")
|
||||
public ResponseEntity<User[]> getAllUsers(@RequestParam(name = "sessionid") String sessionid)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
|
||||
if(u != null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
User[] output = db.getAllUsers();
|
||||
return new ResponseEntity<>(output, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
|
||||
//a user wants to login
|
||||
@CrossOrigin
|
||||
@GetMapping("/users")
|
||||
public ResponseEntity<String> login(@RequestParam(name = "mail") String mail, @RequestParam(name = "password") String password) {
|
||||
//generate a session id for the user trying to login
|
||||
boolean isEncrypted = false;
|
||||
if(isEncrypted)
|
||||
{
|
||||
RSA rsa = RSA.getInstance();
|
||||
byte[] psw = rsa.loadByteArray(password);
|
||||
try {
|
||||
password = rsa.decrypt(psw);
|
||||
} catch (Exception e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
|
||||
String sessionID = UserSessionIDHandler.addUser(mail, password);
|
||||
|
||||
return new ResponseEntity<>(sessionID, HttpStatus.OK);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/users/logout")
|
||||
public ResponseEntity<Boolean> logout(@RequestParam(name = "sessionid") String sessionID) {
|
||||
boolean success = UserSessionIDHandler.removeUser(sessionID);
|
||||
return new ResponseEntity<>(success, HttpStatus.OK);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/users/data")
|
||||
public ResponseEntity<User> getUserData(
|
||||
@RequestParam(name = "sessionid") String sessionID,
|
||||
@RequestParam(name = "mail") String mail) {
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if (sessionUser != null) {
|
||||
System.out.println(sessionUser.getMail() + " " + mail);
|
||||
|
||||
if (sessionUser.getMail().equals(mail) || sessionUser.getPermissions() == UserPermissions.admin.getValue()) {
|
||||
User searchedUser = db.getUser(mail);
|
||||
return new ResponseEntity<>(searchedUser, HttpStatus.OK);
|
||||
}
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping("/users/check")
|
||||
public ResponseEntity<User> checkLogin(@RequestParam(name="sessionid") String sessionid)
|
||||
{
|
||||
User u = UserSessionIDHandler.getUserBySessionID(sessionid);
|
||||
|
||||
if(u != null)
|
||||
{
|
||||
return new ResponseEntity<>(db.getUser(u.getId()), HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
//adds a new user to the database (cannot create an admin user)
|
||||
@CrossOrigin
|
||||
@PostMapping("/users")
|
||||
public ResponseEntity<String> addUser(@RequestBody User user) {
|
||||
User checkUser = db.getUser(user.getMail());
|
||||
|
||||
if (checkUser != null) {
|
||||
return new ResponseEntity<>("mail", HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
//if user was successfully added to database
|
||||
User u = db.addUser(user);
|
||||
|
||||
if (u != null) {
|
||||
//generate a session id
|
||||
return new ResponseEntity<String>(UserSessionIDHandler.addUser(user.getMail(), user.getPassword()), HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<String>(HttpStatus.BAD_REQUEST);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@PutMapping("/users")
|
||||
public ResponseEntity<Boolean> updateUser(@RequestParam(name = "sessionid") String sessionID, @RequestBody User u, @RequestParam(name = "mail") String mail) {
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if (sessionUser != null) {
|
||||
if (sessionUser.getMail().equals(mail) || sessionUser.getPermissions() == UserPermissions.admin.getValue()) {
|
||||
System.out.println(sessionUser.getId());
|
||||
|
||||
User resultingUser = db.updateUser(u, sessionUser.getId(), false);
|
||||
|
||||
if (resultingUser != null) {
|
||||
UserSessionIDHandler.removeUser(sessionID);
|
||||
return new ResponseEntity<>(true, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.NOT_FOUND);
|
||||
}
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@PutMapping("/users/elevate")
|
||||
public ResponseEntity<Boolean> elevateUser(
|
||||
@RequestParam(name = "sessionid") String sessionID,
|
||||
@RequestParam(name = "mail") String mail,
|
||||
@RequestParam(name = "permission") int permission)
|
||||
{
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if(sessionUser != null && sessionUser.getPermissions() == UserPermissions.admin.getValue())
|
||||
{
|
||||
System.out.println("test");
|
||||
User userToUpdateTemplate = db.getUser(mail);
|
||||
User userToUpdate = new User(userToUpdateTemplate.getId(), userToUpdateTemplate.getFirstName(), userToUpdateTemplate.getLastName(),
|
||||
userToUpdateTemplate.getMail(), userToUpdateTemplate.getPassword(), permission);
|
||||
|
||||
User resultingUser = db.updateUser(userToUpdate, userToUpdate.getId(), true);
|
||||
|
||||
if(resultingUser == null)
|
||||
{
|
||||
return new ResponseEntity<>(false, HttpStatus.NOT_FOUND);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(true, HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(false, HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
@CrossOrigin
|
||||
@DeleteMapping("/users")
|
||||
public ResponseEntity<Boolean> deleteUser(@RequestParam(name = "sessionid") String sessionID, @RequestParam(name = "mail") String mail) {
|
||||
User sessionUser = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
|
||||
if (sessionUser != null && sessionUser.getPermissions() == UserPermissions.admin.getValue()) {
|
||||
return new ResponseEntity<>(db.deleteUser(mail), HttpStatus.OK);
|
||||
}
|
||||
|
||||
return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,60 @@
|
||||
package com.example.backend.discard;
|
||||
|
||||
import com.example.backend.anwprj.Database.DataBaseHandler;
|
||||
import com.example.backend.discard.Days.Day;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserPermissions;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
@RestController
|
||||
public class DayController
|
||||
{
|
||||
|
||||
// private DataBaseHandler db;
|
||||
//
|
||||
// {
|
||||
// db = DataBaseHandler.getInstance();
|
||||
// }
|
||||
//
|
||||
// @CrossOrigin
|
||||
// @GetMapping("/days")
|
||||
// public ResponseEntity<Day> getDay(
|
||||
// @RequestParam(name="sessionid") String sessionID,
|
||||
// @RequestParam(name="dayinyear") int dayinyear,
|
||||
// @RequestParam(name="yearnumber") int yearnumber,
|
||||
// @RequestParam(name="semesterid") int semesterID)
|
||||
// {
|
||||
// User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
//
|
||||
// if(u != null)
|
||||
// {
|
||||
// Day d = db.getDay(dayinyear, yearnumber, semesterID);
|
||||
//
|
||||
// if (d != null)
|
||||
// {
|
||||
// return new ResponseEntity<>(d, HttpStatus.OK);
|
||||
// }
|
||||
//
|
||||
// return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
// }
|
||||
//
|
||||
// return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
// }
|
||||
//
|
||||
// @CrossOrigin
|
||||
// @PostMapping("/days")
|
||||
// public ResponseEntity<Day> addDay(@RequestBody Day day, @RequestParam(name="sessionid") String sessionID)
|
||||
// {
|
||||
// User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
//
|
||||
// if(u != null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
// {
|
||||
// return new ResponseEntity<>(db.addDay(day), HttpStatus.OK);
|
||||
// }
|
||||
//
|
||||
// return new ResponseEntity<>(null, HttpStatus.FORBIDDEN);
|
||||
// }
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
package com.example.backend.discard.Days;
|
||||
|
||||
public class Day
|
||||
{
|
||||
private int id;
|
||||
private int dayinyear;
|
||||
private int yearnumber;
|
||||
private int semesterid;
|
||||
|
||||
public Day(int id, int dayinyear, int yearnumber, int semesterid) {
|
||||
this.id = id;
|
||||
this.dayinyear = dayinyear;
|
||||
this.yearnumber = yearnumber;
|
||||
this.semesterid = semesterid;
|
||||
}
|
||||
|
||||
public int getId() {
|
||||
return id;
|
||||
}
|
||||
|
||||
public int getDayinyear() {
|
||||
return dayinyear;
|
||||
}
|
||||
|
||||
public int getYearnumber() {
|
||||
return yearnumber;
|
||||
}
|
||||
|
||||
public int getSemesterid() {
|
||||
return semesterid;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
package com.example.backend.discard.Encryption;
|
||||
|
||||
import javax.crypto.Cipher;
|
||||
import java.io.*;
|
||||
import java.nio.charset.StandardCharsets;
|
||||
import java.security.*;
|
||||
|
||||
public class RSA {
|
||||
|
||||
private PublicKey publicKey;
|
||||
private PrivateKey privateKey;
|
||||
|
||||
private static RSA instance = null;
|
||||
|
||||
public static RSA getInstance()
|
||||
{
|
||||
if(instance == null)
|
||||
{
|
||||
instance = new RSA();
|
||||
}
|
||||
|
||||
return instance;
|
||||
}
|
||||
|
||||
private RSA(){}
|
||||
|
||||
public String decrypt(byte[] text) throws Exception
|
||||
{
|
||||
readKeyPairs();
|
||||
var cipher = Cipher.getInstance("RSA/ECB/PKCS1Padding");
|
||||
cipher.init(Cipher.DECRYPT_MODE, privateKey);
|
||||
var plainText = cipher.doFinal(text);
|
||||
return new String(plainText, StandardCharsets.US_ASCII);
|
||||
}
|
||||
|
||||
private void readKeyPairs() throws Exception
|
||||
{
|
||||
var publicInput = new ObjectInputStream(new FileInputStream(new File("./public.kfs")));
|
||||
publicKey = (PublicKey) publicInput.readObject();
|
||||
publicInput.close();
|
||||
|
||||
var privateInput = new ObjectInputStream(new FileInputStream(new File("./private.kfs")));
|
||||
privateKey = (PrivateKey) privateInput.readObject();
|
||||
privateInput.close();
|
||||
}
|
||||
|
||||
public byte[] loadByteArray(String text)
|
||||
{
|
||||
String[] split = text.split(",");
|
||||
byte[] output = new byte[split.length];
|
||||
for(int i = 0; i < split.length; i++)
|
||||
{
|
||||
output[i] = Byte.parseByte(split[i]);
|
||||
}
|
||||
|
||||
return output;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,124 @@
|
||||
/**
|
||||
* WEEKS
|
||||
*/
|
||||
|
||||
public Week addWeek(Week week)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("insert into weeks (semesterid, weeknumber) values (" + week.getSemesterid() + ", " + week.getWeeknumber() + ")");
|
||||
|
||||
return getWeek(week.getSemesterid(), week.getWeeknumber());
|
||||
|
||||
} catch (SQLException e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Week getWeek(int id)
|
||||
{
|
||||
ResultSet rs = null;
|
||||
try
|
||||
{
|
||||
rs = st.executeQuery("select * from weeks where id=" + id);
|
||||
|
||||
return resultSetToWeek(rs);
|
||||
|
||||
} catch (SQLException e)
|
||||
|
||||
{
|
||||
return null;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
public Week getWeek(int semesterid, int weeknumber)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from weeks where semesterid =" + semesterid + " and weeknumber=" + weeknumber);
|
||||
|
||||
return resultSetToWeek(rs);
|
||||
}
|
||||
catch (SQLException e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
private Week resultSetToWeek(ResultSet rs) {
|
||||
try {
|
||||
rs.next();
|
||||
|
||||
return new Week(
|
||||
rs.getInt("id"),
|
||||
rs.getInt("semesterid"),
|
||||
rs.getInt("weeknumber")
|
||||
);
|
||||
} catch (SQLException e) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
DAYS
|
||||
*/
|
||||
public Day addDay(Day day)
|
||||
{
|
||||
try
|
||||
{
|
||||
st.executeUpdate("insert into days (dayinyear, yearnumber, semesterid) values (" + day.getDayinyear() + ", " + day.getYearnumber() + ", " + day.getSemesterid() + ")");
|
||||
return getDay(day.getDayinyear(), day.getYearnumber(), day.getSemesterid());
|
||||
} catch (SQLException e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Day getDay(int id)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from days where id=" + id);
|
||||
|
||||
return resultSetToDay(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
public Day getDay(int dayinyear, int yearnumber, int semesterid)
|
||||
{
|
||||
try
|
||||
{
|
||||
ResultSet rs = st.executeQuery("select * from days where dayinyear =" + dayinyear + " and yearnumber =" + yearnumber + " and semesterid =" + semesterid);
|
||||
|
||||
return resultSetToDay(rs);
|
||||
}
|
||||
catch(Exception e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
private Day resultSetToDay(ResultSet rs)
|
||||
{
|
||||
try
|
||||
{
|
||||
rs.next();
|
||||
|
||||
return new Day(
|
||||
rs.getInt("id"),
|
||||
rs.getInt("dayinyear"),
|
||||
rs.getInt("yearnumber"),
|
||||
rs.getInt("semesterid")
|
||||
);
|
||||
} catch (SQLException e)
|
||||
{
|
||||
return null;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
package com.example.backend.discard.Week;
|
||||
|
||||
public class Week {
|
||||
|
||||
private int id;
|
||||
private int semesterid;
|
||||
private int weeknumber;
|
||||
|
||||
public Week(int id, int semesterid, int weeknumber) {
|
||||
this.id = id;
|
||||
this.semesterid = semesterid;
|
||||
this.weeknumber = weeknumber;
|
||||
}
|
||||
|
||||
public int getId() {
|
||||
return id;
|
||||
}
|
||||
|
||||
public int getSemesterid() {
|
||||
return semesterid;
|
||||
}
|
||||
|
||||
public int getWeeknumber() {
|
||||
return weeknumber;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,59 @@
|
||||
package com.example.backend.discard;
|
||||
|
||||
import com.example.backend.anwprj.Database.DataBaseHandler;
|
||||
import com.example.backend.anwprj.Users.User;
|
||||
import com.example.backend.anwprj.Users.UserPermissions;
|
||||
import com.example.backend.anwprj.Users.UserSessionIDHandler;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import com.example.backend.discard.Week.Week;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
import java.sql.SQLException;
|
||||
|
||||
@RestController
|
||||
public class WeekController
|
||||
{
|
||||
|
||||
// private DataBaseHandler db;
|
||||
//
|
||||
// {
|
||||
// db = DataBaseHandler.getInstance();
|
||||
// }
|
||||
//
|
||||
// @CrossOrigin
|
||||
// @GetMapping("/weeks")
|
||||
// public ResponseEntity<Week> getWeek(
|
||||
// @RequestParam(name="sessionid") String sessionID,
|
||||
// @RequestParam(name="semesterid") int semesterID,
|
||||
// @RequestParam(name="weeknumber") int weekNumber) throws SQLException {
|
||||
// User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
//
|
||||
// if(u != null)
|
||||
// {
|
||||
// Week w = db.getWeek(semesterID,weekNumber);
|
||||
//
|
||||
// if(w != null)
|
||||
// {
|
||||
// return new ResponseEntity<>(w, HttpStatus.OK);
|
||||
// }
|
||||
// return new ResponseEntity<>(HttpStatus.NOT_FOUND);
|
||||
// }
|
||||
// return new ResponseEntity<>(HttpStatus.FORBIDDEN);
|
||||
// }
|
||||
//
|
||||
// @CrossOrigin
|
||||
// @PostMapping("/weeks")
|
||||
// public ResponseEntity<Week> addWeek(@RequestBody Week week, @RequestParam(name="sessionid") String sessionID)
|
||||
// {
|
||||
// User u = UserSessionIDHandler.getUserBySessionID(sessionID);
|
||||
//
|
||||
// if(u !=null && u.getPermissions() == UserPermissions.admin.getValue())
|
||||
// {
|
||||
// return new ResponseEntity<>(db.addWeek(week), HttpStatus.OK);
|
||||
// }
|
||||
//
|
||||
// return new ResponseEntity<>(null, HttpStatus.FORBIDDEN);
|
||||
// }
|
||||
}
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
package com.example.backend;
|
||||
|
||||
import org.junit.jupiter.api.Test;
|
||||
import org.springframework.boot.test.context.SpringBootTest;
|
||||
|
||||
@SpringBootTest
|
||||
class BackendApplicationTests
|
||||
{
|
||||
|
||||
@Test
|
||||
void contextLoads()
|
||||
{
|
||||
}
|
||||
|
||||
}
|
||||
Reference in New Issue
Block a user