idk i think it works
This commit is contained in:
@@ -78,10 +78,10 @@ async def register_endpoint(req: Request):
|
||||
await create_user(body["first_name"], body["last_name"], body["email"], body["password"])
|
||||
return PlainTextResponse("User registered")
|
||||
|
||||
@app.put("/edit_user")
|
||||
@app.post("/edit_user")
|
||||
async def edit_endpoint(req: Request):
|
||||
body:dict = await req.json()
|
||||
print(body.keys())
|
||||
print(body)
|
||||
|
||||
if "user_id" not in body.keys(): raise HTTPException(400, "Provide user ID")
|
||||
|
||||
@@ -91,6 +91,26 @@ async def edit_endpoint(req: Request):
|
||||
await edit_user(body["user_id"], params)
|
||||
return PlainTextResponse("User edited")
|
||||
|
||||
@app.post("/changepw")
|
||||
async def changepw_endpoint(req: Request):
|
||||
body:dict = await req.json()
|
||||
print(body)
|
||||
|
||||
if "user_id" not in body.keys(): raise HTTPException(400, "Provide user ID")
|
||||
|
||||
params = copy.deepcopy(body) # to create a completely new version (ridiculous but okay)
|
||||
params.pop("user_id")
|
||||
params.pop("old_password")
|
||||
|
||||
user = await fetch_user_info(body["user_id"],"id")
|
||||
|
||||
if bcrypt.checkpw(body["old_password"].encode(), user["password"].encode()) == False:
|
||||
raise HTTPException(403, "Incorrect password")
|
||||
|
||||
|
||||
|
||||
await edit_user(body["user_id"], params)
|
||||
return PlainTextResponse("Password changed")
|
||||
#
|
||||
# Track-specific endpoints
|
||||
#
|
||||
|
||||
@@ -57,6 +57,8 @@ async def edit_user(user_id: int, updates: dict):
|
||||
"""Edits an existing user."""
|
||||
if db.mode == "mysql":
|
||||
placeholders = ", ".join(["%s"] * len(updates))
|
||||
if updates.get("password") is not None: # there is a password update
|
||||
updates["password"] = bcrypt.hashpw(updates["password"].encode(), bcrypt.gensalt()).decode()
|
||||
values = list(updates.values())
|
||||
query = f"UPDATE users SET {', '.join([f'{key} = %s' for key in updates.keys()])} WHERE id = %s"
|
||||
values.append(user_id)
|
||||
|
||||
Reference in New Issue
Block a user