user.rb 15.3 KB
Newer Older
D
Dmitriy Zaporozhets 已提交
1 2 3 4
# == Schema Information
#
# Table name: users
#
D
Dmitriy Zaporozhets 已提交
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46
#  id                       :integer          not null, primary key
#  email                    :string(255)      default(""), not null
#  encrypted_password       :string(255)      default(""), not null
#  reset_password_token     :string(255)
#  reset_password_sent_at   :datetime
#  remember_created_at      :datetime
#  sign_in_count            :integer          default(0)
#  current_sign_in_at       :datetime
#  last_sign_in_at          :datetime
#  current_sign_in_ip       :string(255)
#  last_sign_in_ip          :string(255)
#  created_at               :datetime
#  updated_at               :datetime
#  name                     :string(255)
#  admin                    :boolean          default(FALSE), not null
#  projects_limit           :integer          default(10)
#  skype                    :string(255)      default(""), not null
#  linkedin                 :string(255)      default(""), not null
#  twitter                  :string(255)      default(""), not null
#  authentication_token     :string(255)
#  theme_id                 :integer          default(1), not null
#  bio                      :string(255)
#  failed_attempts          :integer          default(0)
#  locked_at                :datetime
#  extern_uid               :string(255)
#  provider                 :string(255)
#  username                 :string(255)
#  can_create_group         :boolean          default(TRUE), not null
#  can_create_team          :boolean          default(TRUE), not null
#  state                    :string(255)
#  color_scheme_id          :integer          default(1), not null
#  notification_level       :integer          default(1), not null
#  password_expires_at      :datetime
#  created_by_id            :integer
#  last_credential_check_at :datetime
#  avatar                   :string(255)
#  confirmation_token       :string(255)
#  confirmed_at             :datetime
#  confirmation_sent_at     :datetime
#  unconfirmed_email        :string(255)
#  hide_no_ssh_key          :boolean          default(FALSE)
#  website_url              :string(255)      default(""), not null
D
Dmitriy Zaporozhets 已提交
47 48
#

S
Steven Thonus 已提交
49 50 51
require 'carrierwave/orm/activerecord'
require 'file_size_validator'

G
gitlabhq 已提交
52
class User < ActiveRecord::Base
53 54 55 56 57
  default_value_for :admin, false
  default_value_for :can_create_group, true
  default_value_for :can_create_team, false
  default_value_for :hide_no_ssh_key, false

D
Dmitriy Zaporozhets 已提交
58
  devise :database_authenticatable, :token_authenticatable, :lockable, :async,
59
         :recoverable, :rememberable, :trackable, :validatable, :omniauthable, :confirmable, :registerable
G
gitlabhq 已提交
60

61
  attr_accessor :force_random_password
G
gitlabhq 已提交
62

63 64 65
  # Virtual attribute for authenticating by either username or email
  attr_accessor :login

66 67 68 69
  #
  # Relations
  #

70
  # Namespace for personal projects
71
  has_one :namespace, -> { where type: nil }, dependent: :destroy, foreign_key: :owner_id, class_name: "Namespace"
72 73 74

  # Profile
  has_many :keys, dependent: :destroy
75
  has_many :emails, dependent: :destroy
76 77

  # Groups
78 79
  has_many :users_groups, dependent: :destroy
  has_many :groups, through: :users_groups
80
  has_many :owned_groups, -> { where users_groups: { group_access: UsersGroup::OWNER } }, through: :users_groups, source: :group
81 82
  has_many :masters_groups, -> { where users_groups: { group_access: UsersGroup::MASTER } }, through: :users_groups, source: :group

83
  # Projects
84 85 86 87 88
  has_many :groups_projects,          through: :groups, source: :projects
  has_many :personal_projects,        through: :namespace, source: :projects
  has_many :projects,                 through: :users_projects
  has_many :created_projects,         foreign_key: :creator_id, class_name: 'Project'

89
  has_many :snippets,                 dependent: :destroy, foreign_key: :author_id, class_name: "Snippet"
90 91 92 93 94
  has_many :users_projects,           dependent: :destroy
  has_many :issues,                   dependent: :destroy, foreign_key: :author_id
  has_many :notes,                    dependent: :destroy, foreign_key: :author_id
  has_many :merge_requests,           dependent: :destroy, foreign_key: :author_id
  has_many :events,                   dependent: :destroy, foreign_key: :author_id,   class_name: "Event"
95
  has_many :recent_events, -> { order "id DESC" }, foreign_key: :author_id,   class_name: "Event"
96 97 98
  has_many :assigned_issues,          dependent: :destroy, foreign_key: :assignee_id, class_name: "Issue"
  has_many :assigned_merge_requests,  dependent: :destroy, foreign_key: :assignee_id, class_name: "MergeRequest"

99

100 101 102
  #
  # Validations
  #
C
Cyril 已提交
103
  validates :name, presence: true
104
  validates :email, presence: true, email: {strict_mode: true}, uniqueness: true
105
  validates :bio, length: { maximum: 255 }, allow_blank: true
106
  validates :extern_uid, allow_blank: true, uniqueness: {scope: :provider}
N
Nihad Abbasov 已提交
107
  validates :projects_limit, presence: true, numericality: {greater_than_or_equal_to: 0}
108
  validates :username, presence: true, uniqueness: { case_sensitive: false },
D
Dmitriy Zaporozhets 已提交
109
            exclusion: { in: Gitlab::Blacklist.path },
110 111 112
            format: { with: Gitlab::Regex.username_regex,
                      message: "only letters, digits & '_' '-' '.' allowed. Letter should be first" }

A
Andrey Kumanyaev 已提交
113
  validates :notification_level, inclusion: { in: Notification.notification_levels }, presence: true
114
  validate :namespace_uniq, if: ->(user) { user.username_changed? }
115
  validate :avatar_type, if: ->(user) { user.avatar_changed? }
116
  validate :unique_email, if: ->(user) { user.email_changed? }
S
Steven Thonus 已提交
117
  validates :avatar, file_size: { maximum: 100.kilobytes.to_i }
118

119
  before_validation :generate_password, on: :create
120 121
  before_validation :sanitize_attrs

N
Nihad Abbasov 已提交
122
  before_save :ensure_authentication_token
D
Dmitriy Zaporozhets 已提交
123 124 125 126
  after_save :ensure_namespace_correct
  after_create :post_create_hook
  after_destroy :post_destroy_hook

127

N
Nihad Abbasov 已提交
128
  alias_attribute :private_token, :authentication_token
129

130
  delegate :path, to: :namespace, allow_nil: true, prefix: true
131

132 133 134 135
  state_machine :state, initial: :active do
    after_transition any => :blocked do |user, transition|
      # Remove user from all projects and
      user.users_projects.find_each do |membership|
D
Dmitriy Zaporozhets 已提交
136 137 138 139 140 141 142 143 144
        # skip owned resources
        next if membership.project.owner == user

        return false unless membership.destroy
      end

      # Remove user from all groups
      user.users_groups.find_each do |membership|
        # skip owned resources
145
        next if membership.group.last_owner?(user)
D
Dmitriy Zaporozhets 已提交
146

147 148 149 150 151 152 153 154 155 156 157 158 159
        return false unless membership.destroy
      end
    end

    event :block do
      transition active: :blocked
    end

    event :activate do
      transition blocked: :active
    end
  end

S
Steven Thonus 已提交
160 161
  mount_uploader :avatar, AttachmentUploader

A
Andrey Kumanyaev 已提交
162
  # Scopes
A
Andrew8xx8 已提交
163
  scope :admins, -> { where(admin:  true) }
164 165
  scope :blocked, -> { with_state(:blocked) }
  scope :active, -> { with_state(:active) }
A
Andrew8xx8 已提交
166
  scope :alphabetically, -> { order('name ASC') }
167 168
  scope :in_team, ->(team){ where(id: team.member_ids) }
  scope :not_in_team, ->(team){ where('users.id NOT IN (:ids)', ids: team.member_ids) }
S
skv 已提交
169
  scope :not_in_project, ->(project) { project.users.present? ? where("id not in (:ids)", ids: project.users.map(&:id) ) : all }
A
Andrey Kumanyaev 已提交
170
  scope :without_projects, -> { where('id NOT IN (SELECT DISTINCT(user_id) FROM users_projects)') }
171
  scope :ldap, -> { where(provider:  'ldap') }
A
Andrey Kumanyaev 已提交
172

173
  scope :potential_team_members, ->(team) { team.members.any? ? active.not_in_team(team) : active  }
A
Andrey Kumanyaev 已提交
174

175 176 177
  #
  # Class methods
  #
A
Andrey Kumanyaev 已提交
178
  class << self
179
    # Devise method overridden to allow sign in with email or username
180 181 182 183 184 185 186 187
    def find_for_database_authentication(warden_conditions)
      conditions = warden_conditions.dup
      if login = conditions.delete(:login)
        where(conditions).where(["lower(username) = :value OR lower(email) = :value", { value: login.downcase }]).first
      else
        where(conditions).first
      end
    end
188

189 190 191 192 193 194
    def find_for_commit(email, name)
      # Prefer email match over name match
      User.where(email: email).first ||
        User.joins(:emails).where(emails: { email: email }).first ||
        User.where(name: name).first
    end
195

A
Andrey Kumanyaev 已提交
196 197 198 199 200 201 202 203
    def filter filter_name
      case filter_name
      when "admins"; self.admins
      when "blocked"; self.blocked
      when "wop"; self.without_projects
      else
        self.active
      end
204 205
    end

A
Andrey Kumanyaev 已提交
206
    def search query
207
      where("lower(name) LIKE :query OR lower(email) LIKE :query OR lower(username) LIKE :query", query: "%#{query.downcase}%")
A
Andrey Kumanyaev 已提交
208
    end
209 210

    def by_username_or_id(name_or_id)
211
      where('users.username = ? OR users.id = ?', name_or_id.to_s, name_or_id.to_i).first
212
    end
213

214
    def build_user(attrs = {}, options= {})
215 216 217 218 219
      if options[:as] == :admin
        User.new(defaults.merge(attrs.symbolize_keys), options)
      else
        User.new(attrs, options).with_defaults
      end
220 221
    end

222
    def defaults
I
Izaak Alpert 已提交
223 224 225
      {
        projects_limit: Gitlab.config.gitlab.default_projects_limit,
        can_create_group: Gitlab.config.gitlab.default_can_create_group,
I
Izaak Alpert 已提交
226
        theme_id: Gitlab.config.gitlab.default_theme
I
Izaak Alpert 已提交
227
      }
228
    end
V
vsizov 已提交
229
  end
R
randx 已提交
230

231 232 233
  #
  # Instance methods
  #
234 235 236 237 238

  def to_param
    username
  end

D
Dmitriy Zaporozhets 已提交
239 240 241 242
  def notification
    @notification ||= Notification.new(self)
  end

A
Andrey Kumanyaev 已提交
243 244 245 246
  def generate_password
    if self.force_random_password
      self.password = self.password_confirmation = Devise.friendly_token.first(8)
    end
R
randx 已提交
247
  end
248

249 250
  def namespace_uniq
    namespace_name = self.username
S
skv 已提交
251
    if Namespace.find_by(path: namespace_name)
L
lol768 已提交
252
      self.errors.add :username, "already exists"
253 254
    end
  end
255

256 257 258 259 260 261
  def avatar_type
    unless self.avatar.image?
      self.errors.add :avatar, "only images allowed"
    end
  end

262 263 264 265
  def unique_email
    self.errors.add(:email, 'has already been taken') if Email.exists?(email: self.email)
  end

266 267
  # Groups user has access to
  def authorized_groups
268
    @authorized_groups ||= begin
269
                             group_ids = (groups.pluck(:id) + authorized_projects.pluck(:namespace_id))
270
                             Group.where(id: group_ids).order('namespaces.name ASC')
271
                           end
272 273 274 275 276
  end


  # Projects user has access to
  def authorized_projects
277
    @authorized_projects ||= begin
278 279 280
                               project_ids = personal_projects.pluck(:id)
                               project_ids += groups_projects.pluck(:id)
                               project_ids += projects.pluck(:id).uniq
281
                               Project.where(id: project_ids).joins(:namespace).order('namespaces.name ASC')
282
                             end
283 284
  end

285 286 287 288 289 290
  def owned_projects
    @owned_projects ||= begin
                          Project.where(namespace_id: owned_groups.pluck(:id).push(namespace.id)).joins(:namespace)
                        end
  end

291 292
  # Team membership in authorized projects
  def tm_in_authorized_projects
A
Andrey Kumanyaev 已提交
293
    UsersProject.where(project_id: authorized_projects.map(&:id), user_id: self.id)
294
  end
D
Dmitriy Zaporozhets 已提交
295 296 297 298 299 300 301 302 303

  def is_admin?
    admin
  end

  def require_ssh_key?
    keys.count == 0
  end

304 305 306 307
  def can_change_username?
    Gitlab.config.gitlab.username_changing_enabled
  end

D
Dmitriy Zaporozhets 已提交
308
  def can_create_project?
309
    projects_limit_left > 0
D
Dmitriy Zaporozhets 已提交
310 311 312
  end

  def can_create_group?
313
    can?(:create_group, nil)
D
Dmitriy Zaporozhets 已提交
314 315 316 317 318 319 320 321 322 323
  end

  def abilities
    @abilities ||= begin
                     abilities = Six.new
                     abilities << Ability
                     abilities
                   end
  end

324 325 326 327
  def can_select_namespace?
    several_namespaces? || admin
  end

D
Dmitriy Zaporozhets 已提交
328 329 330 331 332 333 334 335 336
  def can? action, subject
    abilities.allowed?(self, action, subject)
  end

  def first_name
    name.split.first unless name.blank?
  end

  def cared_merge_requests
337
    MergeRequest.cared(self)
D
Dmitriy Zaporozhets 已提交
338 339
  end

340
  def projects_limit_left
341
    projects_limit - personal_projects.count
342 343
  end

D
Dmitriy Zaporozhets 已提交
344 345
  def projects_limit_percent
    return 100 if projects_limit.zero?
346
    (personal_projects.count.to_f / projects_limit) * 100
D
Dmitriy Zaporozhets 已提交
347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362
  end

  def recent_push project_id = nil
    # Get push events not earlier than 2 hours ago
    events = recent_events.code_push.where("created_at > ?", Time.now - 2.hours)
    events = events.where(project_id: project_id) if project_id

    # Take only latest one
    events = events.recent.limit(1).first
  end

  def projects_sorted_by_activity
    authorized_projects.sorted_by_activity
  end

  def several_namespaces?
363
    owned_groups.any? || masters_groups.any?
D
Dmitriy Zaporozhets 已提交
364 365 366 367 368
  end

  def namespace_id
    namespace.try :id
  end
369

370 371 372
  def name_with_username
    "#{name} (#{username})"
  end
D
Dmitriy Zaporozhets 已提交
373 374 375 376

  def tm_of(project)
    project.team_member_by_id(self.id)
  end
377 378 379 380 381 382 383 384 385 386 387 388 389 390

  def already_forked? project
    !!fork_of(project)
  end

  def fork_of project
    links = ForkedProjectLink.where(forked_from_project_id: project, forked_to_project_id: personal_projects)

    if links.any?
      links.first.forked_to_project
    else
      nil
    end
  end
391 392 393 394

  def ldap_user?
    extern_uid && provider == 'ldap'
  end
395

396
  def accessible_deploy_keys
397
    DeployKey.in_projects(self.authorized_projects.pluck(:id)).uniq
398
  end
399 400

  def created_by
S
skv 已提交
401
    User.find_by(id: created_by_id) if created_by_id
402
  end
403 404 405 406 407 408 409

  def sanitize_attrs
    %w(name username skype linkedin twitter bio).each do |attr|
      value = self.send(attr)
      self.send("#{attr}=", Sanitize.clean(value)) if value.present?
    end
  end
410

411 412 413 414 415 416 417 418
  def requires_ldap_check?
    if ldap_user?
      !last_credential_check_at || (last_credential_check_at + 1.hour) < Time.now
    else
      false
    end
  end

419 420 421 422 423
  def solo_owned_groups
    @solo_owned_groups ||= owned_groups.select do |group|
      group.owners == [self]
    end
  end
424 425

  def with_defaults
426 427
    User.defaults.each do |k, v|
      self.send("#{k}=", v)
428
    end
429 430

    self
431
  end
432

433 434 435 436
  def can_leave_project?(project)
    project.namespace != namespace &&
      project.project_member(self)
  end
437 438 439 440 441 442 443 444 445 446 447 448 449 450

  # Reset project events cache related to this user
  #
  # Since we do cache @event we need to reset cache in special cases:
  # * when the user changes their avatar
  # Events cache stored like  events/23-20130109142513.
  # The cache key includes updated_at timestamp.
  # Thus it will automatically generate a new fragment
  # when the event is updated because the key changes.
  def reset_events_cache
    Event.where(author_id: self.id).
      order('id DESC').limit(1000).
      update_all(updated_at: Time.now)
  end
J
Jerome Dalbert 已提交
451 452 453 454 455 456 457 458 459 460

  def full_website_url
    return "http://#{website_url}" if website_url !~ /^https?:\/\//

    website_url
  end

  def short_website_url
    website_url.gsub(/https?:\/\//, '')
  end
G
GitLab 已提交
461

462
  def all_ssh_keys
G
GitLab 已提交
463
    keys.map(&:key)
464
  end
465 466 467 468 469 470

  def temp_oauth_email?
    email =~ /\Atemp-email-for-oauth/
  end

  def generate_tmp_oauth_email
471
    self.email = "temp-email-for-oauth-#{username}@gitlab.localhost"
472
  end
D
Dmitriy Zaporozhets 已提交
473 474 475 476

  def public_profile?
    authorized_projects.public_only.any?
  end
477 478 479 480 481

  def avatar_url(size = nil)
    if avatar.present?
      URI::join(Gitlab.config.gitlab.url, avatar.url).to_s
    else
482
      GravatarService.new.execute(email, size)
483 484
    end
  end
D
Dmitriy Zaporozhets 已提交
485 486 487 488 489 490 491 492 493 494 495 496

  def ensure_namespace_correct
    # Ensure user has namespace
    self.create_namespace!(path: self.username, name: self.username) unless self.namespace

    if self.username_changed?
      self.namespace.update_attributes(path: self.username, name: self.username)
    end
  end

  def post_create_hook
    log_info("User \"#{self.name}\" (#{self.email}) was created")
D
Dmitriy Zaporozhets 已提交
497
    notification_service.new_user(self)
D
Dmitriy Zaporozhets 已提交
498 499 500 501 502 503 504 505
    system_hook_service.execute_hooks_for(self, :create)
  end

  def post_destroy_hook
    log_info("User \"#{self.name}\" (#{self.email})  was removed")
    system_hook_service.execute_hooks_for(self, :destroy)
  end

D
Dmitriy Zaporozhets 已提交
506
  def notification_service
D
Dmitriy Zaporozhets 已提交
507 508 509 510 511 512 513 514 515 516
    NotificationService.new
  end

  def log_info message
    Gitlab::AppLogger.info message
  end

  def system_hook_service
    SystemHooksService.new
  end
G
gitlabhq 已提交
517
end