user.rb 18.7 KB
Newer Older
D
Dmitriy Zaporozhets 已提交
1 2 3 4
# == Schema Information
#
# Table name: users
#
D
Dmitriy Zaporozhets 已提交
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42
#  id                       :integer          not null, primary key
#  email                    :string(255)      default(""), not null
#  encrypted_password       :string(255)      default(""), not null
#  reset_password_token     :string(255)
#  reset_password_sent_at   :datetime
#  remember_created_at      :datetime
#  sign_in_count            :integer          default(0)
#  current_sign_in_at       :datetime
#  last_sign_in_at          :datetime
#  current_sign_in_ip       :string(255)
#  last_sign_in_ip          :string(255)
#  created_at               :datetime
#  updated_at               :datetime
#  name                     :string(255)
#  admin                    :boolean          default(FALSE), not null
#  projects_limit           :integer          default(10)
#  skype                    :string(255)      default(""), not null
#  linkedin                 :string(255)      default(""), not null
#  twitter                  :string(255)      default(""), not null
#  authentication_token     :string(255)
#  theme_id                 :integer          default(1), not null
#  bio                      :string(255)
#  failed_attempts          :integer          default(0)
#  locked_at                :datetime
#  username                 :string(255)
#  can_create_group         :boolean          default(TRUE), not null
#  can_create_team          :boolean          default(TRUE), not null
#  state                    :string(255)
#  color_scheme_id          :integer          default(1), not null
#  notification_level       :integer          default(1), not null
#  password_expires_at      :datetime
#  created_by_id            :integer
#  avatar                   :string(255)
#  confirmation_token       :string(255)
#  confirmed_at             :datetime
#  confirmation_sent_at     :datetime
#  unconfirmed_email        :string(255)
#  hide_no_ssh_key          :boolean          default(FALSE)
43
#  hide_no_password         :boolean          default(FALSE)
D
Dmitriy Zaporozhets 已提交
44
#  website_url              :string(255)      default(""), not null
D
Dmitriy Zaporozhets 已提交
45 46
#  last_credential_check_at :datetime
#  github_access_token      :string(255)
47
#  notification_email       :string(255)
48
#  password_automatically_set :boolean        default(FALSE)
D
Douwe Maan 已提交
49
#  bitbucket_access_token   :string(255)
D
Dmitriy Zaporozhets 已提交
50 51
#

S
Steven Thonus 已提交
52 53 54
require 'carrierwave/orm/activerecord'
require 'file_size_validator'

G
gitlabhq 已提交
55
class User < ActiveRecord::Base
56
  include Sortable
57
  include Gitlab::ConfigHelper
58
  include TokenAuthenticatable
59
  extend Gitlab::ConfigHelper
60
  include Gitlab::CurrentSettings
61

62
  default_value_for :admin, false
63
  default_value_for :can_create_group, gitlab_config.default_can_create_group
64 65
  default_value_for :can_create_team, false
  default_value_for :hide_no_ssh_key, false
66
  default_value_for :hide_no_password, false
67
  default_value_for :theme_id, gitlab_config.default_theme
68

69
  devise :database_authenticatable, :lockable, :async,
70
         :recoverable, :rememberable, :trackable, :validatable, :omniauthable, :confirmable, :registerable
G
gitlabhq 已提交
71

72
  attr_accessor :force_random_password
G
gitlabhq 已提交
73

74 75 76
  # Virtual attribute for authenticating by either username or email
  attr_accessor :login

77 78 79 80
  #
  # Relations
  #

81
  # Namespace for personal projects
82
  has_one :namespace, -> { where type: nil }, dependent: :destroy, foreign_key: :owner_id, class_name: "Namespace"
83 84 85

  # Profile
  has_many :keys, dependent: :destroy
86
  has_many :emails, dependent: :destroy
87
  has_many :identities, dependent: :destroy
88 89

  # Groups
90 91 92 93
  has_many :members, dependent: :destroy
  has_many :project_members, source: 'ProjectMember'
  has_many :group_members, source: 'GroupMember'
  has_many :groups, through: :group_members
94 95
  has_many :owned_groups, -> { where members: { access_level: Gitlab::Access::OWNER } }, through: :group_members, source: :group
  has_many :masters_groups, -> { where members: { access_level: Gitlab::Access::MASTER } }, through: :group_members, source: :group
96

97
  # Projects
98 99
  has_many :groups_projects,          through: :groups, source: :projects
  has_many :personal_projects,        through: :namespace, source: :projects
100
  has_many :projects,                 through: :project_members
101
  has_many :created_projects,         foreign_key: :creator_id, class_name: 'Project'
C
Ciro Santilli 已提交
102 103
  has_many :users_star_projects, dependent: :destroy
  has_many :starred_projects, through: :users_star_projects, source: :project
104

105
  has_many :snippets,                 dependent: :destroy, foreign_key: :author_id, class_name: "Snippet"
106
  has_many :project_members,          dependent: :destroy, class_name: 'ProjectMember'
107 108 109 110
  has_many :issues,                   dependent: :destroy, foreign_key: :author_id
  has_many :notes,                    dependent: :destroy, foreign_key: :author_id
  has_many :merge_requests,           dependent: :destroy, foreign_key: :author_id
  has_many :events,                   dependent: :destroy, foreign_key: :author_id,   class_name: "Event"
111
  has_many :recent_events, -> { order "id DESC" }, foreign_key: :author_id,   class_name: "Event"
112 113
  has_many :assigned_issues,          dependent: :destroy, foreign_key: :assignee_id, class_name: "Issue"
  has_many :assigned_merge_requests,  dependent: :destroy, foreign_key: :assignee_id, class_name: "MergeRequest"
V
Valery Sizov 已提交
114
  has_many :oauth_applications, class_name: 'Doorkeeper::Application', as: :owner, dependent: :destroy
115

116

117 118 119
  #
  # Validations
  #
C
Cyril 已提交
120
  validates :name, presence: true
121
  validates :email, presence: true, email: { strict_mode: true }, uniqueness: true
122
  validates :notification_email, presence: true, email: { strict_mode: true }
123
  validates :bio, length: { maximum: 255 }, allow_blank: true
124
  validates :projects_limit, presence: true, numericality: { greater_than_or_equal_to: 0 }
125 126 127 128 129 130
  validates :username,
    presence: true,
    uniqueness: { case_sensitive: false },
    exclusion: { in: Gitlab::Blacklist.path },
    format: { with: Gitlab::Regex.username_regex,
              message: Gitlab::Regex.username_regex_message }
131

A
Andrey Kumanyaev 已提交
132
  validates :notification_level, inclusion: { in: Notification.notification_levels }, presence: true
133
  validate :namespace_uniq, if: ->(user) { user.username_changed? }
134
  validate :avatar_type, if: ->(user) { user.avatar_changed? }
135
  validate :unique_email, if: ->(user) { user.email_changed? }
136
  validate :owns_notification_email, if: ->(user) { user.notification_email_changed? }
137
  validates :avatar, file_size: { maximum: 200.kilobytes.to_i }
138

139
  before_validation :generate_password, on: :create
140
  before_validation :sanitize_attrs
141
  before_validation :set_notification_email, if: ->(user) { user.email_changed? }
142

N
Nihad Abbasov 已提交
143
  before_save :ensure_authentication_token
D
Dmitriy Zaporozhets 已提交
144
  after_save :ensure_namespace_correct
145
  after_initialize :set_projects_limit
D
Dmitriy Zaporozhets 已提交
146 147 148
  after_create :post_create_hook
  after_destroy :post_destroy_hook

149

N
Nihad Abbasov 已提交
150
  alias_attribute :private_token, :authentication_token
151

152
  delegate :path, to: :namespace, allow_nil: true, prefix: true
153

154 155 156
  state_machine :state, initial: :active do
    after_transition any => :blocked do |user, transition|
      # Remove user from all projects and
157
      user.project_members.find_each do |membership|
D
Dmitriy Zaporozhets 已提交
158 159 160 161 162 163 164
        # skip owned resources
        next if membership.project.owner == user

        return false unless membership.destroy
      end

      # Remove user from all groups
165
      user.group_members.find_each do |membership|
D
Dmitriy Zaporozhets 已提交
166
        # skip owned resources
167
        next if membership.group.last_owner?(user)
D
Dmitriy Zaporozhets 已提交
168

169 170 171 172 173 174 175 176 177 178 179 180 181
        return false unless membership.destroy
      end
    end

    event :block do
      transition active: :blocked
    end

    event :activate do
      transition blocked: :active
    end
  end

182
  mount_uploader :avatar, AvatarUploader
S
Steven Thonus 已提交
183

A
Andrey Kumanyaev 已提交
184
  # Scopes
A
Andrew8xx8 已提交
185
  scope :admins, -> { where(admin:  true) }
186 187
  scope :blocked, -> { with_state(:blocked) }
  scope :active, -> { with_state(:active) }
188 189
  scope :in_team, ->(team){ where(id: team.member_ids) }
  scope :not_in_team, ->(team){ where('users.id NOT IN (:ids)', ids: team.member_ids) }
S
skv 已提交
190
  scope :not_in_project, ->(project) { project.users.present? ? where("id not in (:ids)", ids: project.users.map(&:id) ) : all }
191
  scope :without_projects, -> { where('id NOT IN (SELECT DISTINCT(user_id) FROM members)') }
192
  scope :potential_team_members, ->(team) { team.members.any? ? active.not_in_team(team) : active  }
A
Andrey Kumanyaev 已提交
193

194 195 196
  #
  # Class methods
  #
A
Andrey Kumanyaev 已提交
197
  class << self
198
    # Devise method overridden to allow sign in with email or username
199 200 201 202 203 204 205 206
    def find_for_database_authentication(warden_conditions)
      conditions = warden_conditions.dup
      if login = conditions.delete(:login)
        where(conditions).where(["lower(username) = :value OR lower(email) = :value", { value: login.downcase }]).first
      else
        where(conditions).first
      end
    end
207

V
Valery Sizov 已提交
208 209
    def sort(method)
      case method.to_s
210 211 212 213
      when 'recent_sign_in' then reorder(last_sign_in_at: :desc)
      when 'oldest_sign_in' then reorder(last_sign_in_at: :asc)
      else
        order_by(method)
V
Valery Sizov 已提交
214 215 216
      end
    end

217 218 219 220 221 222
    def find_for_commit(email, name)
      # Prefer email match over name match
      User.where(email: email).first ||
        User.joins(:emails).where(emails: { email: email }).first ||
        User.where(name: name).first
    end
223

224
    def filter(filter_name)
A
Andrey Kumanyaev 已提交
225 226 227 228 229 230 231
      case filter_name
      when "admins"; self.admins
      when "blocked"; self.blocked
      when "wop"; self.without_projects
      else
        self.active
      end
232 233
    end

234
    def search(query)
235
      where("lower(name) LIKE :query OR lower(email) LIKE :query OR lower(username) LIKE :query", query: "%#{query.downcase}%")
A
Andrey Kumanyaev 已提交
236
    end
237

238 239 240 241 242
    def by_login(login)
      where('lower(username) = :value OR lower(email) = :value',
            value: login.to_s.downcase).first
    end

243
    def by_username_or_id(name_or_id)
244
      where('users.username = ? OR users.id = ?', name_or_id.to_s, name_or_id.to_i).first
245
    end
246

247 248
    def build_user(attrs = {})
      User.new(attrs)
249
    end
250 251 252 253 254 255 256 257 258

    def clean_username(username)
      username.gsub!(/@.*\z/,             "")
      username.gsub!(/\.git\z/,           "")
      username.gsub!(/\A-/,               "")
      username.gsub!(/[^a-zA-Z0-9_\-\.]/, "")

      counter = 0
      base = username
259
      while User.by_login(username).present? || Namespace.by_path(username).present?
260
        counter += 1
261 262 263 264 265
        username = "#{base}#{counter}"
      end

      username
    end
V
vsizov 已提交
266
  end
R
randx 已提交
267

268 269 270
  #
  # Instance methods
  #
271 272 273 274 275

  def to_param
    username
  end

D
Dmitriy Zaporozhets 已提交
276 277 278 279
  def notification
    @notification ||= Notification.new(self)
  end

A
Andrey Kumanyaev 已提交
280 281 282 283
  def generate_password
    if self.force_random_password
      self.password = self.password_confirmation = Devise.friendly_token.first(8)
    end
R
randx 已提交
284
  end
285

286
  def generate_reset_token
M
Marin Jankovski 已提交
287
    @reset_token, enc = Devise.token_generator.generate(self.class, :reset_password_token)
288 289 290 291

    self.reset_password_token   = enc
    self.reset_password_sent_at = Time.now.utc

M
Marin Jankovski 已提交
292
    @reset_token
293 294
  end

295 296
  def namespace_uniq
    namespace_name = self.username
297 298
    existing_namespace = Namespace.by_path(namespace_name)
    if existing_namespace && existing_namespace != self.namespace
L
lol768 已提交
299
      self.errors.add :username, "already exists"
300 301
    end
  end
302

303 304 305 306 307 308
  def avatar_type
    unless self.avatar.image?
      self.errors.add :avatar, "only images allowed"
    end
  end

309 310 311 312
  def unique_email
    self.errors.add(:email, 'has already been taken') if Email.exists?(email: self.email)
  end

313 314 315 316
  def owns_notification_email
    self.errors.add(:notification_email, "is not an email you own") unless self.all_emails.include?(self.notification_email)
  end

317 318
  # Groups user has access to
  def authorized_groups
319
    @authorized_groups ||= begin
320
                             group_ids = (groups.pluck(:id) + authorized_projects.pluck(:namespace_id))
321
                             Group.where(id: group_ids)
322
                           end
323 324 325 326 327
  end


  # Projects user has access to
  def authorized_projects
328
    @authorized_projects ||= begin
329
                               project_ids = personal_projects.pluck(:id)
330 331
                               project_ids.push(*groups_projects.pluck(:id))
                               project_ids.push(*projects.pluck(:id).uniq)
332
                               Project.where(id: project_ids)
333
                             end
334 335
  end

336 337 338 339 340 341
  def owned_projects
    @owned_projects ||= begin
                          Project.where(namespace_id: owned_groups.pluck(:id).push(namespace.id)).joins(:namespace)
                        end
  end

342 343
  # Team membership in authorized projects
  def tm_in_authorized_projects
344
    ProjectMember.where(source_id: authorized_projects.map(&:id), user_id: self.id)
345
  end
D
Dmitriy Zaporozhets 已提交
346 347 348 349 350 351 352 353 354

  def is_admin?
    admin
  end

  def require_ssh_key?
    keys.count == 0
  end

355 356 357 358
  def require_password?
    password_automatically_set? && !ldap_user?
  end

359
  def can_change_username?
360
    gitlab_config.username_changing_enabled
361 362
  end

D
Dmitriy Zaporozhets 已提交
363
  def can_create_project?
364
    projects_limit_left > 0
D
Dmitriy Zaporozhets 已提交
365 366 367
  end

  def can_create_group?
368
    can?(:create_group, nil)
D
Dmitriy Zaporozhets 已提交
369 370 371
  end

  def abilities
C
Ciro Santilli 已提交
372
    Ability.abilities
D
Dmitriy Zaporozhets 已提交
373 374
  end

375 376 377 378
  def can_select_namespace?
    several_namespaces? || admin
  end

379
  def can?(action, subject)
D
Dmitriy Zaporozhets 已提交
380 381 382 383 384 385 386 387
    abilities.allowed?(self, action, subject)
  end

  def first_name
    name.split.first unless name.blank?
  end

  def cared_merge_requests
388
    MergeRequest.cared(self)
D
Dmitriy Zaporozhets 已提交
389 390
  end

391
  def projects_limit_left
392
    projects_limit - personal_projects.count
393 394
  end

D
Dmitriy Zaporozhets 已提交
395 396
  def projects_limit_percent
    return 100 if projects_limit.zero?
397
    (personal_projects.count.to_f / projects_limit) * 100
D
Dmitriy Zaporozhets 已提交
398 399
  end

400
  def recent_push(project_id = nil)
D
Dmitriy Zaporozhets 已提交
401 402 403 404 405 406 407 408 409 410 411 412 413
    # Get push events not earlier than 2 hours ago
    events = recent_events.code_push.where("created_at > ?", Time.now - 2.hours)
    events = events.where(project_id: project_id) if project_id

    # Take only latest one
    events = events.recent.limit(1).first
  end

  def projects_sorted_by_activity
    authorized_projects.sorted_by_activity
  end

  def several_namespaces?
414
    owned_groups.any? || masters_groups.any?
D
Dmitriy Zaporozhets 已提交
415 416 417 418 419
  end

  def namespace_id
    namespace.try :id
  end
420

421 422 423
  def name_with_username
    "#{name} (#{username})"
  end
D
Dmitriy Zaporozhets 已提交
424 425 426 427

  def tm_of(project)
    project.team_member_by_id(self.id)
  end
428

429
  def already_forked?(project)
430 431 432
    !!fork_of(project)
  end

433
  def fork_of(project)
434 435 436 437 438 439 440 441
    links = ForkedProjectLink.where(forked_from_project_id: project, forked_to_project_id: personal_projects)

    if links.any?
      links.first.forked_to_project
    else
      nil
    end
  end
442 443

  def ldap_user?
444 445 446 447 448
    identities.exists?(["provider LIKE ? AND extern_uid IS NOT NULL", "ldap%"])
  end

  def ldap_identity
    @ldap_identity ||= identities.find_by(["provider LIKE ?", "ldap%"])
449
  end
450

451
  def accessible_deploy_keys
452
    DeployKey.in_projects(self.authorized_projects.pluck(:id)).uniq
453
  end
454 455

  def created_by
S
skv 已提交
456
    User.find_by(id: created_by_id) if created_by_id
457
  end
458 459 460 461 462 463 464

  def sanitize_attrs
    %w(name username skype linkedin twitter bio).each do |attr|
      value = self.send(attr)
      self.send("#{attr}=", Sanitize.clean(value)) if value.present?
    end
  end
465

466 467
  def set_notification_email
    if self.notification_email.blank? || !self.all_emails.include?(self.notification_email)
468
      self.notification_email = self.email
469 470 471
    end
  end

472 473 474 475 476 477 478
  def set_projects_limit
    connection_default_value_defined = new_record? && !projects_limit_changed?
    return unless self.projects_limit.nil? || connection_default_value_defined

    self.projects_limit = current_application_settings.default_projects_limit
  end

479
  def requires_ldap_check?
480 481 482
    if !Gitlab.config.ldap.enabled
      false
    elsif ldap_user?
483 484 485 486 487 488
      !last_credential_check_at || (last_credential_check_at + 1.hour) < Time.now
    else
      false
    end
  end

489 490 491 492 493
  def solo_owned_groups
    @solo_owned_groups ||= owned_groups.select do |group|
      group.owners == [self]
    end
  end
494 495

  def with_defaults
496 497
    User.defaults.each do |k, v|
      self.send("#{k}=", v)
498
    end
499 500

    self
501
  end
502

503 504 505 506
  def can_leave_project?(project)
    project.namespace != namespace &&
      project.project_member(self)
  end
507 508 509 510 511 512 513 514 515 516 517 518 519 520

  # Reset project events cache related to this user
  #
  # Since we do cache @event we need to reset cache in special cases:
  # * when the user changes their avatar
  # Events cache stored like  events/23-20130109142513.
  # The cache key includes updated_at timestamp.
  # Thus it will automatically generate a new fragment
  # when the event is updated because the key changes.
  def reset_events_cache
    Event.where(author_id: self.id).
      order('id DESC').limit(1000).
      update_all(updated_at: Time.now)
  end
J
Jerome Dalbert 已提交
521 522 523 524 525 526 527 528 529 530

  def full_website_url
    return "http://#{website_url}" if website_url !~ /^https?:\/\//

    website_url
  end

  def short_website_url
    website_url.gsub(/https?:\/\//, '')
  end
G
GitLab 已提交
531

532
  def all_ssh_keys
G
GitLab 已提交
533
    keys.map(&:key)
534
  end
535 536

  def temp_oauth_email?
537
    email.start_with?('temp-email-for-oauth')
538 539
  end

D
Dmitriy Zaporozhets 已提交
540 541 542
  def public_profile?
    authorized_projects.public_only.any?
  end
543 544 545

  def avatar_url(size = nil)
    if avatar.present?
546
      [gitlab_config.url, avatar.url].join
547
    else
548
      GravatarService.new.execute(email, size)
549 550
    end
  end
D
Dmitriy Zaporozhets 已提交
551

552 553 554 555
  def all_emails
    [self.email, *self.emails.map(&:email)]
  end

K
Kirill Zaitsev 已提交
556 557 558 559 560 561 562 563
  def hook_attrs
    {
      name: name,
      username: username,
      avatar_url: avatar_url
    }
  end

D
Dmitriy Zaporozhets 已提交
564 565 566 567 568 569 570 571 572 573 574
  def ensure_namespace_correct
    # Ensure user has namespace
    self.create_namespace!(path: self.username, name: self.username) unless self.namespace

    if self.username_changed?
      self.namespace.update_attributes(path: self.username, name: self.username)
    end
  end

  def post_create_hook
    log_info("User \"#{self.name}\" (#{self.email}) was created")
575
    notification_service.new_user(self, @reset_token) if self.created_by_id
D
Dmitriy Zaporozhets 已提交
576 577 578 579 580 581 582 583
    system_hook_service.execute_hooks_for(self, :create)
  end

  def post_destroy_hook
    log_info("User \"#{self.name}\" (#{self.email})  was removed")
    system_hook_service.execute_hooks_for(self, :destroy)
  end

D
Dmitriy Zaporozhets 已提交
584
  def notification_service
D
Dmitriy Zaporozhets 已提交
585 586 587
    NotificationService.new
  end

588
  def log_info(message)
D
Dmitriy Zaporozhets 已提交
589 590 591 592 593 594
    Gitlab::AppLogger.info message
  end

  def system_hook_service
    SystemHooksService.new
  end
C
Ciro Santilli 已提交
595 596 597 598 599 600

  def starred?(project)
    starred_projects.exists?(project)
  end

  def toggle_star(project)
601 602
    user_star_project = users_star_projects.
      where(project: project, user: self).take
C
Ciro Santilli 已提交
603 604 605 606 607 608
    if user_star_project
      user_star_project.destroy
    else
      UsersStarProject.create!(project: project, user: self)
    end
  end
609 610 611 612 613 614 615 616 617 618

  def manageable_namespaces
    @manageable_namespaces ||=
      begin
        namespaces = []
        namespaces << namespace
        namespaces += owned_groups
        namespaces += masters_groups
      end
  end
D
Dmitriy Zaporozhets 已提交
619 620 621 622

  def oauth_authorized_tokens
    Doorkeeper::AccessToken.where(resource_owner_id: self.id, revoked_at: nil)
  end
623 624 625

  def contributed_projects_ids
    Event.where(author_id: self).
626
      where("created_at > ?", Time.now - 1.year).
627 628
      where("action = :pushed OR (target_type = 'MergeRequest' AND action = :created)", 
        pushed: Event::PUSHED, created: Event::CREATED).
629
      reorder(project_id: :desc).
630 631
      select(:project_id).
      uniq
632
      .map(&:project_id)
633
  end
G
gitlabhq 已提交
634
end