user.rb 23.4 KB
Newer Older
D
Dmitriy Zaporozhets 已提交
1 2 3 4
# == Schema Information
#
# Table name: users
#
S
Stan Hu 已提交
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56
#  id                         :integer          not null, primary key
#  email                      :string(255)      default(""), not null
#  encrypted_password         :string(255)      default(""), not null
#  reset_password_token       :string(255)
#  reset_password_sent_at     :datetime
#  remember_created_at        :datetime
#  sign_in_count              :integer          default(0)
#  current_sign_in_at         :datetime
#  last_sign_in_at            :datetime
#  current_sign_in_ip         :string(255)
#  last_sign_in_ip            :string(255)
#  created_at                 :datetime
#  updated_at                 :datetime
#  name                       :string(255)
#  admin                      :boolean          default(FALSE), not null
#  projects_limit             :integer          default(10)
#  skype                      :string(255)      default(""), not null
#  linkedin                   :string(255)      default(""), not null
#  twitter                    :string(255)      default(""), not null
#  authentication_token       :string(255)
#  theme_id                   :integer          default(1), not null
#  bio                        :string(255)
#  failed_attempts            :integer          default(0)
#  locked_at                  :datetime
#  username                   :string(255)
#  can_create_group           :boolean          default(TRUE), not null
#  can_create_team            :boolean          default(TRUE), not null
#  state                      :string(255)
#  color_scheme_id            :integer          default(1), not null
#  notification_level         :integer          default(1), not null
#  password_expires_at        :datetime
#  created_by_id              :integer
#  last_credential_check_at   :datetime
#  avatar                     :string(255)
#  confirmation_token         :string(255)
#  confirmed_at               :datetime
#  confirmation_sent_at       :datetime
#  unconfirmed_email          :string(255)
#  hide_no_ssh_key            :boolean          default(FALSE)
#  website_url                :string(255)      default(""), not null
#  notification_email         :string(255)
#  hide_no_password           :boolean          default(FALSE)
#  password_automatically_set :boolean          default(FALSE)
#  location                   :string(255)
#  encrypted_otp_secret       :string(255)
#  encrypted_otp_secret_iv    :string(255)
#  encrypted_otp_secret_salt  :string(255)
#  otp_required_for_login     :boolean          default(FALSE), not null
#  otp_backup_codes           :text
#  public_email               :string(255)      default(""), not null
#  dashboard                  :integer          default(0)
#  project_view               :integer          default(0)
57
#  layout                     :integer          default(0)
D
Dmitriy Zaporozhets 已提交
58 59
#

S
Steven Thonus 已提交
60 61 62
require 'carrierwave/orm/activerecord'
require 'file_size_validator'

G
gitlabhq 已提交
63
class User < ActiveRecord::Base
64
  extend Gitlab::ConfigHelper
65 66

  include Gitlab::ConfigHelper
67
  include Gitlab::CurrentSettings
68 69 70
  include Referable
  include Sortable
  include TokenAuthenticatable
71
  include CaseSensitivity
72

73
  default_value_for :admin, false
74
  default_value_for :can_create_group, gitlab_config.default_can_create_group
75 76
  default_value_for :can_create_team, false
  default_value_for :hide_no_ssh_key, false
77
  default_value_for :hide_no_password, false
78
  default_value_for :theme_id, gitlab_config.default_theme
79

80 81
  devise :two_factor_authenticatable,
         otp_secret_encryption_key: File.read(Rails.root.join('.secret')).chomp
82
  alias_attribute :two_factor_enabled, :otp_required_for_login
R
Robert Speicher 已提交
83

84
  devise :two_factor_backupable, otp_number_of_backup_codes: 10
R
Robert Speicher 已提交
85 86
  serialize :otp_backup_codes, JSON

87 88
  devise :lockable, :async, :recoverable, :rememberable, :trackable,
    :validatable, :omniauthable, :confirmable, :registerable
G
gitlabhq 已提交
89

90
  attr_accessor :force_random_password
G
gitlabhq 已提交
91

92 93 94
  # Virtual attribute for authenticating by either username or email
  attr_accessor :login

95 96 97 98
  #
  # Relations
  #

99
  # Namespace for personal projects
100
  has_one :namespace, -> { where type: nil }, dependent: :destroy, foreign_key: :owner_id, class_name: "Namespace"
101 102 103

  # Profile
  has_many :keys, dependent: :destroy
104
  has_many :emails, dependent: :destroy
105
  has_many :identities, dependent: :destroy, autosave: true
106 107

  # Groups
108 109 110 111
  has_many :members, dependent: :destroy
  has_many :project_members, source: 'ProjectMember'
  has_many :group_members, source: 'GroupMember'
  has_many :groups, through: :group_members
112 113
  has_many :owned_groups, -> { where members: { access_level: Gitlab::Access::OWNER } }, through: :group_members, source: :group
  has_many :masters_groups, -> { where members: { access_level: Gitlab::Access::MASTER } }, through: :group_members, source: :group
114

115
  # Projects
116 117
  has_many :groups_projects,          through: :groups, source: :projects
  has_many :personal_projects,        through: :namespace, source: :projects
118
  has_many :projects,                 through: :project_members
119
  has_many :created_projects,         foreign_key: :creator_id, class_name: 'Project'
C
Ciro Santilli 已提交
120 121
  has_many :users_star_projects, dependent: :destroy
  has_many :starred_projects, through: :users_star_projects, source: :project
122

123
  has_many :snippets,                 dependent: :destroy, foreign_key: :author_id, class_name: "Snippet"
124
  has_many :project_members,          dependent: :destroy, class_name: 'ProjectMember'
125 126 127 128
  has_many :issues,                   dependent: :destroy, foreign_key: :author_id
  has_many :notes,                    dependent: :destroy, foreign_key: :author_id
  has_many :merge_requests,           dependent: :destroy, foreign_key: :author_id
  has_many :events,                   dependent: :destroy, foreign_key: :author_id,   class_name: "Event"
129
  has_many :subscriptions,            dependent: :destroy
130
  has_many :recent_events, -> { order "id DESC" }, foreign_key: :author_id,   class_name: "Event"
131 132
  has_many :assigned_issues,          dependent: :destroy, foreign_key: :assignee_id, class_name: "Issue"
  has_many :assigned_merge_requests,  dependent: :destroy, foreign_key: :assignee_id, class_name: "MergeRequest"
V
Valery Sizov 已提交
133
  has_many :oauth_applications, class_name: 'Doorkeeper::Application', as: :owner, dependent: :destroy
R
Rémy Coutable 已提交
134
  has_one  :abuse_report,             dependent: :destroy
135
  has_many :ci_builds,                dependent: :nullify, class_name: 'Ci::Build'
136

137

138 139 140
  #
  # Validations
  #
C
Cyril 已提交
141
  validates :name, presence: true
142
  # Note that a 'uniqueness' and presence check is provided by devise :validatable for email. We do not need to
143
  # duplicate that here as the validation framework will have duplicate errors in the event of a failure.
144
  validates :email, presence: true, email: { strict_mode: true }
145
  validates :notification_email, presence: true, email: { strict_mode: true }
146
  validates :public_email, presence: true, email: { strict_mode: true }, allow_blank: true, uniqueness: true
147
  validates :bio, length: { maximum: 255 }, allow_blank: true
148
  validates :projects_limit, presence: true, numericality: { greater_than_or_equal_to: 0 }
149 150 151 152
  validates :username,
    presence: true,
    uniqueness: { case_sensitive: false },
    exclusion: { in: Gitlab::Blacklist.path },
D
Douwe Maan 已提交
153 154
    format: { with: Gitlab::Regex.namespace_regex,
              message: Gitlab::Regex.namespace_regex_message }
155

A
Andrey Kumanyaev 已提交
156
  validates :notification_level, inclusion: { in: Notification.notification_levels }, presence: true
157
  validate :namespace_uniq, if: ->(user) { user.username_changed? }
158
  validate :avatar_type, if: ->(user) { user.avatar.present? && user.avatar_changed? }
159
  validate :unique_email, if: ->(user) { user.email_changed? }
160
  validate :owns_notification_email, if: ->(user) { user.notification_email_changed? }
161
  validate :owns_public_email, if: ->(user) { user.public_email_changed? }
162
  validates :avatar, file_size: { maximum: 200.kilobytes.to_i }
163

164
  before_validation :generate_password, on: :create
165
  before_validation :restricted_signup_domains, on: :create
166
  before_validation :sanitize_attrs
167
  before_validation :set_notification_email, if: ->(user) { user.email_changed? }
168
  before_validation :set_public_email, if: ->(user) { user.public_email_changed? }
169

170
  after_update :update_emails_with_primary_email, if: ->(user) { user.email_changed? }
N
Nihad Abbasov 已提交
171
  before_save :ensure_authentication_token
D
Dmitriy Zaporozhets 已提交
172
  after_save :ensure_namespace_correct
173
  after_initialize :set_projects_limit
D
Dmitriy Zaporozhets 已提交
174 175 176
  after_create :post_create_hook
  after_destroy :post_destroy_hook

177
  # User's Layout preference
178
  enum layout: [:fixed, :fluid]
179

180 181
  # User's Dashboard preference
  # Note: When adding an option, it MUST go on the end of the array.
182
  enum dashboard: [:projects, :stars, :project_activity, :starred_project_activity]
183

184 185
  # User's Project preference
  # Note: When adding an option, it MUST go on the end of the array.
186
  enum project_view: [:readme, :activity, :files]
187

N
Nihad Abbasov 已提交
188
  alias_attribute :private_token, :authentication_token
189

190
  delegate :path, to: :namespace, allow_nil: true, prefix: true
191

192 193 194 195 196 197 198 199 200 201
  state_machine :state, initial: :active do
    event :block do
      transition active: :blocked
    end

    event :activate do
      transition blocked: :active
    end
  end

202
  mount_uploader :avatar, AvatarUploader
S
Steven Thonus 已提交
203

A
Andrey Kumanyaev 已提交
204
  # Scopes
205
  scope :admins, -> { where(admin: true) }
206 207
  scope :blocked, -> { with_state(:blocked) }
  scope :active, -> { with_state(:active) }
S
skv 已提交
208
  scope :not_in_project, ->(project) { project.users.present? ? where("id not in (:ids)", ids: project.users.map(&:id) ) : all }
209
  scope :without_projects, -> { where('id NOT IN (SELECT DISTINCT(user_id) FROM members)') }
210 211
  scope :with_two_factor,    -> { where(two_factor_enabled: true) }
  scope :without_two_factor, -> { where(two_factor_enabled: false) }
A
Andrey Kumanyaev 已提交
212

213 214 215
  #
  # Class methods
  #
A
Andrey Kumanyaev 已提交
216
  class << self
217
    # Devise method overridden to allow sign in with email or username
218 219 220 221 222 223 224 225
    def find_for_database_authentication(warden_conditions)
      conditions = warden_conditions.dup
      if login = conditions.delete(:login)
        where(conditions).where(["lower(username) = :value OR lower(email) = :value", { value: login.downcase }]).first
      else
        where(conditions).first
      end
    end
226

V
Valery Sizov 已提交
227 228
    def sort(method)
      case method.to_s
229 230 231 232
      when 'recent_sign_in' then reorder(last_sign_in_at: :desc)
      when 'oldest_sign_in' then reorder(last_sign_in_at: :asc)
      else
        order_by(method)
V
Valery Sizov 已提交
233 234 235
      end
    end

236 237
    # Find a User by their primary email or any associated secondary email
    def find_by_any_email(email)
238 239 240
      # Arel doesn't allow for chaining operations on union nodes, thus we have
      # to write this query by hand. See the following issue for more info:
      # https://github.com/rails/arel/issues/98.
Y
Yorick Peterse 已提交
241
      sql = '(SELECT * FROM users WHERE email = :email)
242
      UNION
Y
Yorick Peterse 已提交
243
      (SELECT users.*
244 245 246 247 248 249
      FROM emails
      INNER JOIN users ON users.id = emails.user_id
      WHERE emails.email = :email)
      LIMIT 1;'

      User.find_by_sql([sql, { email: email }]).first
250
    end
251

252
    def filter(filter_name)
A
Andrey Kumanyaev 已提交
253
      case filter_name
254 255 256 257 258 259 260 261 262 263
      when 'admins'
        self.admins
      when 'blocked'
        self.blocked
      when 'two_factor_disabled'
        self.without_two_factor
      when 'two_factor_enabled'
        self.with_two_factor
      when 'wop'
        self.without_projects
A
Andrey Kumanyaev 已提交
264 265 266
      else
        self.active
      end
267 268
    end

269
    def search(query)
270
      where("lower(name) LIKE :query OR lower(email) LIKE :query OR lower(username) LIKE :query", query: "%#{query.downcase}%")
A
Andrey Kumanyaev 已提交
271
    end
272

273
    def by_login(login)
274 275 276 277 278 279 280
      return nil unless login

      if login.include?('@'.freeze)
        unscoped.iwhere(email: login).take
      else
        unscoped.iwhere(username: login).take
      end
281 282
    end

R
Robert Speicher 已提交
283 284 285 286
    def find_by_username!(username)
      find_by!('lower(username) = ?', username.downcase)
    end

287
    def by_username_or_id(name_or_id)
288
      where('users.username = ? OR users.id = ?', name_or_id.to_s, name_or_id.to_i).first
289
    end
290

291 292
    def build_user(attrs = {})
      User.new(attrs)
293
    end
294 295 296 297

    def reference_prefix
      '@'
    end
298 299 300 301 302 303 304 305

    # Pattern used to extract `@user` user references from text
    def reference_pattern
      %r{
        #{Regexp.escape(reference_prefix)}
        (?<user>#{Gitlab::Regex::NAMESPACE_REGEX_STR})
      }x
    end
V
vsizov 已提交
306
  end
R
randx 已提交
307

308 309 310
  #
  # Instance methods
  #
311 312 313 314 315

  def to_param
    username
  end

316 317 318 319
  def to_reference(_from_project = nil)
    "#{self.class.reference_prefix}#{username}"
  end

D
Dmitriy Zaporozhets 已提交
320 321 322 323
  def notification
    @notification ||= Notification.new(self)
  end

A
Andrey Kumanyaev 已提交
324 325 326 327
  def generate_password
    if self.force_random_password
      self.password = self.password_confirmation = Devise.friendly_token.first(8)
    end
R
randx 已提交
328
  end
329

330
  def generate_reset_token
M
Marin Jankovski 已提交
331
    @reset_token, enc = Devise.token_generator.generate(self.class, :reset_password_token)
332 333 334 335

    self.reset_password_token   = enc
    self.reset_password_sent_at = Time.now.utc

M
Marin Jankovski 已提交
336
    @reset_token
337 338
  end

339 340 341 342
  def recently_sent_password_reset?
    reset_password_sent_at.present? && reset_password_sent_at >= 1.minute.ago
  end

R
Robert Speicher 已提交
343 344 345 346 347 348 349 350 351 352
  def disable_two_factor!
    update_attributes(
      two_factor_enabled:        false,
      encrypted_otp_secret:      nil,
      encrypted_otp_secret_iv:   nil,
      encrypted_otp_secret_salt: nil,
      otp_backup_codes:          nil
    )
  end

353 354
  def namespace_uniq
    namespace_name = self.username
355 356
    existing_namespace = Namespace.by_path(namespace_name)
    if existing_namespace && existing_namespace != self.namespace
L
lol768 已提交
357
      self.errors.add :username, "already exists"
358 359
    end
  end
360

361 362 363 364 365 366
  def avatar_type
    unless self.avatar.image?
      self.errors.add :avatar, "only images allowed"
    end
  end

367
  def unique_email
368 369 370
    if !self.emails.exists?(email: self.email) && Email.exists?(email: self.email)
      self.errors.add(:email, 'has already been taken')
    end
371 372
  end

373 374 375 376
  def owns_notification_email
    self.errors.add(:notification_email, "is not an email you own") unless self.all_emails.include?(self.notification_email)
  end

377
  def owns_public_email
378 379
    return if self.public_email.blank?

380 381 382 383 384 385 386 387
    self.errors.add(:public_email, "is not an email you own") unless self.all_emails.include?(self.public_email)
  end

  def update_emails_with_primary_email
    primary_email_record = self.emails.find_by(email: self.email)
    if primary_email_record
      primary_email_record.destroy
      self.emails.create(email: self.email_was)
388

389 390 391 392
      self.update_secondary_emails!
    end
  end

393 394
  # Groups user has access to
  def authorized_groups
395
    @authorized_groups ||= begin
396
                             group_ids = (groups.pluck(:id) + authorized_projects.pluck(:namespace_id))
397
                             Group.where(id: group_ids)
398
                           end
399 400
  end

K
Kamil Trzcinski 已提交
401 402 403 404 405 406 407
  def authorized_projects_id
    @authorized_projects_id ||= begin
      project_ids = personal_projects.pluck(:id)
      project_ids.push(*groups_projects.pluck(:id))
      project_ids.push(*projects.pluck(:id).uniq)
    end
  end
408 409 410

  # Projects user has access to
  def authorized_projects
K
Kamil Trzcinski 已提交
411
    @authorized_projects ||= Project.where(id: authorized_projects_id)
412 413
  end

414
  def owned_projects
415 416 417 418 419
    @owned_projects ||=
      begin
        namespace_ids = owned_groups.pluck(:id).push(namespace.id)
        Project.in_namespace(namespace_ids).joins(:namespace)
      end
420 421
  end

422 423
  # Team membership in authorized projects
  def tm_in_authorized_projects
424
    ProjectMember.where(source_id: authorized_projects.map(&:id), user_id: self.id)
425
  end
D
Dmitriy Zaporozhets 已提交
426 427 428 429 430 431 432 433 434

  def is_admin?
    admin
  end

  def require_ssh_key?
    keys.count == 0
  end

435 436 437 438
  def require_password?
    password_automatically_set? && !ldap_user?
  end

439
  def can_change_username?
440
    gitlab_config.username_changing_enabled
441 442
  end

D
Dmitriy Zaporozhets 已提交
443
  def can_create_project?
444
    projects_limit_left > 0
D
Dmitriy Zaporozhets 已提交
445 446 447
  end

  def can_create_group?
448
    can?(:create_group, nil)
D
Dmitriy Zaporozhets 已提交
449 450 451
  end

  def abilities
C
Ciro Santilli 已提交
452
    Ability.abilities
D
Dmitriy Zaporozhets 已提交
453 454
  end

455 456 457 458
  def can_select_namespace?
    several_namespaces? || admin
  end

459
  def can?(action, subject)
D
Dmitriy Zaporozhets 已提交
460 461 462 463 464 465 466 467
    abilities.allowed?(self, action, subject)
  end

  def first_name
    name.split.first unless name.blank?
  end

  def cared_merge_requests
468
    MergeRequest.cared(self)
D
Dmitriy Zaporozhets 已提交
469 470
  end

471
  def projects_limit_left
472
    projects_limit - personal_projects.count
473 474
  end

D
Dmitriy Zaporozhets 已提交
475 476
  def projects_limit_percent
    return 100 if projects_limit.zero?
477
    (personal_projects.count.to_f / projects_limit) * 100
D
Dmitriy Zaporozhets 已提交
478 479
  end

480
  def recent_push(project_id = nil)
D
Dmitriy Zaporozhets 已提交
481 482 483 484
    # Get push events not earlier than 2 hours ago
    events = recent_events.code_push.where("created_at > ?", Time.now - 2.hours)
    events = events.where(project_id: project_id) if project_id

485 486 487 488 489 490 491 492 493 494 495 496 497
    # Use the latest event that has not been pushed or merged recently
    events.recent.find do |event|
      project = Project.find_by_id(event.project_id)
      next unless project
      repo = project.repository

      if repo.branch_names.include?(event.branch_name)
        merge_requests = MergeRequest.where("created_at >= ?", event.created_at).
            where(source_project_id: project.id,
                  source_branch: event.branch_name)
        merge_requests.empty?
      end
    end
D
Dmitriy Zaporozhets 已提交
498 499 500 501 502 503 504
  end

  def projects_sorted_by_activity
    authorized_projects.sorted_by_activity
  end

  def several_namespaces?
505
    owned_groups.any? || masters_groups.any?
D
Dmitriy Zaporozhets 已提交
506 507 508 509 510
  end

  def namespace_id
    namespace.try :id
  end
511

512 513 514
  def name_with_username
    "#{name} (#{username})"
  end
D
Dmitriy Zaporozhets 已提交
515 516

  def tm_of(project)
517
    project.project_member_by_id(self.id)
D
Dmitriy Zaporozhets 已提交
518
  end
519

520
  def already_forked?(project)
521 522 523
    !!fork_of(project)
  end

524
  def fork_of(project)
525 526 527 528 529 530 531 532
    links = ForkedProjectLink.where(forked_from_project_id: project, forked_to_project_id: personal_projects)

    if links.any?
      links.first.forked_to_project
    else
      nil
    end
  end
533 534

  def ldap_user?
535 536 537 538 539
    identities.exists?(["provider LIKE ? AND extern_uid IS NOT NULL", "ldap%"])
  end

  def ldap_identity
    @ldap_identity ||= identities.find_by(["provider LIKE ?", "ldap%"])
540
  end
541

542
  def project_deploy_keys
543
    DeployKey.unscoped.in_projects(self.authorized_projects.pluck(:id)).distinct(:id)
544 545
  end

546
  def accessible_deploy_keys
547 548 549 550 551
    @accessible_deploy_keys ||= begin
      key_ids = project_deploy_keys.pluck(:id)
      key_ids.push(*DeployKey.are_public.pluck(:id))
      DeployKey.where(id: key_ids)
    end
552
  end
553 554

  def created_by
S
skv 已提交
555
    User.find_by(id: created_by_id) if created_by_id
556
  end
557 558

  def sanitize_attrs
559
    %w(name username skype linkedin twitter).each do |attr|
560 561 562 563
      value = self.send(attr)
      self.send("#{attr}=", Sanitize.clean(value)) if value.present?
    end
  end
564

565 566
  def set_notification_email
    if self.notification_email.blank? || !self.all_emails.include?(self.notification_email)
567
      self.notification_email = self.email
568 569 570
    end
  end

571 572
  def set_public_email
    if self.public_email.blank? || !self.all_emails.include?(self.public_email)
573
      self.public_email = ''
574 575 576
    end
  end

577 578 579 580 581 582
  def update_secondary_emails!
    self.set_notification_email
    self.set_public_email
    self.save if self.notification_email_changed? || self.public_email_changed?
  end

583 584 585 586 587 588 589
  def set_projects_limit
    connection_default_value_defined = new_record? && !projects_limit_changed?
    return unless self.projects_limit.nil? || connection_default_value_defined

    self.projects_limit = current_application_settings.default_projects_limit
  end

590
  def requires_ldap_check?
591 592 593
    if !Gitlab.config.ldap.enabled
      false
    elsif ldap_user?
594 595 596 597 598 599
      !last_credential_check_at || (last_credential_check_at + 1.hour) < Time.now
    else
      false
    end
  end

600 601 602 603 604
  def solo_owned_groups
    @solo_owned_groups ||= owned_groups.select do |group|
      group.owners == [self]
    end
  end
605 606

  def with_defaults
607 608
    User.defaults.each do |k, v|
      self.send("#{k}=", v)
609
    end
610 611

    self
612
  end
613

614 615 616 617
  def can_leave_project?(project)
    project.namespace != namespace &&
      project.project_member(self)
  end
618 619 620 621 622 623 624 625 626 627 628 629 630 631

  # Reset project events cache related to this user
  #
  # Since we do cache @event we need to reset cache in special cases:
  # * when the user changes their avatar
  # Events cache stored like  events/23-20130109142513.
  # The cache key includes updated_at timestamp.
  # Thus it will automatically generate a new fragment
  # when the event is updated because the key changes.
  def reset_events_cache
    Event.where(author_id: self.id).
      order('id DESC').limit(1000).
      update_all(updated_at: Time.now)
  end
J
Jerome Dalbert 已提交
632 633

  def full_website_url
634
    return "http://#{website_url}" if website_url !~ /\Ahttps?:\/\//
J
Jerome Dalbert 已提交
635 636 637 638 639

    website_url
  end

  def short_website_url
640
    website_url.sub(/\Ahttps?:\/\//, '')
J
Jerome Dalbert 已提交
641
  end
G
GitLab 已提交
642

643
  def all_ssh_keys
644
    keys.map(&:publishable_key)
645
  end
646 647

  def temp_oauth_email?
648
    email.start_with?('temp-email-for-oauth')
649 650
  end

651 652
  def avatar_url(size = nil)
    if avatar.present?
653
      [gitlab_config.url, avatar.url].join
654
    else
655
      GravatarService.new.execute(email, size)
656 657
    end
  end
D
Dmitriy Zaporozhets 已提交
658

659 660 661 662
  def all_emails
    [self.email, *self.emails.map(&:email)]
  end

K
Kirill Zaitsev 已提交
663 664 665 666 667 668 669 670
  def hook_attrs
    {
      name: name,
      username: username,
      avatar_url: avatar_url
    }
  end

D
Dmitriy Zaporozhets 已提交
671 672 673 674 675 676 677 678 679 680 681
  def ensure_namespace_correct
    # Ensure user has namespace
    self.create_namespace!(path: self.username, name: self.username) unless self.namespace

    if self.username_changed?
      self.namespace.update_attributes(path: self.username, name: self.username)
    end
  end

  def post_create_hook
    log_info("User \"#{self.name}\" (#{self.email}) was created")
682
    notification_service.new_user(self, @reset_token) if self.created_by_id
D
Dmitriy Zaporozhets 已提交
683 684 685 686 687 688 689 690
    system_hook_service.execute_hooks_for(self, :create)
  end

  def post_destroy_hook
    log_info("User \"#{self.name}\" (#{self.email})  was removed")
    system_hook_service.execute_hooks_for(self, :destroy)
  end

D
Dmitriy Zaporozhets 已提交
691
  def notification_service
D
Dmitriy Zaporozhets 已提交
692 693 694
    NotificationService.new
  end

695
  def log_info(message)
D
Dmitriy Zaporozhets 已提交
696 697 698 699 700 701
    Gitlab::AppLogger.info message
  end

  def system_hook_service
    SystemHooksService.new
  end
C
Ciro Santilli 已提交
702 703 704 705 706 707

  def starred?(project)
    starred_projects.exists?(project)
  end

  def toggle_star(project)
708 709 710 711 712 713 714 715 716
    UsersStarProject.transaction do
      user_star_project = users_star_projects.
          where(project: project, user: self).lock(true).first

      if user_star_project
        user_star_project.destroy
      else
        UsersStarProject.create!(project: project, user: self)
      end
C
Ciro Santilli 已提交
717 718
    end
  end
719 720

  def manageable_namespaces
G
Guilherme Garnier 已提交
721
    @manageable_namespaces ||= [namespace] + owned_groups + masters_groups
722
  end
D
Dmitriy Zaporozhets 已提交
723

724 725 726 727 728 729
  def namespaces
    namespace_ids = groups.pluck(:id)
    namespace_ids.push(namespace.id)
    Namespace.where(id: namespace_ids)
  end

D
Dmitriy Zaporozhets 已提交
730 731 732
  def oauth_authorized_tokens
    Doorkeeper::AccessToken.where(resource_owner_id: self.id, revoked_at: nil)
  end
733 734

  def contributed_projects_ids
735
    Event.contributions.where(author_id: self).
736
      where("created_at > ?", Time.now - 1.year).
737
      reorder(project_id: :desc).
738
      select(:project_id).
739
      uniq.map(&:project_id)
740
  end
741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763

  def restricted_signup_domains
    email_domains = current_application_settings.restricted_signup_domains

    unless email_domains.blank?
      match_found = email_domains.any? do |domain|
        escaped = Regexp.escape(domain).gsub('\*','.*?')
        regexp = Regexp.new "^#{escaped}$", Regexp::IGNORECASE
        email_domain = Mail::Address.new(self.email).domain
        email_domain =~ regexp
      end

      unless match_found
        self.errors.add :email,
                        'is not whitelisted. ' +
                        'Email domains valid for registration are: ' +
                        email_domains.join(', ')
        return false
      end
    end

    true
  end
764 765 766 767

  def can_be_removed?
    !solo_owned_groups.present?
  end
768 769

  def ci_authorized_projects
K
Kamil Trzcinski 已提交
770
    @ci_authorized_projects ||= Ci::Project.where(gitlab_id: authorized_projects_id)
771 772 773
  end

  def ci_authorized_runners
K
Kamil Trzcinski 已提交
774 775 776 777 778
    @ci_authorized_runners ||= begin
      runner_ids = Ci::RunnerProject.joins(:project).
        where(ci_projects: { gitlab_id: authorized_projects_id }).select(:runner_id)
      Ci::Runner.specific.where(id: runner_ids)
    end
779
  end
G
gitlabhq 已提交
780
end