package handlers import ( "net/http" "strings" "github.com/gin-contrib/sessions" "github.com/gin-gonic/gin" "gorm.io/gorm" "go_blog/models" ) // LoginPage renders the login form. func LoginPage() gin.HandlerFunc { return func(c *gin.Context) { tr := getTr(c) data := DefaultData(c) data["Title"] = tr["page_login"] if c.Query("error") == "1" { data["Error"] = tr["login_error"] } // Check if registration is allowed from site settings siteSetting, _ := c.Get("site_setting") if s, ok := siteSetting.(*models.SiteSetting); ok && s != nil { data["AllowRegistration"] = s.AllowRegistration } c.HTML(http.StatusOK, "login", data) } } // Login processes the login form submission. func Login(db *gorm.DB) gin.HandlerFunc { return func(c *gin.Context) { username := c.PostForm("username") password := c.PostForm("password") var user models.User if err := db.Where("username = ?", username).First(&user).Error; err != nil { c.Redirect(http.StatusFound, "/login?error=1") return } if !user.CheckPassword(password) { c.Redirect(http.StatusFound, "/login?error=1") return } // Refuse login for non-normal accounts (disabled / locked / unactivated). if user.Status != models.StatusNormal { c.Redirect(http.StatusFound, "/login?error=1") return } // Create session. session := sessions.Default(c) session.Set("user_id", user.ID) session.Set("username", user.Username) if err := session.Save(); err != nil { c.String(http.StatusInternalServerError, "Failed to save session") return } // Redirect based on user role: admins to /admin, others to home if user.Role == models.RoleAdmin { c.Redirect(http.StatusFound, "/admin") } else { c.Redirect(http.StatusFound, "/") } } } // Logout clears the session and redirects home. func Logout() gin.HandlerFunc { return func(c *gin.Context) { session := sessions.Default(c) session.Clear() session.Save() c.Redirect(http.StatusFound, "/") } } // RegisterPage renders the registration form (only when registration is enabled). func RegisterPage(db *gorm.DB) gin.HandlerFunc { return func(c *gin.Context) { // Check if registration is allowed var s models.SiteSetting if err := db.First(&s, 1).Error; err != nil || !s.AllowRegistration { c.Redirect(http.StatusFound, "/login") return } tr := getTr(c) data := DefaultData(c) data["Title"] = tr["page_register"] if errMsg := c.Query("error"); errMsg != "" { data["Error"] = tr[errMsg] } c.HTML(http.StatusOK, "register", data) } } // Register processes the registration form submission. func Register(db *gorm.DB) gin.HandlerFunc { return func(c *gin.Context) { // Check if registration is allowed var s models.SiteSetting if err := db.First(&s, 1).Error; err != nil || !s.AllowRegistration { c.Redirect(http.StatusFound, "/login") return } username := strings.TrimSpace(c.PostForm("username")) password := c.PostForm("password") confirmPassword := c.PostForm("confirm_password") email := strings.TrimSpace(c.PostForm("email")) displayName := strings.TrimSpace(c.PostForm("display_name")) // Validate inputs if username == "" || password == "" { c.Redirect(http.StatusFound, "/register?error=register_required") return } if len(username) < 3 || len(username) > 32 { c.Redirect(http.StatusFound, "/register?error=register_username_length") return } if len(password) < 6 { c.Redirect(http.StatusFound, "/register?error=register_password_length") return } if password != confirmPassword { c.Redirect(http.StatusFound, "/register?error=register_password_mismatch") return } // Check if username already exists var existingUser models.User if err := db.Where("username = ?", username).First(&existingUser).Error; err == nil { c.Redirect(http.StatusFound, "/register?error=user_username_exists") return } // Create new user user := models.User{ Username: username, Email: email, DisplayName: displayName, Role: models.RoleAuthor, Status: models.StatusNormal, } if displayName == "" { user.DisplayName = username } if err := user.SetPassword(password); err != nil { c.Redirect(http.StatusFound, "/register?error=register_error") return } if err := db.Create(&user).Error; err != nil { c.Redirect(http.StatusFound, "/register?error=register_error") return } // Auto-login after successful registration session := sessions.Default(c) session.Set("user_id", user.ID) session.Set("username", user.Username) if err := session.Save(); err != nil { c.Redirect(http.StatusFound, "/login") return } // Redirect to home page c.Redirect(http.StatusFound, "/") } }