0
0
Fork 0
mirror of https://github.com/matrix-construct/construct synced 2024-11-25 00:02:34 +01:00
construct/modules/client/delete_devices.cc
2020-04-01 19:52:31 -07:00

120 lines
2.3 KiB
C++

// Matrix Construct
//
// Copyright (C) Matrix Construct Developers, Authors & Contributors
// Copyright (C) 2016-2019 Jason Volk <jason@zemos.net>
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice is present in all copies. The
// full license for this software is available in the LICENSE file.
using namespace ircd;
static m::resource::response
post__delete_devices(client &client,
const m::resource::request &request);
extern const std::string flows;
mapi::header
IRCD_MODULE
{
"Client 14.10.1.5 :Device Management"
};
ircd::m::resource
delete_devices_resource
{
"/_matrix/client/r0/delete_devices/",
{
"14.10.1.5 :Device Management"
}
};
ircd::m::resource
delete_devices_resource__unstable
{
"/_matrix/client/unstable/delete_devices/",
{
"14.10.1.5 :Device Management (redirect)"
}
};
m::resource::method
method_post
{
delete_devices_resource, "POST", post__delete_devices,
{
method_post.REQUIRES_AUTH
}
};
m::resource::method
method_post__unstable
{
delete_devices_resource__unstable, "POST", post__delete_devices,
{
method_post.REQUIRES_AUTH
}
};
m::resource::response
post__delete_devices(client &client,
const m::resource::request &request)
{
const json::array &devices
{
request.at("devices")
};
const json::object &auth
{
request["auth"]
};
// 14.10.2 Security considerations
const json::string &type{auth["type"]};
if(type != "m.login.password")
return m::resource::response
{
client, http::UNAUTHORIZED, json::object{flows}
};
const json::string &password{auth["password"]};
if(!m::user(request.user_id).is_password(password))
throw m::ACCESS_DENIED
{
"Incorrect password."
};
const m::user::devices user_devices
{
request.user_id
};
for(const json::string &device_id : devices)
user_devices.del(device_id);
return m::resource::response
{
client, http::OK
};
}
const std::string
flows
{
ircd::string(512 | SHRINK_TO_FIT, [](const mutable_buffer &buf)
{
json::stack out{buf};
{
json::stack::object top{out};
json::stack::array flows{top, "flows"};
json::stack::object flow{flows};
json::stack::array stages{flow, "stages"};
stages.append("m.login.password");
}
return out.completed();
})
};