//--------------------------------------------------------------------------------------// void Http_getMailboxes(T R) { const char *mailbox = Request_getId(R); TRACE(TRACE_DEBUG,"mailbox [%s]", mailbox); char *endptr = NULL; struct evbuffer *buf; uint64_t id = 0; if (! mailbox) { Request_error(R, HTTP_SERVUNAVAIL, "Server error"); return; } if (! (id = strtoull(mailbox, &endptr, 10))) { Request_error(R, HTTP_NOTFOUND, "Not found"); return; } TRACE(TRACE_DEBUG,"mailbox id [%lu]", id); buf = evbuffer_new(); Request_setContentType(R,"application/json; charset=utf-8"); if (Request_getMethod(R) == NULL) { /* * retrieve mailbox meta-data * C < GET /mailboxes/876 * * or * * append a new message * C < POST /mailboxes/876 */ const char *msg; uint64_t msg_id = 0; MailboxState_T b = MailboxState_new(id); unsigned exists = MailboxState_getExists(b); if ((msg = evhttp_find_header(Request_getPOST(R),"message"))) { if (! db_append_msg(msg, MailboxState_getId(b), MailboxState_getOwner(b), NULL, &msg_id, TRUE)) exists++; } evbuffer_add_printf(buf, "{\"mailboxes\": {\n"); evbuffer_add_printf(buf, " \"%lu\":{\"name\":\"%s\",\"exists\":%d}", MailboxState_getId(b), MailboxState_getName(b), exists); evbuffer_add_printf(buf, "\n}}\n"); MailboxState_free(&b); } else if (MATCH(Request_getMethod(R),"messages")) { /* * list messages in mailbox * C < GET /mailboxes/876/messages */ MailboxState_T b = MailboxState_new(id); GTree *msns = MailboxState_getMsn(b); GList *ids = g_tree_keys(msns); GTree *msginfo = MailboxState_getMsginfo(b); evbuffer_add_printf(buf, "{\"messages\": {\n"); while (ids && ids->data) { uint64_t *msn = (uint64_t *)ids->data; uint64_t *uid = (uint64_t *)g_tree_lookup(msns, msn); MessageInfo *info = (MessageInfo *)g_tree_lookup(msginfo, uid); evbuffer_add_printf(buf, " \"%lu\":{\"size\":%lu}", *uid, info->rfcsize); if (! g_list_next(ids)) break; ids = g_list_next(ids); evbuffer_add_printf(buf,",\n"); } evbuffer_add_printf(buf, "\n}}\n"); if (ids) g_list_free(g_list_first(ids)); MailboxState_free(&b); } if (EVBUFFER_LENGTH(buf)) Request_send(R, HTTP_OK, "OK", buf); else Request_error(R, HTTP_SERVUNAVAIL, "Server error"); evbuffer_free(buf); }
int MailboxState_hasPermission(T M, uint64_t userid, const char *right_flag) { PreparedStatement_T stmt; Connection_T c; ResultSet_T r; volatile int result = FALSE; volatile bool owner_acl = false; uint64_t owner_id, mboxid; mboxid = MailboxState_getId(M); TRACE(TRACE_DEBUG, "checking ACL [%s] for user [%" PRIu64 "] on mailbox [%" PRIu64 "]", right_flag, userid, mboxid); /* If we don't know who owns the mailbox, look it up. */ owner_id = MailboxState_getOwner(M); if (! owner_id) { result = db_get_mailbox_owner(mboxid, &owner_id); MailboxState_setOwner(M, owner_id); if (! (result > 0)) return result; } if (owner_id == userid) { c = db_con_get(); TRY stmt = db_stmt_prepare(c, "SELECT * FROM %sacl WHERE " "user_id = ? AND mailbox_id = ?", DBPFX); db_stmt_set_u64(stmt, 1, userid); db_stmt_set_u64(stmt, 2, mboxid); r = db_stmt_query(stmt); if (db_result_next(r)) owner_acl = true; CATCH(SQLException) LOG_SQLERROR; result = DM_EQUERY; FINALLY db_con_close(c); END_TRY; if (! owner_acl) { TRACE(TRACE_DEBUG, "mailbox [%" PRIu64 "] is owned by user [%" PRIu64 "]" "and no ACL in place. Giving all rights", mboxid, userid); return 1; } else { TRACE(TRACE_DEBUG, "mailbox [%" PRIu64 "] is owned by user [%" PRIu64 "]" "but ACL in place. Restricted access for owner.", mboxid, userid); } } result = FALSE; c = db_con_get(); TRY stmt = db_stmt_prepare(c, "SELECT * FROM %sacl WHERE " "user_id = ? AND mailbox_id = ? AND %s = 1", DBPFX, right_flag); db_stmt_set_u64(stmt, 1, userid); db_stmt_set_u64(stmt, 2, mboxid); r = db_stmt_query(stmt); if (db_result_next(r)) result = TRUE; CATCH(SQLException) LOG_SQLERROR; result = DM_EQUERY; FINALLY db_con_close(c); END_TRY; return result; }