BigW Consortium Gitlab

user.rb 25.7 KB
Newer Older
1 2 3 4
# == Schema Information
#
# Table name: users
#
Stan Hu committed
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61
#  id                          :integer          not null, primary key
#  email                       :string(255)      default(""), not null
#  encrypted_password          :string(255)      default(""), not null
#  reset_password_token        :string(255)
#  reset_password_sent_at      :datetime
#  remember_created_at         :datetime
#  sign_in_count               :integer          default(0)
#  current_sign_in_at          :datetime
#  last_sign_in_at             :datetime
#  current_sign_in_ip          :string(255)
#  last_sign_in_ip             :string(255)
#  created_at                  :datetime
#  updated_at                  :datetime
#  name                        :string(255)
#  admin                       :boolean          default(FALSE), not null
#  projects_limit              :integer          default(10)
#  skype                       :string(255)      default(""), not null
#  linkedin                    :string(255)      default(""), not null
#  twitter                     :string(255)      default(""), not null
#  authentication_token        :string(255)
#  theme_id                    :integer          default(1), not null
#  bio                         :string(255)
#  failed_attempts             :integer          default(0)
#  locked_at                   :datetime
#  username                    :string(255)
#  can_create_group            :boolean          default(TRUE), not null
#  can_create_team             :boolean          default(TRUE), not null
#  state                       :string(255)
#  color_scheme_id             :integer          default(1), not null
#  notification_level          :integer          default(1), not null
#  password_expires_at         :datetime
#  created_by_id               :integer
#  last_credential_check_at    :datetime
#  avatar                      :string(255)
#  confirmation_token          :string(255)
#  confirmed_at                :datetime
#  confirmation_sent_at        :datetime
#  unconfirmed_email           :string(255)
#  hide_no_ssh_key             :boolean          default(FALSE)
#  website_url                 :string(255)      default(""), not null
#  notification_email          :string(255)
#  hide_no_password            :boolean          default(FALSE)
#  password_automatically_set  :boolean          default(FALSE)
#  location                    :string(255)
#  encrypted_otp_secret        :string(255)
#  encrypted_otp_secret_iv     :string(255)
#  encrypted_otp_secret_salt   :string(255)
#  otp_required_for_login      :boolean          default(FALSE), not null
#  otp_backup_codes            :text
#  public_email                :string(255)      default(""), not null
#  dashboard                   :integer          default(0)
#  project_view                :integer          default(0)
#  consumed_timestep           :integer
#  layout                      :integer          default(0)
#  hide_project_limit          :boolean          default(FALSE)
#  unlock_token                :string
#  otp_grace_period_started_at :datetime
Zeger-Jan van de Weg committed
62
#  external                    :boolean           default(FALSE)
63 64
#

65 66 67
require 'carrierwave/orm/activerecord'
require 'file_size_validator'

gitlabhq committed
68
class User < ActiveRecord::Base
69
  extend Gitlab::ConfigHelper
70 71

  include Gitlab::ConfigHelper
72
  include Gitlab::CurrentSettings
73 74
  include Referable
  include Sortable
75
  include CaseSensitivity
76 77 78
  include TokenAuthenticatable

  add_authentication_token_field :authentication_token
79

80
  default_value_for :admin, false
Zeger-Jan van de Weg committed
81
  default_value_for :external, false
82
  default_value_for :can_create_group, gitlab_config.default_can_create_group
83 84
  default_value_for :can_create_team, false
  default_value_for :hide_no_ssh_key, false
85
  default_value_for :hide_no_password, false
86
  default_value_for :theme_id, gitlab_config.default_theme
87

88 89
  devise :two_factor_authenticatable,
         otp_secret_encryption_key: File.read(Rails.root.join('.secret')).chomp
90
  alias_attribute :two_factor_enabled, :otp_required_for_login
91

92
  devise :two_factor_backupable, otp_number_of_backup_codes: 10
93 94
  serialize :otp_backup_codes, JSON

95 96
  devise :lockable, :async, :recoverable, :rememberable, :trackable,
    :validatable, :omniauthable, :confirmable, :registerable
gitlabhq committed
97

98
  attr_accessor :force_random_password
gitlabhq committed
99

100 101 102
  # Virtual attribute for authenticating by either username or email
  attr_accessor :login

103 104 105 106
  #
  # Relations
  #

107
  # Namespace for personal projects
108
  has_one :namespace, -> { where type: nil }, dependent: :destroy, foreign_key: :owner_id, class_name: "Namespace"
109 110 111

  # Profile
  has_many :keys, dependent: :destroy
112
  has_many :emails, dependent: :destroy
113
  has_many :identities, dependent: :destroy, autosave: true
114 115

  # Groups
116 117 118 119
  has_many :members, dependent: :destroy
  has_many :project_members, source: 'ProjectMember'
  has_many :group_members, source: 'GroupMember'
  has_many :groups, through: :group_members
120 121
  has_many :owned_groups, -> { where members: { access_level: Gitlab::Access::OWNER } }, through: :group_members, source: :group
  has_many :masters_groups, -> { where members: { access_level: Gitlab::Access::MASTER } }, through: :group_members, source: :group
122

123
  # Projects
124 125
  has_many :groups_projects,          through: :groups, source: :projects
  has_many :personal_projects,        through: :namespace, source: :projects
126
  has_many :projects,                 through: :project_members
127
  has_many :created_projects,         foreign_key: :creator_id, class_name: 'Project'
Ciro Santilli committed
128 129
  has_many :users_star_projects, dependent: :destroy
  has_many :starred_projects, through: :users_star_projects, source: :project
130

131
  has_many :snippets,                 dependent: :destroy, foreign_key: :author_id, class_name: "Snippet"
132
  has_many :project_members,          dependent: :destroy, class_name: 'ProjectMember'
133 134 135 136
  has_many :issues,                   dependent: :destroy, foreign_key: :author_id
  has_many :notes,                    dependent: :destroy, foreign_key: :author_id
  has_many :merge_requests,           dependent: :destroy, foreign_key: :author_id
  has_many :events,                   dependent: :destroy, foreign_key: :author_id,   class_name: "Event"
137
  has_many :subscriptions,            dependent: :destroy
138
  has_many :recent_events, -> { order "id DESC" }, foreign_key: :author_id,   class_name: "Event"
139 140
  has_many :assigned_issues,          dependent: :destroy, foreign_key: :assignee_id, class_name: "Issue"
  has_many :assigned_merge_requests,  dependent: :destroy, foreign_key: :assignee_id, class_name: "MergeRequest"
Valery Sizov committed
141
  has_many :oauth_applications, class_name: 'Doorkeeper::Application', as: :owner, dependent: :destroy
142
  has_one  :abuse_report,             dependent: :destroy
143
  has_many :spam_logs,                dependent: :destroy
144
  has_many :builds,                   dependent: :nullify, class_name: 'Ci::Build'
145
  has_many :todos,                    dependent: :destroy
146

147 148 149
  #
  # Validations
  #
Cyril committed
150
  validates :name, presence: true
151 152
  validates :notification_email, presence: true, email: true
  validates :public_email, presence: true, uniqueness: true, email: true, allow_blank: true
153
  validates :bio, length: { maximum: 255 }, allow_blank: true
154
  validates :projects_limit, presence: true, numericality: { greater_than_or_equal_to: 0 }
155
  validates :username,
156
    namespace: true,
157
    presence: true,
158
    uniqueness: { case_sensitive: false }
159

Andrey Kumanyaev committed
160
  validates :notification_level, inclusion: { in: Notification.notification_levels }, presence: true
161
  validate :namespace_uniq, if: ->(user) { user.username_changed? }
162
  validate :avatar_type, if: ->(user) { user.avatar.present? && user.avatar_changed? }
163
  validate :unique_email, if: ->(user) { user.email_changed? }
164
  validate :owns_notification_email, if: ->(user) { user.notification_email_changed? }
165
  validate :owns_public_email, if: ->(user) { user.public_email_changed? }
166
  validates :avatar, file_size: { maximum: 200.kilobytes.to_i }
167

168
  before_validation :generate_password, on: :create
169
  before_validation :restricted_signup_domains, on: :create
170
  before_validation :sanitize_attrs
171
  before_validation :set_notification_email, if: ->(user) { user.email_changed? }
172
  before_validation :set_public_email, if: ->(user) { user.public_email_changed? }
173

174
  after_update :update_emails_with_primary_email, if: ->(user) { user.email_changed? }
175
  before_save :ensure_authentication_token
Zeger-Jan van de Weg committed
176
  before_save :ensure_external_user_rights
177
  after_save :ensure_namespace_correct
178
  after_initialize :set_projects_limit
179 180 181
  after_create :post_create_hook
  after_destroy :post_destroy_hook

182
  # User's Layout preference
183
  enum layout: [:fixed, :fluid]
184

185 186
  # User's Dashboard preference
  # Note: When adding an option, it MUST go on the end of the array.
187
  enum dashboard: [:projects, :stars, :project_activity, :starred_project_activity]
188

189 190
  # User's Project preference
  # Note: When adding an option, it MUST go on the end of the array.
191
  enum project_view: [:readme, :activity, :files]
192

193
  alias_attribute :private_token, :authentication_token
194

195
  delegate :path, to: :namespace, allow_nil: true, prefix: true
196

197 198 199
  state_machine :state, initial: :active do
    event :block do
      transition active: :blocked
200
      transition ldap_blocked: :blocked
201 202
    end

203 204 205 206
    event :ldap_block do
      transition active: :ldap_blocked
    end

207 208
    event :activate do
      transition blocked: :active
209
      transition ldap_blocked: :active
210
    end
211 212 213 214 215 216

    state :blocked, :ldap_blocked do
      def blocked?
        true
      end
    end
217 218
  end

219
  mount_uploader :avatar, AvatarUploader
220

Andrey Kumanyaev committed
221
  # Scopes
222
  scope :admins, -> { where(admin: true) }
223
  scope :blocked, -> { with_states(:blocked, :ldap_blocked) }
224
  scope :external, -> { where(external: true) }
225
  scope :active, -> { with_state(:active) }
skv committed
226
  scope :not_in_project, ->(project) { project.users.present? ? where("id not in (:ids)", ids: project.users.map(&:id) ) : all }
227
  scope :without_projects, -> { where('id NOT IN (SELECT DISTINCT(user_id) FROM members)') }
228 229
  scope :with_two_factor,    -> { where(two_factor_enabled: true) }
  scope :without_two_factor, -> { where(two_factor_enabled: false) }
Andrey Kumanyaev committed
230

231 232 233
  #
  # Class methods
  #
Andrey Kumanyaev committed
234
  class << self
235
    # Devise method overridden to allow sign in with email or username
236 237 238
    def find_for_database_authentication(warden_conditions)
      conditions = warden_conditions.dup
      if login = conditions.delete(:login)
239
        where(conditions).find_by("lower(username) = :value OR lower(email) = :value", value: login.downcase)
240
      else
241
        find_by(conditions)
242 243
      end
    end
244

Valery Sizov committed
245 246
    def sort(method)
      case method.to_s
247 248 249 250
      when 'recent_sign_in' then reorder(last_sign_in_at: :desc)
      when 'oldest_sign_in' then reorder(last_sign_in_at: :asc)
      else
        order_by(method)
Valery Sizov committed
251 252 253
      end
    end

254 255
    # Find a User by their primary email or any associated secondary email
    def find_by_any_email(email)
256 257 258 259 260 261 262
      sql = 'SELECT *
      FROM users
      WHERE id IN (
        SELECT id FROM users WHERE email = :email
        UNION
        SELECT emails.user_id FROM emails WHERE email = :email
      )
263 264 265
      LIMIT 1;'

      User.find_by_sql([sql, { email: email }]).first
266
    end
267

268
    def filter(filter_name)
Andrey Kumanyaev committed
269
      case filter_name
270 271 272 273 274 275 276 277 278 279
      when 'admins'
        self.admins
      when 'blocked'
        self.blocked
      when 'two_factor_disabled'
        self.without_two_factor
      when 'two_factor_enabled'
        self.with_two_factor
      when 'wop'
        self.without_projects
280 281
      when 'external'
        self.external
Andrey Kumanyaev committed
282 283 284
      else
        self.active
      end
285 286
    end

287 288 289 290 291 292 293
    # Searches users matching the given query.
    #
    # This method uses ILIKE on PostgreSQL and LIKE on MySQL.
    #
    # query - The search query as a String
    #
    # Returns an ActiveRecord::Relation.
294
    def search(query)
295
      table   = arel_table
296 297 298 299 300 301 302
      pattern = "%#{query}%"

      where(
        table[:name].matches(pattern).
          or(table[:email].matches(pattern)).
          or(table[:username].matches(pattern))
      )
Andrey Kumanyaev committed
303
    end
304

305
    def by_login(login)
306 307 308 309 310 311 312
      return nil unless login

      if login.include?('@'.freeze)
        unscoped.iwhere(email: login).take
      else
        unscoped.iwhere(username: login).take
      end
313 314
    end

315 316 317 318
    def find_by_username!(username)
      find_by!('lower(username) = ?', username.downcase)
    end

319
    def by_username_or_id(name_or_id)
320
      find_by('users.username = ? OR users.id = ?', name_or_id.to_s, name_or_id.to_i)
321
    end
322

323 324
    def build_user(attrs = {})
      User.new(attrs)
325
    end
326 327 328 329

    def reference_prefix
      '@'
    end
330 331 332 333 334 335 336 337

    # Pattern used to extract `@user` user references from text
    def reference_pattern
      %r{
        #{Regexp.escape(reference_prefix)}
        (?<user>#{Gitlab::Regex::NAMESPACE_REGEX_STR})
      }x
    end
vsizov committed
338
  end
randx committed
339

340 341 342
  #
  # Instance methods
  #
343 344 345 346 347

  def to_param
    username
  end

348 349 350 351
  def to_reference(_from_project = nil)
    "#{self.class.reference_prefix}#{username}"
  end

352 353 354 355
  def notification
    @notification ||= Notification.new(self)
  end

Andrey Kumanyaev committed
356 357 358 359
  def generate_password
    if self.force_random_password
      self.password = self.password_confirmation = Devise.friendly_token.first(8)
    end
randx committed
360
  end
361

362
  def generate_reset_token
363
    @reset_token, enc = Devise.token_generator.generate(self.class, :reset_password_token)
364 365 366 367

    self.reset_password_token   = enc
    self.reset_password_sent_at = Time.now.utc

368
    @reset_token
369 370
  end

371 372 373 374
  def recently_sent_password_reset?
    reset_password_sent_at.present? && reset_password_sent_at >= 1.minute.ago
  end

375 376
  def disable_two_factor!
    update_attributes(
377 378 379 380 381 382
      two_factor_enabled:          false,
      encrypted_otp_secret:        nil,
      encrypted_otp_secret_iv:     nil,
      encrypted_otp_secret_salt:   nil,
      otp_grace_period_started_at: nil,
      otp_backup_codes:            nil
383 384 385
    )
  end

386
  def namespace_uniq
387
    # Return early if username already failed the first uniqueness validation
388 389
    return if self.errors.key?(:username) &&
      self.errors[:username].include?('has already been taken')
390

391
    namespace_name = self.username
392 393
    existing_namespace = Namespace.by_path(namespace_name)
    if existing_namespace && existing_namespace != self.namespace
394
      self.errors.add(:username, 'has already been taken')
395 396
    end
  end
397

398 399 400 401 402 403
  def avatar_type
    unless self.avatar.image?
      self.errors.add :avatar, "only images allowed"
    end
  end

404
  def unique_email
405 406 407
    if !self.emails.exists?(email: self.email) && Email.exists?(email: self.email)
      self.errors.add(:email, 'has already been taken')
    end
408 409
  end

410 411 412 413
  def owns_notification_email
    self.errors.add(:notification_email, "is not an email you own") unless self.all_emails.include?(self.notification_email)
  end

414
  def owns_public_email
415 416
    return if self.public_email.blank?

417 418 419 420 421 422 423 424
    self.errors.add(:public_email, "is not an email you own") unless self.all_emails.include?(self.public_email)
  end

  def update_emails_with_primary_email
    primary_email_record = self.emails.find_by(email: self.email)
    if primary_email_record
      primary_email_record.destroy
      self.emails.create(email: self.email_was)
425

426 427 428 429
      self.update_secondary_emails!
    end
  end

430 431
  # Returns the groups a user has access to
  def authorized_groups
432
    union = Gitlab::SQL::Union.
433
      new([groups.select(:id), authorized_projects.select(:namespace_id)])
434

435
    Group.where("namespaces.id IN (#{union.to_sql})")
436 437
  end

438
  # Returns the groups a user is authorized to access.
439 440
  def authorized_projects
    Project.where("projects.id IN (#{projects_union.to_sql})")
441 442
  end

443
  def owned_projects
444
    @owned_projects ||=
445 446
      Project.where('namespace_id IN (?) OR namespace_id = ?',
                    owned_groups.select(:id), namespace.id).joins(:namespace)
447 448
  end

449 450
  # Team membership in authorized projects
  def tm_in_authorized_projects
451
    ProjectMember.where(source_id: authorized_projects.map(&:id), user_id: self.id)
452
  end
Dmitriy Zaporozhets committed
453 454 455 456 457 458 459 460 461

  def is_admin?
    admin
  end

  def require_ssh_key?
    keys.count == 0
  end

462 463 464 465
  def require_password?
    password_automatically_set? && !ldap_user?
  end

466
  def can_change_username?
467
    gitlab_config.username_changing_enabled
468 469
  end

Dmitriy Zaporozhets committed
470
  def can_create_project?
471
    projects_limit_left > 0
Dmitriy Zaporozhets committed
472 473 474
  end

  def can_create_group?
475
    can?(:create_group, nil)
Dmitriy Zaporozhets committed
476 477 478
  end

  def abilities
Ciro Santilli committed
479
    Ability.abilities
Dmitriy Zaporozhets committed
480 481
  end

482 483 484 485
  def can_select_namespace?
    several_namespaces? || admin
  end

486
  def can?(action, subject)
Dmitriy Zaporozhets committed
487 488 489 490 491 492 493 494
    abilities.allowed?(self, action, subject)
  end

  def first_name
    name.split.first unless name.blank?
  end

  def cared_merge_requests
495
    MergeRequest.cared(self)
Dmitriy Zaporozhets committed
496 497
  end

498
  def projects_limit_left
499
    projects_limit - personal_projects.count
500 501
  end

Dmitriy Zaporozhets committed
502 503
  def projects_limit_percent
    return 100 if projects_limit.zero?
504
    (personal_projects.count.to_f / projects_limit) * 100
Dmitriy Zaporozhets committed
505 506
  end

507
  def recent_push(project_id = nil)
Dmitriy Zaporozhets committed
508 509 510 511
    # Get push events not earlier than 2 hours ago
    events = recent_events.code_push.where("created_at > ?", Time.now - 2.hours)
    events = events.where(project_id: project_id) if project_id

512 513 514 515 516 517 518 519 520 521 522 523 524
    # Use the latest event that has not been pushed or merged recently
    events.recent.find do |event|
      project = Project.find_by_id(event.project_id)
      next unless project
      repo = project.repository

      if repo.branch_names.include?(event.branch_name)
        merge_requests = MergeRequest.where("created_at >= ?", event.created_at).
            where(source_project_id: project.id,
                  source_branch: event.branch_name)
        merge_requests.empty?
      end
    end
Dmitriy Zaporozhets committed
525 526 527 528 529 530 531
  end

  def projects_sorted_by_activity
    authorized_projects.sorted_by_activity
  end

  def several_namespaces?
532
    owned_groups.any? || masters_groups.any?
Dmitriy Zaporozhets committed
533 534 535 536 537
  end

  def namespace_id
    namespace.try :id
  end
538

539 540 541
  def name_with_username
    "#{name} (#{username})"
  end
542 543

  def tm_of(project)
544
    project.project_member_by_id(self.id)
545
  end
546

547
  def already_forked?(project)
548 549 550
    !!fork_of(project)
  end

551
  def fork_of(project)
552 553 554 555 556 557 558 559
    links = ForkedProjectLink.where(forked_from_project_id: project, forked_to_project_id: personal_projects)

    if links.any?
      links.first.forked_to_project
    else
      nil
    end
  end
560 561

  def ldap_user?
562 563 564 565 566
    identities.exists?(["provider LIKE ? AND extern_uid IS NOT NULL", "ldap%"])
  end

  def ldap_identity
    @ldap_identity ||= identities.find_by(["provider LIKE ?", "ldap%"])
567
  end
568

569
  def project_deploy_keys
570
    DeployKey.unscoped.in_projects(self.authorized_projects.pluck(:id)).distinct(:id)
571 572
  end

573
  def accessible_deploy_keys
574 575 576 577 578
    @accessible_deploy_keys ||= begin
      key_ids = project_deploy_keys.pluck(:id)
      key_ids.push(*DeployKey.are_public.pluck(:id))
      DeployKey.where(id: key_ids)
    end
579
  end
580 581

  def created_by
skv committed
582
    User.find_by(id: created_by_id) if created_by_id
583
  end
584 585

  def sanitize_attrs
586
    %w(name username skype linkedin twitter).each do |attr|
587 588 589 590
      value = self.send(attr)
      self.send("#{attr}=", Sanitize.clean(value)) if value.present?
    end
  end
591

592 593
  def set_notification_email
    if self.notification_email.blank? || !self.all_emails.include?(self.notification_email)
594
      self.notification_email = self.email
595 596 597
    end
  end

598 599
  def set_public_email
    if self.public_email.blank? || !self.all_emails.include?(self.public_email)
600
      self.public_email = ''
601 602 603
    end
  end

604 605 606 607 608 609
  def update_secondary_emails!
    self.set_notification_email
    self.set_public_email
    self.save if self.notification_email_changed? || self.public_email_changed?
  end

610 611 612 613 614 615 616
  def set_projects_limit
    connection_default_value_defined = new_record? && !projects_limit_changed?
    return unless self.projects_limit.nil? || connection_default_value_defined

    self.projects_limit = current_application_settings.default_projects_limit
  end

617
  def requires_ldap_check?
618 619 620
    if !Gitlab.config.ldap.enabled
      false
    elsif ldap_user?
621 622 623 624 625 626
      !last_credential_check_at || (last_credential_check_at + 1.hour) < Time.now
    else
      false
    end
  end

Jacob Vosmaer committed
627 628 629 630 631 632 633
  def try_obtain_ldap_lease
    # After obtaining this lease LDAP checks will be blocked for 600 seconds
    # (10 minutes) for this user.
    lease = Gitlab::ExclusiveLease.new("user_ldap_check:#{id}", timeout: 600)
    lease.try_obtain
  end

634 635 636 637 638
  def solo_owned_groups
    @solo_owned_groups ||= owned_groups.select do |group|
      group.owners == [self]
    end
  end
639 640

  def with_defaults
641 642
    User.defaults.each do |k, v|
      self.send("#{k}=", v)
643
    end
644 645

    self
646
  end
647

648 649 650 651
  def can_leave_project?(project)
    project.namespace != namespace &&
      project.project_member(self)
  end
652 653 654 655 656 657 658 659 660 661 662 663 664 665

  # Reset project events cache related to this user
  #
  # Since we do cache @event we need to reset cache in special cases:
  # * when the user changes their avatar
  # Events cache stored like  events/23-20130109142513.
  # The cache key includes updated_at timestamp.
  # Thus it will automatically generate a new fragment
  # when the event is updated because the key changes.
  def reset_events_cache
    Event.where(author_id: self.id).
      order('id DESC').limit(1000).
      update_all(updated_at: Time.now)
  end
Jerome Dalbert committed
666 667

  def full_website_url
668
    return "http://#{website_url}" if website_url !~ /\Ahttps?:\/\//
Jerome Dalbert committed
669 670 671 672 673

    website_url
  end

  def short_website_url
674
    website_url.sub(/\Ahttps?:\/\//, '')
Jerome Dalbert committed
675
  end
GitLab committed
676

677
  def all_ssh_keys
678
    keys.map(&:publishable_key)
679
  end
680 681

  def temp_oauth_email?
682
    email.start_with?('temp-email-for-oauth')
683 684
  end

685
  def avatar_url(size = nil, scale = 2)
686
    if avatar.present?
687
      [gitlab_config.url, avatar.url].join
688
    else
689
      GravatarService.new.execute(email, size, scale)
690 691
    end
  end
692

693
  def all_emails
694 695 696 697
    all_emails = []
    all_emails << self.email unless self.temp_oauth_email?
    all_emails.concat(self.emails.map(&:email))
    all_emails
698 699
  end

Kirill Zaitsev committed
700 701 702 703 704 705 706 707
  def hook_attrs
    {
      name: name,
      username: username,
      avatar_url: avatar_url
    }
  end

708 709 710 711 712 713 714 715 716 717 718
  def ensure_namespace_correct
    # Ensure user has namespace
    self.create_namespace!(path: self.username, name: self.username) unless self.namespace

    if self.username_changed?
      self.namespace.update_attributes(path: self.username, name: self.username)
    end
  end

  def post_create_hook
    log_info("User \"#{self.name}\" (#{self.email}) was created")
719
    notification_service.new_user(self, @reset_token) if self.created_by_id
720 721 722 723 724 725 726 727
    system_hook_service.execute_hooks_for(self, :create)
  end

  def post_destroy_hook
    log_info("User \"#{self.name}\" (#{self.email})  was removed")
    system_hook_service.execute_hooks_for(self, :destroy)
  end

728
  def notification_service
729 730 731
    NotificationService.new
  end

732
  def log_info(message)
733 734 735 736 737 738
    Gitlab::AppLogger.info message
  end

  def system_hook_service
    SystemHooksService.new
  end
Ciro Santilli committed
739 740

  def starred?(project)
741
    starred_projects.exists?(project.id)
Ciro Santilli committed
742 743 744
  end

  def toggle_star(project)
745 746 747 748 749 750 751 752 753
    UsersStarProject.transaction do
      user_star_project = users_star_projects.
          where(project: project, user: self).lock(true).first

      if user_star_project
        user_star_project.destroy
      else
        UsersStarProject.create!(project: project, user: self)
      end
Ciro Santilli committed
754 755
    end
  end
756 757

  def manageable_namespaces
758
    @manageable_namespaces ||= [namespace] + owned_groups + masters_groups
759
  end
760

761 762 763 764 765 766
  def namespaces
    namespace_ids = groups.pluck(:id)
    namespace_ids.push(namespace.id)
    Namespace.where(id: namespace_ids)
  end

767 768 769
  def oauth_authorized_tokens
    Doorkeeper::AccessToken.where(resource_owner_id: self.id, revoked_at: nil)
  end
770

771 772 773 774 775 776 777 778 779
  # Returns the projects a user contributed to in the last year.
  #
  # This method relies on a subquery as this performs significantly better
  # compared to a JOIN when coupled with, for example,
  # `Project.visible_to_user`. That is, consider the following code:
  #
  #     some_user.contributed_projects.visible_to_user(other_user)
  #
  # If this method were to use a JOIN the resulting query would take roughly 200
780
  # ms on a database with a similar size to GitLab.com's database. On the other
781 782 783 784
  # hand, using a subquery means we can get the exact same data in about 40 ms.
  def contributed_projects
    events = Event.select(:project_id).
      contributions.where(author_id: self).
785
      where("created_at > ?", Time.now - 1.year).
786
      uniq.
787 788 789
      reorder(nil)

    Project.where(id: events)
790
  end
791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813

  def restricted_signup_domains
    email_domains = current_application_settings.restricted_signup_domains

    unless email_domains.blank?
      match_found = email_domains.any? do |domain|
        escaped = Regexp.escape(domain).gsub('\*','.*?')
        regexp = Regexp.new "^#{escaped}$", Regexp::IGNORECASE
        email_domain = Mail::Address.new(self.email).domain
        email_domain =~ regexp
      end

      unless match_found
        self.errors.add :email,
                        'is not whitelisted. ' +
                        'Email domains valid for registration are: ' +
                        email_domains.join(', ')
        return false
      end
    end

    true
  end
814 815 816 817

  def can_be_removed?
    !solo_owned_groups.present?
  end
818 819

  def ci_authorized_runners
820
    @ci_authorized_runners ||= begin
821 822
      runner_ids = Ci::RunnerProject.
        where("ci_runner_projects.gl_project_id IN (#{ci_projects_union.to_sql})").
823
        select(:runner_id)
824 825
      Ci::Runner.specific.where(id: runner_ids)
    end
826
  end
827 828 829 830

  private

  def projects_union
831 832
    Gitlab::SQL::Union.new([personal_projects.select(:id),
                            groups_projects.select(:id),
833 834
                            projects.select(:id),
                            groups.joins(:shared_projects).select(:project_id)])
835
  end
836 837 838 839 840 841 842 843 844

  def ci_projects_union
    scope  = { access_level: [Gitlab::Access::MASTER, Gitlab::Access::OWNER] }
    groups = groups_projects.where(members: scope)
    other  = projects.where(members: scope)

    Gitlab::SQL::Union.new([personal_projects.select(:id), groups.select(:id),
                            other.select(:id)])
  end
845 846 847 848 849

  # Added according to https://github.com/plataformatec/devise/blob/7df57d5081f9884849ca15e4fde179ef164a575f/README.md#activejob-integration
  def send_devise_notification(notification, *args)
    devise_mailer.send(notification, self, *args).deliver_later
  end
Zeger-Jan van de Weg committed
850 851 852 853 854 855 856

  def ensure_external_user_rights
    return unless self.external?

    self.can_create_group   = false
    self.projects_limit     = 0
  end
gitlabhq committed
857
end