db_conn_postgres.rs 46.6 KB
Newer Older
1
2
#![cfg(feature = "postgres")]

3
4
extern crate postgres;

5
6
7
use postgres::Connection;
use time;
use time::Duration;
8
9
10

use db_conn::{MedalConnection, MedalObject};
use db_objects::*;
11
use helpers;
12

13
trait Queryable {
Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
14
15
    fn query_map_one<T, F>(&self, sql: &str, params: &[&dyn postgres::types::ToSql], f: F)
                           -> postgres::Result<Option<T>>
16
        where F: FnOnce(postgres::rows::Row<'_>) -> T;
17
    fn exists(&self, sql: &str, params: &[&dyn postgres::types::ToSql]) -> bool;
18
    fn get_last_id(&self) -> Option<i32>;
19
20
21
}

impl Queryable for Connection {
Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
22
23
    fn query_map_one<T, F>(&self, sql: &str, params: &[&dyn postgres::types::ToSql], f: F)
                           -> postgres::Result<Option<T>>
24
25
        where F: FnOnce(postgres::rows::Row<'_>) -> T {
        let rows = self.query(sql, params)?;
26

27
28
        Ok(rows.iter().next().map(f))
    }
29

30
31
32
33
34
    fn exists(&self, sql: &str, params: &[&dyn postgres::types::ToSql]) -> bool {
        let stmt = self.prepare(sql).unwrap();
        !stmt.query(params).unwrap().is_empty()
    }

35
36
37
38
39
40
    fn get_last_id(&self) -> Option<i32> {
        self.query("SELECT lastval()", &[]).unwrap().iter().next().map(|row| {
                                                                      let r: i64 = row.get(0);
                                                                      r as i32
                                                                  })
    }
41
42
43
}

impl MedalConnection for Connection {
44
45
46
47
48
49
    fn dbtype(&self) -> &'static str { "postgres" }

    fn migration_already_applied(&self, name: &str) -> bool {
        let create_string = "CREATE TABLE IF NOT EXISTS migrations (name TEXT PRIMARY KEY);";
        self.execute(create_string, &[]).unwrap();

50
51
        let query = "SELECT name FROM migrations WHERE name = $1";
        self.exists(query, &[&name])
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
    }

    fn apply_migration(&mut self, name: &str, contents: &str) {
        print!("Applying migration `{}` … ", name);

        let tx = self.transaction().unwrap();

        tx.batch_execute(&contents).unwrap();
        tx.execute("INSERT INTO migrations (name) VALUES ($1)", &[&name]).unwrap();

        tx.commit().unwrap();

        println!("OK.");
    }

    // fn get_session<T: ToSql>(&self, key: T, keyname: &str) -> Option<SessionUser> {
    fn get_session(&self, key: &str) -> Option<SessionUser> {
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
        let query = "SELECT id, csrf_token, last_login, last_activity, permanent_login, username, password, logincode, email, email_unconfirmed, email_confirmationcode, firstname, lastname, street, zip, city, nation, grade, is_teacher, managed_by, oauth_provider, oauth_foreign_id, salt FROM session WHERE session_token = $1";
        let session = self.query_map_one(query, &[&key], |row| SessionUser { id: row.get(0),
                                                                             session_token: Some(key.to_string()),
                                                                             csrf_token: row.get(1),
                                                                             last_login: row.get(2),
                                                                             last_activity: row.get(3),
                                                                             permanent_login: row.get(4),

                                                                             username: row.get(5),
                                                                             password: row.get(6),
                                                                             salt: row.get(22),
                                                                             logincode: row.get(7),
                                                                             email: row.get(8),
                                                                             email_unconfirmed: row.get(9),
                                                                             email_confirmationcode: row.get(10),

                                                                             firstname: row.get(11),
                                                                             lastname: row.get(12),
                                                                             street: row.get(13),
                                                                             zip: row.get(14),
                                                                             city: row.get(15),
                                                                             nation: row.get(16),
                                                                             grade: row.get(17),

                                                                             is_teacher: row.get(18),
                                                                             managed_by: row.get(19),

                                                                             oauth_provider: row.get(20),
                                                                             oauth_foreign_id: row.get(21) })
                          .ok()??;
99
100
101

        let duration = if session.permanent_login { Duration::days(90) } else { Duration::minutes(90) };
        let now = time::get_time();
102

103
104
105
106
        if let Some(last_activity) = session.last_activity {
            if now - last_activity < duration {
                self.execute("UPDATE session SET last_activity = $1 WHERE id = $2", &[&now, &session.id]).unwrap();
                return Some(session);
107
            } else {
108
109
110
111
                // Session timed out
                // Should remove session token from session
                return None;
            }
112
        }
113
114
115
        // last_activity undefined
        // TODO: What should happen here?
        None
116
117
118
119
120
121
122
123
124
125
126
127
    }
    fn save_session(&self, session: SessionUser) {
        self.execute("UPDATE session SET
                      username = $1,
                      password = $2,
                      salt = $3,
                      logincode = $4,
                      firstname = $5,
                      lastname = $6,
                      street = $7,
                      zip = $8,
                      city = $9,
128
129
130
                      grade = $10,
                      is_teacher = $11
                      WHERE id = $12",
131
132
133
134
135
136
137
138
139
140
                     &[&session.username,
                       &session.password,
                       &session.salt,
                       &session.logincode,
                       &session.firstname,
                       &session.lastname,
                       &session.street,
                       &session.zip,
                       &session.city,
                       &session.grade,
141
                       &session.is_teacher,
142
143
144
145
                       &session.id])
            .unwrap();
    }
    fn new_session(&self, session_token: &str) -> SessionUser {
146
        let csrf_token = helpers::make_csrf_token();
147
148

        let now = time::get_time();
Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
149
150
        self.execute(
            "INSERT INTO session (session_token, csrf_token, last_activity, permanent_login, grade, is_teacher)
151
                      VALUES ($1, $2, $3, FALSE, 0, FALSE)",
Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
152
153
154
            &[&session_token, &csrf_token, &now],
        )
        .unwrap();
155

156
157
        let id = self.get_last_id().expect("Expected to get last row id");

158
        SessionUser::minimal(id as i32, session_token.to_owned(), csrf_token)
159
160
    }
    fn get_session_or_new(&self, key: &str) -> SessionUser {
161
162
163
164
        self.get_session(&key).ensure_alive().unwrap_or_else(|| {
                                                 // TODO: Factor this out in own function
                                                 // TODO: Should a new session key be generated every time?
                                                 self.execute(
165
                    "UPDATE session SET session_token = $1 WHERE session_token = $2",
166
167
168
                    &[&Option::<String>::None, &key]).unwrap();
                                                 self.new_session(&key)
                                             })
169
170
171
    }

    fn get_user_by_id(&self, user_id: i32) -> Option<SessionUser> {
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
        let query = "SELECT session_token, csrf_token, last_login, last_activity, permanent_login, username, password, logincode, email, email_unconfirmed, email_confirmationcode, firstname, lastname, street, zip, city, nation, grade, is_teacher, managed_by, oauth_provider, oauth_foreign_id, salt FROM session WHERE id = $1";
        self.query_map_one(query, &[&user_id], |row| SessionUser { id: user_id,
                                                                   session_token: row.get(0),
                                                                   csrf_token: row.get(1),
                                                                   last_login: row.get(2),
                                                                   last_activity: row.get(3),
                                                                   permanent_login: row.get(4),

                                                                   username: row.get(5),
                                                                   password: row.get(6),
                                                                   salt: row.get(22),
                                                                   logincode: row.get(7),
                                                                   email: row.get(8),
                                                                   email_unconfirmed: row.get(9),
                                                                   email_confirmationcode: row.get(10),

                                                                   firstname: row.get(11),
                                                                   lastname: row.get(12),
                                                                   street: row.get(13),
                                                                   zip: row.get(14),
                                                                   city: row.get(15),
                                                                   nation: row.get(16),
                                                                   grade: row.get(17),

                                                                   is_teacher: row.get(18),
                                                                   managed_by: row.get(19),

                                                                   oauth_provider: row.get(20),
                                                                   oauth_foreign_id: row.get(21) })
201
            .ok()?
202
203
204
205
206
207
208
209
210
211
    }

    fn get_user_and_group_by_id(&self, user_id: i32) -> Option<(SessionUser, Option<Group>)> {
        let session = self.get_user_by_id(user_id)?;

        let group_id = match session.managed_by {
            Some(id) => id,
            None => return Some((session, None)),
        };

212
213
214
215
216
217
218
219
220
221
        let query = "SELECT name, groupcode, tag, admin FROM usergroup WHERE id = $1";
        let res = self.query_map_one(query, &[&group_id], |row| Group { id: Some(group_id),
                                                                        name: row.get(0),
                                                                        groupcode: row.get(1),
                                                                        tag: row.get(2),
                                                                        admin: row.get(3),
                                                                        members: Vec::new() })
                      .ok()?;
        match res {
            Some(group) => Some((session, Some(group))),
222
223
224
225
226
227
            _ => Some((session, None)),
        }
    }

    //TODO: use session
    fn login(&self, _session: Option<&str>, username: &str, password: &str) -> Result<String, ()> {
228
229
230
231
232
        let query = "SELECT id, password, salt FROM session WHERE username = $1";
        self.query_map_one(
            query,
            &[&username],
            |row| {
233
234
235
236
                let (id, password_hash, salt): (i32, Option<String>, Option<String>) =
                    (row.get(0), row.get(1), row.get(2));

                //password_hash ist das, was in der Datenbank steht
237
238
239
                if helpers::verify_password(&password,
                                            &salt.expect("salt from database empty"),
                                            &password_hash.expect("password from database empty"))
240
241
242
243
                {
                    // TODO: fail more pleasantly
                    // Login okay, update session now!

244
245
                    let session_token = helpers::make_session_token();
                    let csrf_token = helpers::make_csrf_token();
246
247
                    let now = time::get_time();

248
249
                    let query = "UPDATE session SET session_token = $1, csrf_token = $2, last_login = $3, last_activity = $3 WHERE id = $4";
                    self.execute(query, &[&session_token, &csrf_token, &now, &id]).unwrap();
250
251
252
253
254

                    Ok(session_token)
                } else {
                    Err(())
                }
255
            }).map_err(|_| ())?.ok_or(())?
256
257
258
259
    }

    //TODO: use session
    fn login_with_code(&self, _session: Option<&str>, logincode: &str) -> Result<String, ()> {
260
261
262
263
264
        let query = "SELECT id FROM session WHERE logincode = $1";
        self.query_map_one(
            query,
            &[&logincode],
            |row| {
265
266
267
                // Login okay, update session now!
                let id: i32 = row.get(0);

268
269
                let session_token = helpers::make_session_token();
                let csrf_token = helpers::make_csrf_token();
270
271
                let now = time::get_time();

272
273
                let query = "UPDATE session SET session_token = $1, csrf_token = $2, last_login = $3, last_activity = $3 WHERE id = $4";
                self.execute(query, &[&session_token, &csrf_token, &now, &id]).unwrap();
274

275
276
                session_token
            }).map_err(|_| ())?.ok_or(())
277
278
279
    }

    //TODO: use session
280
281
    fn login_foreign(&self, _session: Option<&str>, foreign_id: &str, is_teacher: bool, firstname: &str,
                     lastname: &str)
282
283
                     -> Result<String, ()>
    {
284
285
        let session_token = helpers::make_session_token();
        let csrf_token = helpers::make_csrf_token();
286
287
        let now = time::get_time();

288
289
290
291
292
        let query = "SELECT id FROM session WHERE oauth_foreign_id = $1";
        match self.query_map_one(query, &[&foreign_id], |row| -> i32 { row.get(0) }) {
            Ok(Some(id)) => {
                let query = "UPDATE session SET session_token = $1, csrf_token = $2, last_login = $3, last_activity = $3 WHERE id = $4";
                self.execute(query, &[&session_token, &csrf_token, &now, &id]).unwrap();
293
294
295
296
297

                Ok(session_token)
            }
            // Add!
            _ => {
298
299
300
301
302
303
304
305
306
307
308
309
                let query = "INSERT INTO session (session_token, csrf_token, last_login, last_activity, permanent_login, grade, is_teacher, oauth_foreign_id, firstname, lastname) VALUES ($1, $2, $3, $3, $4, $5, $6, $7, $8, $9)";
                self.execute(query,
                             &[&session_token,
                               &csrf_token,
                               &now,
                               &false,
                               &0,
                               &is_teacher,
                               &foreign_id,
                               &firstname,
                               &lastname])
                    .unwrap();
310
311
312
313
314
315
316
317

                Ok(session_token)
            }
        }
    }

    //TODO: use session
    fn create_user_with_groupcode(&self, _session: Option<&str>, groupcode: &str) -> Result<String, ()> {
318
319
320
        let query = "SELECT id FROM usergroup WHERE groupcode = $1";
        let group_id =
            self.query_map_one(query, &[&groupcode], |row| -> i32 { row.get(0) }).map_err(|_| ())?.ok_or(())?;
321

322
323
324
325
326
        // Login okay, create session!
        let session_token = helpers::make_session_token();
        let csrf_token = helpers::make_csrf_token();
        let login_code = helpers::make_login_code(); // todo: check for collisions
        let now = time::get_time();
327

328
329
        let query = "INSERT INTO session (session_token, csrf_token, last_login, last_activity, permanent_login, logincode, grade, is_teacher, managed_by) VALUES ($1, $2, $3, $3, $4, $5, $6, $7, $8)";
        self.execute(query, &[&session_token, &csrf_token, &now, &false, &login_code, &0, &false, &group_id]).unwrap();
330

331
        Ok(session_token)
332
333
    }

Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
334
    fn create_group_with_users(&self, mut group: Group) {
335
336
337
338
339
340
        // Generate group ID:
        group.save(self);

        for user in group.members {
            let csrf_token = helpers::make_csrf_token();
            let login_code = helpers::make_login_code(); // TODO: check for collisions
Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
341

342
343
344
345
346
347
348
349
350
351
352
            let query = "INSERT INTO session (firstname, lastname, csrf_token, permanent_login, logincode, grade, is_teacher, managed_by) VALUES ($1, $2, $3, $4, $5, $6, $7, $8)";
            self.execute(query,
                         &[&user.firstname,
                           &user.lastname,
                           &csrf_token,
                           &false,
                           &login_code,
                           &user.grade,
                           &false,
                           &group.id])
                .unwrap();
353
        }
354
355
    }

356
    fn logout(&self, session: &str) {
357
358
        let query = "UPDATE session SET session_token = NULL WHERE session_token = $1";
        self.execute(query, &[&session]).unwrap();
359
360
361
362
    }

    fn load_submission(&self, session: &SessionUser, task: i32, subtask: Option<&str>) -> Option<Submission> {
        match subtask {
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
            None => self.query_map_one("SELECT id, grade, validated, nonvalidated_grade, value, date, needs_validation FROM submission WHERE task = $1 AND session = $2 ORDER BY id DESC LIMIT 1", &[&task, &session.id], |row| {
                Submission {
                    id: Some(row.get(0)),
                    task: task,
                    session_user: session.id,
                    grade: row.get(1),
                    validated: row.get(2),
                    nonvalidated_grade: row.get(3 ),
                    subtask_identifier: None,
                    value: row.get(4),
                    date: row.get(5),
                    needs_validation: row.get(6),
                }
            }).ok()?,
            Some(subtask_id) => self.query_map_one("SELECT id, grade, validated, nonvalidated_grade, value, date, needs_validation FROM submission WHERE task = $1 AND session = $2 AND subtask_identifier = $3 ORDER BY id DESC LIMIT 1", &[&task, &session.id, &subtask_id], |row| {
                Submission {
                    id: Some(row.get(0)),
                    task: task,
                    session_user: session.id,
                    grade: row.get(1),
                    validated: row.get(2),
                    nonvalidated_grade: row.get(3),
                    subtask_identifier: Some(subtask_id.to_string()),
                    value: row.get(4),
                    date: row.get(5),
                    needs_validation: row.get(6),
                }
            }).ok()?,
391
392
393
394
395
396
397
398
399
400
401
402
403
        }
    }
    fn submit_submission(&self, mut submission: Submission) {
        submission.save(self);

        let mut grade = self.get_grade_by_submission(submission.id.unwrap());
        if grade.grade.is_none() || submission.grade > grade.grade.unwrap() {
            grade.grade = Some(submission.grade);
            grade.validated = false;
            grade.save(self);
        }
    }
    fn get_grade_by_submission(&self, submission_id: i32) -> Grade {
404
405
406
407
408
409
410
411
412
413
414
        let query = "SELECT grade.taskgroup, grade.session, grade.grade, grade.validated FROM grade JOIN task ON grade.taskgroup = task.taskgroup JOIN submission ON task.id = submission.task AND grade.session = submission.session WHERE submission.id = $1";
        self.query_map_one(query, &[&submission_id], |row| {
            Grade {
                taskgroup: row.get(0),
                user: row.get(1),
                grade: row.get(2),
                validated: row.get(3),
            }
        }).unwrap_or(None).unwrap_or_else(|| {
            let query = "SELECT task.taskgroup, submission.session FROM submission JOIN task ON task.id = submission.task WHERE submission.id = $1";
            self.query_map_one(query, &[&submission_id], |row| {
415
416
417
                Grade {
                    taskgroup: row.get(0),
                    user: row.get(1),
418
419
420
421
422
                    grade: None,
                    validated: false,
                }
            }).unwrap().unwrap() // should this unwrap?
        })
423
424
425
426
    }

    fn get_contest_groups_grades(&self, session_id: i32, contest_id: i32)
                                 -> (Vec<String>, Vec<(Group, Vec<(UserInfo, Vec<Grade>)>)>) {
427
        let stmt = self.prepare("SELECT id, name FROM taskgroup WHERE contest = $1 ORDER BY id ASC").unwrap();
428
429
430
431
432
433
434
435
436
437
438
439
440
441
        let res = stmt.query(&[&contest_id]).unwrap();
        let tasknames_iter = res.iter().map(|row| {
                                           let x: (i32, String) = (row.get(0), row.get(1));
                                           x
                                       });

        let tasknames: Vec<(i32, String)> = tasknames_iter.collect();
        let mut taskindex: ::std::collections::BTreeMap<i32, usize> = ::std::collections::BTreeMap::new();

        let n_tasks = tasknames.len();
        for (index, (i, _)) in tasknames.iter().enumerate() {
            taskindex.insert(*i, index);
        }

442
        let stmt = self.prepare("SELECT grade.taskgroup, grade.session, grade.grade, grade.validated, usergroup.id, usergroup.name, usergroup.groupcode, usergroup.tag, student.id, student.username, student.logincode, student.firstname, student.lastname
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
                                     FROM grade
                                     JOIN taskgroup ON grade.taskgroup = taskgroup.id
                                     JOIN session AS student ON grade.session = student.id
                                     JOIN usergroup ON student.managed_by = usergroup.id
                                     WHERE usergroup.admin = $1 AND taskgroup.contest = $2
                                     ORDER BY usergroup.id, student.id, taskgroup.id ASC").unwrap();
        let res = stmt.query(&[&session_id, &contest_id]).unwrap();
        let mut gradeinfo_iter =
            res.iter().map(|row| {
                          (Grade { taskgroup: row.get(0), user: row.get(1), grade: row.get(2), validated: row.get(3) },
                           Group { id: Some(row.get(4)),
                                   name: row.get(5),
                                   groupcode: row.get(6),
                                   tag: row.get(7),
                                   admin: session_id,
                                   members: Vec::new() },
                           UserInfo { id: row.get(8),
                                      username: row.get(9),
                                      logincode: row.get(10),
                                      firstname: row.get(11),
                                      lastname: row.get(12) })
                      });

        if let Some(t /*Ok((grade, mut group, mut userinfo))*/) = gradeinfo_iter.next() {
467
            let (grade, group, userinfo) = t;
468
469
470
471
472
473
474
475
476
477
478
479
480

            let mut grades: Vec<Grade> = vec![Default::default(); n_tasks];
            let mut users: Vec<(UserInfo, Vec<Grade>)> = Vec::new();
            let mut groups: Vec<(Group, Vec<(UserInfo, Vec<Grade>)>)> = Vec::new();

            let index = grade.taskgroup;
            grades[taskindex[&index]] = grade;

            // TODO: does
            // https://stackoverflow.com/questions/29859892/mutating-an-item-inside-of-nested-loops
            // help to spare all these clones?

            for ggu in gradeinfo_iter {
481
482
483
484
485
486
487
488
489
490
                let (g, gr, ui) = ggu;
                if gr.id != group.id {
                    users.push((userinfo.clone(), grades));
                    grades = vec![Default::default(); n_tasks];

                    groups.push((group.clone(), users));
                    users = Vec::new();
                } else if ui.id != userinfo.id {
                    users.push((userinfo.clone(), grades));
                    grades = vec![Default::default(); n_tasks];
491
                }
492
493
                let index = g.taskgroup;
                grades[taskindex[&index]] = g;
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
            }
            users.push((userinfo, grades));
            groups.push((group, users));

            (tasknames.iter().map(|(_, name)| name.clone()).collect(), groups)
        } else {
            (Vec::new(), Vec::new()) // should those be default filled?
        }
    }
    fn get_contest_user_grades(&self, session_token: &str, contest_id: i32) -> Vec<Grade> {
        let res =
            self.query("SELECT id, name FROM taskgroup WHERE contest = $1 ORDER BY id ASC", &[&contest_id]).unwrap();
        let tasknames_iter = res.iter().map(|row| {
                                           let x: (i32, String) = (row.get(0), row.get(1));
                                           x
                                       });

        let tasknames: Vec<(i32, String)> = tasknames_iter.collect();
        let mut taskindex: ::std::collections::BTreeMap<i32, usize> = ::std::collections::BTreeMap::new();

        let n_tasks = tasknames.len();
        for (index, (i, _)) in tasknames.iter().enumerate() {
            taskindex.insert(*i, index);
        }

        let res = self.query("SELECT grade.taskgroup, grade.session, grade.grade, grade.validated
                                     FROM grade
                                     JOIN taskgroup ON grade.taskgroup = taskgroup.id
                                     JOIN session ON session.id = grade.session
                                     WHERE session.session_token = $1 AND taskgroup.contest = $2
                                     ORDER BY taskgroup.id ASC",
                             &[&session_token, &contest_id])
                      .unwrap();
        let gradeinfo_iter =
            res.iter()
               .map(|row| Grade { taskgroup: row.get(0), user: row.get(1), grade: row.get(2), validated: row.get(3) });

        let mut grades: Vec<Grade> = vec![Default::default(); n_tasks];

        for g in gradeinfo_iter {
            let index = g.taskgroup;
            grades[taskindex[&index]] = g;
        }

        grades
    }

    fn get_taskgroup_user_grade(&self, session_token: &str, taskgroup_id: i32) -> Grade {
        let grade =
            self.query("SELECT grade.taskgroup, grade.session, grade.grade, grade.validated
                                     FROM grade
                                     JOIN session ON session.id = grade.session
                                     WHERE session.session_token = $1 AND grade.taskgroup = $2",
                       &[&session_token, &taskgroup_id])
                .unwrap()
                .iter()
                .next()
                .map(|row| Grade { taskgroup: row.get(0), user: row.get(1), grade: row.get(2), validated: row.get(3) });

        grade.unwrap_or_default()
    }

    fn get_contest_list(&self) -> Vec<Contest> {
        let res =
Robert Czechowski's avatar
Robert Czechowski committed
558
            self.query("SELECT id, location, filename, name, duration, public, start_date, end_date FROM contest ORDER BY id", &[])
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
                .unwrap();
        res.iter()
           .map(|row| Contest { id: Some(row.get(0)),
                                location: row.get(1),
                                filename: row.get(2),
                                name: row.get(3),
                                duration: row.get(4),
                                public: row.get(5),
                                start: row.get(6),
                                end: row.get(7),
                                taskgroups: Vec::new() })
           .collect()
    }

    fn get_contest_by_id(&self, contest_id: i32) -> Contest {
574
575
576
577
578
579
580
581
582
583
584
        let query =
            "SELECT location, filename, name, duration, public, start_date, end_date FROM contest WHERE id = $1";
        self.query_map_one(query, &[&contest_id], |row| Contest { id: Some(contest_id),
                                                                  location: row.get(0),
                                                                  filename: row.get(1),
                                                                  name: row.get(2),
                                                                  duration: row.get(3),
                                                                  public: row.get(4),
                                                                  start: row.get(5),
                                                                  end: row.get(6),
                                                                  taskgroups: Vec::new() })
585
586
587
588
589
            .unwrap()
            .unwrap() // TODO: Should return Option?
    }

    fn get_contest_by_id_complete(&self, contest_id: i32) -> Contest {
590
591
592
        let query = "SELECT contest.location, contest.filename, contest.name, contest.duration, contest.public, contest.start_date, contest.end_date, taskgroup.id, taskgroup.name, task.id, task.location, task.stars FROM contest JOIN taskgroup ON contest.id = taskgroup.contest JOIN task ON taskgroup.id = task.taskgroup WHERE contest.id = $1 ORDER BY taskgroup.id";
        let res = self.query(query, &[&contest_id]).unwrap();

593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
        let mut taskgroupcontest_iter =
            res.iter().map(|row| {
                          (Contest { id: Some(contest_id),
                                     location: row.get(0),
                                     filename: row.get(1),
                                     name: row.get(2),
                                     duration: row.get(3),
                                     public: row.get(4),
                                     start: row.get(5),
                                     end: row.get(6),
                                     taskgroups: Vec::new() },
                           Taskgroup { id: Some(row.get(7)), contest: contest_id, name: row.get(8), tasks: Vec::new() },
                           Task { id: Some(row.get(9)),
                                  taskgroup: row.get(7),
                                  location: row.get(10),
                                  stars: row.get(11) })
                      });

        let (mut contest, mut taskgroup, task) = taskgroupcontest_iter.next().unwrap();
        taskgroup.tasks.push(task);
        for tgc in taskgroupcontest_iter {
614
615
616
617
            let (_, tg, t) = tgc;
            if tg.id != taskgroup.id {
                contest.taskgroups.push(taskgroup);
                taskgroup = tg;
618
            }
619
            taskgroup.tasks.push(t);
620
621
622
623
624
625
        }
        contest.taskgroups.push(taskgroup);
        contest
    }

    fn get_contest_by_id_partial(&self, contest_id: i32) -> Contest {
626
627
628
        let query = "SELECT contest.location, contest.filename, contest.name, contest.duration, contest.public, contest.start_date, contest.end_date, taskgroup.id, taskgroup.name FROM contest JOIN taskgroup ON contest.id = taskgroup.contest WHERE contest.id = $1";

        let res = self.query(query, &[&contest_id]).unwrap();
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
        let mut taskgroupcontest_iter =
            res.iter().map(|row| {
                          (Contest { id: Some(contest_id),
                                     location: row.get(0),
                                     filename: row.get(1),
                                     name: row.get(2),
                                     duration: row.get(3),
                                     public: row.get(4),
                                     start: row.get(5),
                                     end: row.get(6),
                                     taskgroups: Vec::new() },
                           Taskgroup { id: Some(row.get(7)), contest: contest_id, name: row.get(8), tasks: Vec::new() })
                      });

        let (mut contest, taskgroup) = taskgroupcontest_iter.next().unwrap();
        contest.taskgroups.push(taskgroup);
        for tgc in taskgroupcontest_iter {
646
647
            let (_, tg) = tgc;
            contest.taskgroups.push(tg);
648
649
650
651
652
        }
        contest
    }

    fn get_participation(&self, session: &str, contest_id: i32) -> Option<Participation> {
653
654
655
656
657
        let query = "SELECT session, start_date FROM participation JOIN session ON session.id = session WHERE session.session_token = $1 AND contest = $2";
        self.query_map_one(query, &[&session, &contest_id], |row| Participation { contest: contest_id,
                                                                                  user: row.get(0),
                                                                                  start: row.get(1) })
            .ok()?
658
659
    }
    fn new_participation(&self, session: &str, contest_id: i32) -> Result<Participation, ()> {
660
661
662
        let query = "SELECT session, start_date FROM participation JOIN session ON session.id = session WHERE session.session_token = $1 AND contest = $2";
        match self.query_map_one(query, &[&session, &contest_id], |_| {}).map_err(|_| ())? {
            Some(()) => Err(()),
663
664
665
            None => {
                let now = time::get_time();
                self.execute(
666
                             "INSERT INTO participation (contest, session, start_date)
667
                     SELECT $1, id, $2 FROM session WHERE session_token = $3",
668
669
670
                             &[&contest_id, &now, &session],
                )
                    .unwrap();
671
672
673
674
675
676

                Ok(self.get_participation(session, contest_id).unwrap()) // TODO: This errors if not logged in …
            }
        }
    }
    fn get_task_by_id(&self, task_id: i32) -> Task {
677
678
679
680
681
        let query = "SELECT location, stars, taskgroup FROM task WHERE id = $1";
        self.query_map_one(query, &[&task_id], |row| Task { id: Some(task_id),
                                                            taskgroup: row.get(2),
                                                            location: row.get(0),
                                                            stars: row.get(1) })
682
683
684
685
            .unwrap()
            .unwrap()
    }
    fn get_task_by_id_complete(&self, task_id: i32) -> (Task, Taskgroup, Contest) {
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
        let query = "SELECT task.location, task.stars, taskgroup.id, taskgroup.name, contest.id, contest.location, contest.filename, contest.name, contest.duration, contest.public, contest.start_date, contest.end_date FROM contest JOIN taskgroup ON taskgroup.contest = contest.id JOIN task ON task.taskgroup = taskgroup.id WHERE task.id = $1";
        self.query_map_one(query, &[&task_id], |row| {
                (Task { id: Some(task_id), taskgroup: row.get(2), location: row.get(0), stars: row.get(1) },
                 Taskgroup { id: Some(row.get(2)), contest: row.get(4), name: row.get(3), tasks: Vec::new() },
                 Contest { id: Some(row.get(4)),
                           location: row.get(5),
                           filename: row.get(6),
                           name: row.get(7),
                           duration: row.get(8),
                           public: row.get(9),
                           start: row.get(10),
                           end: row.get(11),
                           taskgroups: Vec::new() })
            })
            .unwrap()
            .unwrap()
702
703
704
705
    }

    fn get_submission_to_validate(&self, tasklocation: &str, subtask: Option<&str>) -> i32 {
        match subtask {
706
707
708
709
710
711
712
713
            Some(st) => {
                let query = "SELECT id FROM submission JOIN task ON submission.task = task.id WHERE task.location = $1  AND subtask_identifier = $2 AND needs_validation = 1 LIMIT 1";
                self.query_map_one(query, &[&tasklocation, &st], |row| row.get(0)).unwrap().unwrap()
            }
            None => {
                let query = "SELECT id FROM submission JOIN task ON submission.task = task.id WHERE task.location = $1 AND needs_validation = 1 LIMIT 1";
                self.query_map_one(query, &[&tasklocation], |row| row.get(0)).unwrap().unwrap()
            }
714
715
716
717
        }
    }

    fn find_next_submission_to_validate(&self, userid: i32, taskgroupid: i32) {
718
719
720
        let query = "SELECT id, validated FROM submission JOIN task ON submission.task = task.id WHERE task.taskgroup = $1 AND submission.session = $2 ORDER BY value DESC id DESC LIMIT 1";
        let (id, validated): (i32, bool) =
            self.query_map_one(query, &[&taskgroupid, &userid], |row| (row.get(0), row.get(1))).unwrap().unwrap();
721
        if !validated {
722
723
            let query = "UPDATE submission SET needs_validation = 1 WHERE id = $1";
            self.execute(query, &[&id]).unwrap();
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
        }
    }

    fn add_group(&self, group: &mut Group) { group.save(self); }

    fn get_groups(&self, session_id: i32) -> Vec<Group> {
        self.query("SELECT id, name, groupcode, tag FROM usergroup WHERE admin = $1", &[&session_id])
            .unwrap()
            .iter()
            .map(|row| Group { id: Some(row.get(0)),
                               name: row.get(1),
                               groupcode: row.get(2),
                               tag: row.get(3),
                               admin: session_id,
                               members: Vec::new() })
            .collect()
    }
    fn get_groups_complete(&self, _session_id: i32) -> Vec<Group> {
        unimplemented!();
    }
    fn get_group_complete(&self, group_id: i32) -> Option<Group> {
745
746
747
748
749
750
751
        let query = "SELECT name, groupcode, tag, admin FROM usergroup WHERE id  = $1";
        let mut group = self.query_map_one(query, &[&group_id], |row| Group { id: Some(group_id),
                                                                              name: row.get(0),
                                                                              groupcode: row.get(1),
                                                                              tag: row.get(2),
                                                                              admin: row.get(3),
                                                                              members: Vec::new() })
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
                            .unwrap()
                            .unwrap(); // TODO handle error

        let res = self.query("SELECT id, session_token, csrf_token, last_login, last_activity, permanent_login,
                                     username, password, logincode, email, email_unconfirmed, email_confirmationcode,
                                     firstname, lastname, street, zip, city, nation, grade, is_teacher, oauth_provider,
                                     oauth_foreign_id, salt
                             FROM session
                             WHERE managed_by = $1",
                             &[&group_id])
                      .unwrap();
        let rows = res.iter().map(|row| SessionUser { id: row.get(0),
                                                      session_token: row.get(1),
                                                      csrf_token: row.get(2),
                                                      last_login: row.get(3),
                                                      last_activity: row.get(4),
                                                      permanent_login: row.get(5),

                                                      username: row.get(6),
                                                      password: row.get(7),
                                                      salt: row.get(22),
                                                      logincode: row.get(8),
                                                      email: row.get(9),
                                                      email_unconfirmed: row.get(10),
                                                      email_confirmationcode: row.get(11),

                                                      firstname: row.get(12),
                                                      lastname: row.get(13),
                                                      street: row.get(14),
                                                      zip: row.get(15),
                                                      city: row.get(16),
                                                      nation: row.get(17),
                                                      grade: row.get(18),

                                                      is_teacher: row.get(19),
                                                      managed_by: Some(group_id),

                                                      oauth_provider: row.get(20),
                                                      oauth_foreign_id: row.get(21) });

        for user in rows {
            group.members.push(user);
        }
        Some(group)
    }
797

798
    fn reset_all_contest_visibilities(&self) { self.execute("UPDATE contest SET public = $1", &[&false]).unwrap(); }
799
800
801
802
}

impl MedalObject<Connection> for Task {
    fn save(&mut self, conn: &Connection) {
803
804
805
        let query = "SELECT id FROM task WHERE taskgroup = $1 AND location = $2";
        conn.query_map_one(query, &[&self.taskgroup, &self.location], |row| row.get(0))
            .unwrap_or(None)
806
807
808
809
810
811
812
813
            .and_then(|id| {
                self.set_id(id);
                Some(())
            })
            .unwrap_or(()); // Err means no entry yet and is expected result

        let id = match self.get_id() {
            Some(id) => {
814
815
                let query = "UPDATE task SET taskgroup = $1, location = $2, stars = $3 WHERE id = $4";
                conn.execute(query, &[&self.taskgroup, &self.location, &self.stars, &id]).unwrap();
816
817
818
                id
            }
            None => {
819
820
821
                let query = "INSERT INTO task (taskgroup, location, stars) VALUES ($1, $2, $3)";
                conn.execute(query, &[&self.taskgroup, &self.location, &self.stars]).unwrap();
                conn.get_last_id().unwrap()
822
823
824
825
826
827
828
829
            }
        };
        self.set_id(id);
    }
}

impl MedalObject<Connection> for Taskgroup {
    fn save(&mut self, conn: &Connection) {
830
831
832
        let query = "SELECT id FROM taskgroup WHERE contest = $1 AND name = $2";
        conn.query_map_one(query, &[&self.contest, &self.name], |row| row.get(0))
            .unwrap_or(None)
833
834
835
836
837
838
839
840
            .and_then(|id| {
                self.set_id(id);
                Some(())
            })
            .unwrap_or(()); // Err means no entry yet and is expected result

        let id = match self.get_id() {
            Some(id) => {
841
842
                let query = "UPDATE taskgroup SET contest = $1, name = $2 WHERE id = $3";
                conn.execute(query, &[&self.contest, &self.name, &id]).unwrap();
843
844
845
                id
            }
            None => {
846
847
848
                let query = "INSERT INTO taskgroup (contest, name) VALUES ($1, $2)";
                conn.execute(query, &[&self.contest, &self.name]).unwrap();
                conn.get_last_id().unwrap()
849
850
851
852
853
854
855
856
857
858
859
860
            }
        };
        self.set_id(id);
        for mut task in &mut self.tasks {
            task.taskgroup = id;
            task.save(conn);
        }
    }
}

impl MedalObject<Connection> for Contest {
    fn save(&mut self, conn: &Connection) {
861
862
863
        let query = "SELECT id FROM contest WHERE location = $1 AND filename = $2";
        conn.query_map_one(query, &[&self.location, &self.filename], |row| row.get(0))
            .unwrap_or(None)
864
865
866
867
868
869
            .and_then(|id| {
                self.set_id(id);
                Some(())
            })
            .unwrap_or(()); // Err means no entry yet and is expected result

870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
        let id = match self.get_id() {
            Some(id) => {
                let query = "UPDATE contest SET location = $1,filename = $2, name = $3, duration = $4, public = $5, start_date = $6, end_date = $7 WHERE id = $8";
                conn.execute(query,
                             &[&self.location,
                               &self.filename,
                               &self.name,
                               &self.duration,
                               &self.public,
                               &self.start,
                               &self.end,
                               &id])
                    .unwrap();
                id
            }
            None => {
                let query = "INSERT INTO contest (location, filename, name, duration, public, start_date, end_date) VALUES ($1, $2, $3, $4, $5, $6, $7)";
                conn.execute(query,
                             &[&self.location,
                               &self.filename,
                               &self.name,
                               &self.duration,
                               &self.public,
                               &self.start,
                               &self.end])
                    .unwrap();
                conn.get_last_id().unwrap()
            }
        };
899
900
901
902
903
904
905
906
907
908
        self.set_id(id);
        for mut taskgroup in &mut self.taskgroups {
            taskgroup.contest = id;
            taskgroup.save(conn);
        }
    }
}

impl MedalObject<Connection> for Grade {
    fn save(&mut self, conn: &Connection) {
909
910
        let query = "INSERT INTO grade (taskgroup, session, grade, validated) VALUES ($1, $2, $3, $4) ON CONFLICT ON CONSTRAINT grade_pkey DO UPDATE SET grade = excluded.grade, validated = excluded.validated";
        conn.execute(query, &[&self.taskgroup, &self.user, &self.grade, &self.validated]).unwrap();
911
912
913
914
915
    }
}

impl MedalObject<Connection> for Participation {
    fn save(&mut self, conn: &Connection) {
916
917
        let query = "INSERT INTO participation (contest, session, start_date) VALUES ($1, $2, $3)";
        conn.execute(query, &[&self.contest, &self.user, &self.start]).unwrap();
918
919
920
921
922
923
924
925
    }
}

impl MedalObject<Connection> for Submission {
    fn save(&mut self, conn: &Connection) {
        match self.get_id() {
            Some(_id) => unimplemented!(),
            None => {
926
927
928
929
930
931
932
933
934
935
936
937
938
                let query = "INSERT INTO submission (task, session, grade, validated, nonvalidated_grade, subtask_identifier, value, date, needs_validation) VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9)";
                conn.execute(query,
                             &[&self.task,
                               &self.session_user,
                               &self.grade,
                               &self.validated,
                               &self.nonvalidated_grade,
                               &self.subtask_identifier,
                               &self.value,
                               &self.date,
                               &self.needs_validation])
                    .unwrap();
                self.set_id(conn.get_last_id().unwrap());
939
940
941
942
943
944
945
946
947
948
            }
        }
    }
}

impl MedalObject<Connection> for Group {
    fn save(&mut self, conn: &Connection) {
        match self.get_id() {
            Some(_id) => unimplemented!(),
            None => {
949
950
951
                let query = "INSERT INTO usergroup (name, groupcode, tag, admin) VALUES ($1, $2, $3, $4)";
                conn.execute(query, &[&self.name, &self.groupcode, &self.tag, &self.admin]).unwrap();
                self.set_id(conn.get_last_id().unwrap());
952
953
954
955
            }
        }
    }
}