db_conn_postgres.rs 55.8 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
11
12
13
/* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
 *                                                                             *
 *        WARNING                                                              *
 *                                                                             *
 * This file is auto generated by ./generate_connectors.sh                     *
 *                                                                             *
 * Do not edit this file directly. Instead edit one of the corresponding       *
 * .header.rs oder .base.rs files.                                             *
 *                                                                             *
 *                                                                             *
 *                                                                             *
 * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */

14
15
#![cfg(feature = "postgres")]

16
17
extern crate postgres;

18
19
20
use postgres::Connection;
use time;
use time::Duration;
21
22
23

use db_conn::{MedalConnection, MedalObject};
use db_objects::*;
24
use helpers;
25

26
trait Queryable {
Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
27
28
    fn query_map_one<T, F>(&self, sql: &str, params: &[&dyn postgres::types::ToSql], f: F)
                           -> postgres::Result<Option<T>>
29
        where F: FnOnce(postgres::rows::Row<'_>) -> T;
30
31
    fn query_map_many<T, F>(&self, sql: &str, params: &[&dyn postgres::types::ToSql], f: F) -> postgres::Result<Vec<T>>
        where F: FnMut(postgres::rows::Row<'_>) -> T;
32
    fn exists(&self, sql: &str, params: &[&dyn postgres::types::ToSql]) -> bool;
33
    fn get_last_id(&self) -> Option<i32>;
34
35
36
}

impl Queryable for Connection {
Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
37
38
    fn query_map_one<T, F>(&self, sql: &str, params: &[&dyn postgres::types::ToSql], f: F)
                           -> postgres::Result<Option<T>>
39
40
        where F: FnOnce(postgres::rows::Row<'_>) -> T {
        let rows = self.query(sql, params)?;
41

42
43
        Ok(rows.iter().next().map(f))
    }
44

45
46
47
48
49
    fn query_map_many<T, F>(&self, sql: &str, params: &[&dyn postgres::types::ToSql], f: F) -> postgres::Result<Vec<T>>
        where F: FnMut(postgres::rows::Row<'_>) -> T {
        Ok(self.query(sql, params)?.iter().map(f).collect())
    }

50
51
52
53
54
    fn exists(&self, sql: &str, params: &[&dyn postgres::types::ToSql]) -> bool {
        let stmt = self.prepare(sql).unwrap();
        !stmt.query(params).unwrap().is_empty()
    }

55
56
57
58
59
60
    fn get_last_id(&self) -> Option<i32> {
        self.query("SELECT lastval()", &[]).unwrap().iter().next().map(|row| {
                                                                      let r: i64 = row.get(0);
                                                                      r as i32
                                                                  })
    }
61
    // Empty line intended
62
63
}

64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
impl MedalObject<Connection> for Submission {
    fn save(&mut self, conn: &Connection) {
        match self.get_id() {
            Some(_id) => unimplemented!(),
            None => {
                let query = "INSERT INTO submission (task, session, grade, validated, nonvalidated_grade,
                                                     subtask_identifier, value, date, needs_validation)
                             VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9)";
                conn.execute(query,
                             &[&self.task,
                               &self.session_user,
                               &self.grade,
                               &self.validated,
                               &self.nonvalidated_grade,
                               &self.subtask_identifier,
                               &self.value,
                               &self.date,
                               &self.needs_validation])
                    .unwrap();
                self.set_id(conn.get_last_id().unwrap());
            }
        }
    }
}

impl MedalObject<Connection> for Grade {
    fn save(&mut self, conn: &Connection) {
        let query = "INSERT INTO grade (taskgroup, session, grade, validated)
                     VALUES ($1, $2, $3, $4)
                     ON CONFLICT ON CONSTRAINT grade_pkey DO UPDATE SET grade = excluded.grade, validated = excluded.validated";
        conn.execute(query, &[&self.taskgroup, &self.user, &self.grade, &self.validated]).unwrap();
    }
}
impl MedalObject<Connection> for Participation {
    fn save(&mut self, conn: &Connection) {
        let query = "INSERT INTO participation (contest, session, start_date)
                     VALUES ($1, $2, $3)";
        conn.execute(query, &[&self.contest, &self.user, &self.start]).unwrap();
    }
}

impl MedalObject<Connection> for Group {
    fn save(&mut self, conn: &Connection) {
        match self.get_id() {
            Some(_id) => unimplemented!(),
            None => {
                let query = "INSERT INTO usergroup (name, groupcode, tag, admin)
                             VALUES ($1, $2, $3, $4)";
                conn.execute(query, &[&self.name, &self.groupcode, &self.tag, &self.admin]).unwrap();
                self.set_id(conn.get_last_id().unwrap());
            }
        }
    }
}

impl MedalObject<Connection> for Task {
    fn save(&mut self, conn: &Connection) {
        let query = "SELECT id
                     FROM task
                     WHERE taskgroup = $1
                     AND location = $2";
        conn.query_map_one(query, &[&self.taskgroup, &self.location], |row| row.get(0))
            .unwrap_or(None)
            .and_then(|id| {
                self.set_id(id);
                Some(())
            })
            .unwrap_or(()); // Err means no entry yet and is expected result

        let id = match self.get_id() {
            Some(id) => {
                let query = "UPDATE task
                             SET taskgroup = $1, location = $2, stars = $3
                             WHERE id = $4";
                conn.execute(query, &[&self.taskgroup, &self.location, &self.stars, &id]).unwrap();
                id
            }
            None => {
                let query = "INSERT INTO task (taskgroup, location, stars)
                             VALUES ($1, $2, $3)";
                conn.execute(query, &[&self.taskgroup, &self.location, &self.stars]).unwrap();
                conn.get_last_id().unwrap()
            }
        };
        self.set_id(id);
    }
}

impl MedalObject<Connection> for Taskgroup {
    fn save(&mut self, conn: &Connection) {
        if let Some(first_task) = self.tasks.get(0) {
            let query = "SELECT taskgroup.id
                         FROM taskgroup
                         JOIN task
                         ON task.taskgroup = taskgroup.id
                         WHERE contest = $1
                         AND task.location = $2";
            conn.query_map_one(query, &[&self.contest, &first_task.location], |row| row.get(0))
                .unwrap_or(None)
                .and_then(|id| {
                    self.set_id(id);
                    Some(())
                })
                .unwrap_or(()); // Err means no entry yet and is expected result
        }

        let id = match self.get_id() {
            Some(id) => {
                let query = "UPDATE taskgroup
                             SET contest = $1, name = $2, positionalnumber = $3
                             WHERE id = $4";
                conn.execute(query, &[&self.contest, &self.name, &self.positionalnumber, &id]).unwrap();
                id
            }
            None => {
                let query = "INSERT INTO taskgroup (contest, name, positionalnumber)
                             VALUES ($1, $2, $3)";
                conn.execute(query, &[&self.contest, &self.name, &self.positionalnumber]).unwrap();
                conn.get_last_id().unwrap()
            }
        };
        self.set_id(id);
        for mut task in &mut self.tasks {
            task.taskgroup = id;
            task.save(conn);
        }
    }
}

impl MedalObject<Connection> for Contest {
    fn save(&mut self, conn: &Connection) {
        let query = "SELECT id
                     FROM contest
                     WHERE location = $1
                     AND filename = $2";
        conn.query_map_one(query, &[&self.location, &self.filename], |row| row.get(0))
            .unwrap_or(None)
            .and_then(|id| {
                self.set_id(id);
                Some(())
            })
            .unwrap_or(()); // Err means no entry yet and is expected result

        let id = match self.get_id() {
            Some(id) => {
                let query = "UPDATE contest
210
                             SET location = $1,filename = $2, name = $3, duration = $4, public = $5, start_date = $6,
211
212
                                 end_date = $7, min_grade = $8, max_grade = $9, positionalnumber = $10
                             WHERE id = $11";
213
214
215
216
217
218
219
220
                conn.execute(query,
                             &[&self.location,
                               &self.filename,
                               &self.name,
                               &self.duration,
                               &self.public,
                               &self.start,
                               &self.end,
221
222
                               &self.min_grade,
                               &self.max_grade,
223
                               &self.positionalnumber,
224
225
226
227
228
                               &id])
                    .unwrap();
                id
            }
            None => {
229
                let query = "INSERT INTO contest (location, filename, name, duration, public, start_date, end_date,
230
231
                                                  min_grade, max_grade, positionalnumber)
                             VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10)";
232
233
234
235
236
237
238
                conn.execute(query,
                             &[&self.location,
                               &self.filename,
                               &self.name,
                               &self.duration,
                               &self.public,
                               &self.start,
239
240
                               &self.end,
                               &self.min_grade,
241
242
                               &self.max_grade,
                               &self.positionalnumber])
243
244
245
246
247
248
249
250
251
252
253
254
                    .unwrap();
                conn.get_last_id().unwrap()
            }
        };
        self.set_id(id);
        for mut taskgroup in &mut self.taskgroups {
            taskgroup.contest = id;
            taskgroup.save(conn);
        }
    }
}

255
impl MedalConnection for Connection {
256
257
258
259
260
261
    fn dbtype(&self) -> &'static str { "postgres" }

    fn migration_already_applied(&self, name: &str) -> bool {
        let create_string = "CREATE TABLE IF NOT EXISTS migrations (name TEXT PRIMARY KEY);";
        self.execute(create_string, &[]).unwrap();

262
263
        let query = "SELECT name FROM migrations WHERE name = $1";
        self.exists(query, &[&name])
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
    }

    fn apply_migration(&mut self, name: &str, contents: &str) {
        print!("Applying migration `{}` … ", name);

        let tx = self.transaction().unwrap();

        tx.batch_execute(&contents).unwrap();
        tx.execute("INSERT INTO migrations (name) VALUES ($1)", &[&name]).unwrap();

        tx.commit().unwrap();

        println!("OK.");
    }

    // fn get_session<T: ToSql>(&self, key: T, keyname: &str) -> Option<SessionUser> {
    fn get_session(&self, key: &str) -> Option<SessionUser> {
281
282
283
284
285
        let query = "SELECT id, csrf_token, last_login, last_activity, permanent_login, username, password, logincode,
                            email, email_unconfirmed, email_confirmationcode, firstname, lastname, street, zip, city,
                            nation, grade, is_teacher, managed_by, oauth_provider, oauth_foreign_id, salt
                     FROM session
                     WHERE session_token = $1";
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
        let session = self.query_map_one(query, &[&key], |row| SessionUser { id: row.get(0),
                                                                             session_token: Some(key.to_string()),
                                                                             csrf_token: row.get(1),
                                                                             last_login: row.get(2),
                                                                             last_activity: row.get(3),
                                                                             permanent_login: row.get(4),

                                                                             username: row.get(5),
                                                                             password: row.get(6),
                                                                             salt: row.get(22),
                                                                             logincode: row.get(7),
                                                                             email: row.get(8),
                                                                             email_unconfirmed: row.get(9),
                                                                             email_confirmationcode: row.get(10),

                                                                             firstname: row.get(11),
                                                                             lastname: row.get(12),
                                                                             street: row.get(13),
                                                                             zip: row.get(14),
                                                                             city: row.get(15),
                                                                             nation: row.get(16),
                                                                             grade: row.get(17),

                                                                             is_teacher: row.get(18),
                                                                             managed_by: row.get(19),

                                                                             oauth_provider: row.get(20),
                                                                             oauth_foreign_id: row.get(21) })
                          .ok()??;
315
316
317

        let duration = if session.permanent_login { Duration::days(90) } else { Duration::minutes(90) };
        let now = time::get_time();
318

319
320
        if let Some(last_activity) = session.last_activity {
            if now - last_activity < duration {
321
322
323
324
                let query = "UPDATE session
                             SET last_activity = $1
                             WHERE id = $2";
                self.execute(query, &[&now, &session.id]).unwrap();
325
                return Some(session);
326
            } else {
327
328
329
330
                // Session timed out
                // Should remove session token from session
                return None;
            }
331
        }
332
333
334
        // last_activity undefined
        // TODO: What should happen here?
        None
335
336
337
338
339
340
341
342
343
344
345
346
    }
    fn save_session(&self, session: SessionUser) {
        self.execute("UPDATE session SET
                      username = $1,
                      password = $2,
                      salt = $3,
                      logincode = $4,
                      firstname = $5,
                      lastname = $6,
                      street = $7,
                      zip = $8,
                      city = $9,
347
348
349
                      grade = $10,
                      is_teacher = $11
                      WHERE id = $12",
350
351
352
353
354
355
356
357
358
359
                     &[&session.username,
                       &session.password,
                       &session.salt,
                       &session.logincode,
                       &session.firstname,
                       &session.lastname,
                       &session.street,
                       &session.zip,
                       &session.city,
                       &session.grade,
360
                       &session.is_teacher,
361
362
363
364
                       &session.id])
            .unwrap();
    }
    fn new_session(&self, session_token: &str) -> SessionUser {
365
        let csrf_token = helpers::make_csrf_token();
366
367

        let now = time::get_time();
368
369
        let query = "INSERT INTO session (session_token, csrf_token, last_activity, permanent_login, grade,
                                          is_teacher)
370
371
                     VALUES ($1, $2, $3, $4, $5, $6)";
        self.execute(query, &[&session_token, &csrf_token, &now, &false, &0, &false]).unwrap();
372

373
374
        let id = self.get_last_id().expect("Expected to get last row id");

375
        SessionUser::minimal(id, session_token.to_owned(), csrf_token)
376
377
    }
    fn get_session_or_new(&self, key: &str) -> SessionUser {
378
379
380
        let query = "UPDATE session
                     SET session_token = $1
                     WHERE session_token = $2";
381
382
383
        self.get_session(&key).ensure_alive().unwrap_or_else(|| {
                                                 // TODO: Factor this out in own function
                                                 // TODO: Should a new session key be generated every time?
384
                                                 self.execute(query, &[&Option::<String>::None, &key]).unwrap();
385
386
                                                 self.new_session(&key)
                                             })
387
388
389
    }

    fn get_user_by_id(&self, user_id: i32) -> Option<SessionUser> {
390
391
392
393
394
        let query = "SELECT session_token, csrf_token, last_login, last_activity, permanent_login, username, password,
                            logincode, email, email_unconfirmed, email_confirmationcode, firstname, lastname, street,
                            zip, city, nation, grade, is_teacher, managed_by, oauth_provider, oauth_foreign_id, salt
                     FROM session
                     WHERE id = $1";
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
        self.query_map_one(query, &[&user_id], |row| SessionUser { id: user_id,
                                                                   session_token: row.get(0),
                                                                   csrf_token: row.get(1),
                                                                   last_login: row.get(2),
                                                                   last_activity: row.get(3),
                                                                   permanent_login: row.get(4),

                                                                   username: row.get(5),
                                                                   password: row.get(6),
                                                                   salt: row.get(22),
                                                                   logincode: row.get(7),
                                                                   email: row.get(8),
                                                                   email_unconfirmed: row.get(9),
                                                                   email_confirmationcode: row.get(10),

                                                                   firstname: row.get(11),
                                                                   lastname: row.get(12),
                                                                   street: row.get(13),
                                                                   zip: row.get(14),
                                                                   city: row.get(15),
                                                                   nation: row.get(16),
                                                                   grade: row.get(17),

                                                                   is_teacher: row.get(18),
                                                                   managed_by: row.get(19),

                                                                   oauth_provider: row.get(20),
                                                                   oauth_foreign_id: row.get(21) })
423
            .ok()?
424
425
426
427
428
429
430
431
432
433
    }

    fn get_user_and_group_by_id(&self, user_id: i32) -> Option<(SessionUser, Option<Group>)> {
        let session = self.get_user_by_id(user_id)?;

        let group_id = match session.managed_by {
            Some(id) => id,
            None => return Some((session, None)),
        };

434
435
436
        let query = "SELECT name, groupcode, tag, admin
                     FROM usergroup
                     WHERE id = $1";
437
438
439
440
441
442
443
444
445
        let res = self.query_map_one(query, &[&group_id], |row| Group { id: Some(group_id),
                                                                        name: row.get(0),
                                                                        groupcode: row.get(1),
                                                                        tag: row.get(2),
                                                                        admin: row.get(3),
                                                                        members: Vec::new() })
                      .ok()?;
        match res {
            Some(group) => Some((session, Some(group))),
446
447
448
449
450
451
            _ => Some((session, None)),
        }
    }

    //TODO: use session
    fn login(&self, _session: Option<&str>, username: &str, password: &str) -> Result<String, ()> {
452
453
454
455
        let query = "SELECT id, password, salt
                     FROM session
                     WHERE username = $1";
        self.query_map_one(query, &[&username], |row| {
456
457
458
459
                let (id, password_hash, salt): (i32, Option<String>, Option<String>) =
                    (row.get(0), row.get(1), row.get(2));

                //password_hash ist das, was in der Datenbank steht
460
461
462
                if helpers::verify_password(&password,
                                            &salt.expect("salt from database empty"),
                                            &password_hash.expect("password from database empty"))
463
464
465
466
                {
                    // TODO: fail more pleasantly
                    // Login okay, update session now!

467
468
                    let session_token = helpers::make_session_token();
                    let csrf_token = helpers::make_csrf_token();
469
470
                    let now = time::get_time();

471
472
473
                    let query = "UPDATE session
                                 SET session_token = $1, csrf_token = $2, last_login = $3, last_activity = $3
                                 WHERE id = $4";
474
                    self.execute(query, &[&session_token, &csrf_token, &now, &id]).unwrap();
475
476
477
478
479

                    Ok(session_token)
                } else {
                    Err(())
                }
480
481
482
            })
            .map_err(|_| ())?
            .ok_or(())?
483
484
485
486
    }

    //TODO: use session
    fn login_with_code(&self, _session: Option<&str>, logincode: &str) -> Result<String, ()> {
487
488
489
490
        let query = "SELECT id
                     FROM session
                     WHERE logincode = $1";
        self.query_map_one(query, &[&logincode], |row| {
491
492
493
                // Login okay, update session now!
                let id: i32 = row.get(0);

494
495
                let session_token = helpers::make_session_token();
                let csrf_token = helpers::make_csrf_token();
496
497
                let now = time::get_time();

498
499
500
                let query = "UPDATE session
                             SET session_token = $1, csrf_token = $2, last_login = $3, last_activity = $3
                             WHERE id = $4";
501
                self.execute(query, &[&session_token, &csrf_token, &now, &id]).unwrap();
502

503
                session_token
504
505
506
            })
            .map_err(|_| ())?
            .ok_or(())
507
508
509
    }

    //TODO: use session
510
511
    fn login_foreign(&self, _session: Option<&str>, foreign_id: &str, is_teacher: bool, firstname: &str,
                     lastname: &str)
512
513
                     -> Result<String, ()>
    {
514
515
        let session_token = helpers::make_session_token();
        let csrf_token = helpers::make_csrf_token();
516
517
        let now = time::get_time();

518
519
520
        let query = "SELECT id
                     FROM session
                     WHERE oauth_foreign_id = $1";
521
522
        match self.query_map_one(query, &[&foreign_id], |row| -> i32 { row.get(0) }) {
            Ok(Some(id)) => {
523
524
525
                let query = "UPDATE session
                             SET session_token = $1, csrf_token = $2, last_login = $3, last_activity = $3
                             WHERE id = $4";
526
                self.execute(query, &[&session_token, &csrf_token, &now, &id]).unwrap();
527
528
529
530
531

                Ok(session_token)
            }
            // Add!
            _ => {
532
533
534
535
                let query = "INSERT INTO session (session_token, csrf_token, last_login, last_activity,
                                                  permanent_login, grade, is_teacher, oauth_foreign_id,
                                                  firstname, lastname)
                             VALUES ($1, $2, $3, $3, $4, $5, $6, $7, $8, $9)";
536
537
538
539
540
                self.execute(query,
                             &[&session_token,
                               &csrf_token,
                               &now,
                               &false,
541
                               &(if is_teacher { 255 } else { 0 }),
542
543
544
545
546
                               &is_teacher,
                               &foreign_id,
                               &firstname,
                               &lastname])
                    .unwrap();
547
548
549
550
551
552
553
554

                Ok(session_token)
            }
        }
    }

    //TODO: use session
    fn create_user_with_groupcode(&self, _session: Option<&str>, groupcode: &str) -> Result<String, ()> {
555
556
557
        let query = "SELECT id
                     FROM usergroup
                     WHERE groupcode = $1";
558
559
        let group_id =
            self.query_map_one(query, &[&groupcode], |row| -> i32 { row.get(0) }).map_err(|_| ())?.ok_or(())?;
560

561
562
563
        // Login okay, create session!
        let session_token = helpers::make_session_token();
        let csrf_token = helpers::make_csrf_token();
564
        let login_code = helpers::make_login_code(); // TODO: check for collisions
565
        let now = time::get_time();
566

567
568
569
        let query = "INSERT INTO session (session_token, csrf_token, last_login, last_activity, permanent_login,
                                          logincode, grade, is_teacher, managed_by)
                     VALUES ($1, $2, $3, $3, $4, $5, $6, $7, $8)";
570
        self.execute(query, &[&session_token, &csrf_token, &now, &false, &login_code, &0, &false, &group_id]).unwrap();
571

572
        Ok(session_token)
573
574
    }

Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
575
    fn create_group_with_users(&self, mut group: Group) {
576
577
578
579
580
581
        // Generate group ID:
        group.save(self);

        for user in group.members {
            let csrf_token = helpers::make_csrf_token();
            let login_code = helpers::make_login_code(); // TODO: check for collisions
Robert Czechowski's avatar
rustfmt    
Robert Czechowski committed
582

583
584
585
            let query = "INSERT INTO session (firstname, lastname, csrf_token, permanent_login, logincode, grade,
                                              is_teacher, managed_by)
                         VALUES ($1, $2, $3, $4, $5, $6, $7, $8)";
586
587
588
589
590
591
592
593
594
595
            self.execute(query,
                         &[&user.firstname,
                           &user.lastname,
                           &csrf_token,
                           &false,
                           &login_code,
                           &user.grade,
                           &false,
                           &group.id])
                .unwrap();
596
        }
597
598
    }

599
    fn logout(&self, session: &str) {
600
601
602
        let query = "UPDATE session
                     SET session_token = NULL
                     WHERE session_token = $1";
603
        self.execute(query, &[&session]).unwrap();
604
605
606
607
    }

    fn load_submission(&self, session: &SessionUser, task: i32, subtask: Option<&str>) -> Option<Submission> {
        match subtask {
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
            None => {
                let query = "SELECT id, grade, validated, nonvalidated_grade, value, date, needs_validation
                             FROM submission
                             WHERE task = $1
                             AND session = $2
                             ORDER BY id DESC
                             LIMIT 1";
                self.query_map_one(query, &[&task, &session.id], |row| Submission { id: Some(row.get(0)),
                                                                                    task: task,
                                                                                    session_user: session.id,
                                                                                    grade: row.get(1),
                                                                                    validated: row.get(2),
                                                                                    nonvalidated_grade: row.get(3),
                                                                                    subtask_identifier: None,
                                                                                    value: row.get(4),
                                                                                    date: row.get(5),
                                                                                    needs_validation: row.get(6) })
                    .ok()?
            }
            Some(subtask_id) => {
                let query = "SELECT id, grade, validated, nonvalidated_grade, value, date, needs_validation
                             FROM submission
                             WHERE task = $1
                             AND session = $2
                             AND subtask_identifier = $3
                             ORDER BY id DESC
                             LIMIT 1";
                self.query_map_one(query, &[&task, &session.id, &subtask_id], |row| {
                        Submission { id: Some(row.get(0)),
                                     task: task,
                                     session_user: session.id,
                                     grade: row.get(1),
                                     validated: row.get(2),
                                     nonvalidated_grade: row.get(3),
                                     subtask_identifier: Some(subtask_id.to_string()),
                                     value: row.get(4),
                                     date: row.get(5),
                                     needs_validation: row.get(6) }
                    })
                    .ok()?
            }
649
650
651
652
653
654
655
656
657
658
659
660
661
        }
    }
    fn submit_submission(&self, mut submission: Submission) {
        submission.save(self);

        let mut grade = self.get_grade_by_submission(submission.id.unwrap());
        if grade.grade.is_none() || submission.grade > grade.grade.unwrap() {
            grade.grade = Some(submission.grade);
            grade.validated = false;
            grade.save(self);
        }
    }
    fn get_grade_by_submission(&self, submission_id: i32) -> Grade {
662
663
664
665
666
667
        let query = "SELECT grade.taskgroup, grade.session, grade.grade, grade.validated
                     FROM grade
                     JOIN task ON grade.taskgroup = task.taskgroup
                     JOIN submission ON task.id = submission.task
                     AND grade.session = submission.session
                     WHERE submission.id = $1";
668
669
670
671
672
673
674
        self.query_map_one(query, &[&submission_id], |row| Grade { taskgroup: row.get(0),
                                                                   user: row.get(1),
                                                                   grade: row.get(2),
                                                                   validated: row.get(3) })
            .unwrap_or(None)
            .unwrap_or_else(|| {
                let query = "SELECT task.taskgroup, submission.session
675
676
677
                         FROM submission
                         JOIN task ON task.id = submission.task
                         WHERE submission.id = $1";
678
679
680
681
682
683
684
                self.query_map_one(query, &[&submission_id], |row| Grade { taskgroup: row.get(0),
                                                                           user: row.get(1),
                                                                           grade: None,
                                                                           validated: false })
                    .unwrap()
                    .unwrap() // should this unwrap?
            })
685
686
687
688
    }

    fn get_contest_groups_grades(&self, session_id: i32, contest_id: i32)
                                 -> (Vec<String>, Vec<(Group, Vec<(UserInfo, Vec<Grade>)>)>) {
689
690
691
692
        let query = "SELECT id, name
                     FROM taskgroup
                     WHERE contest = $1
                     ORDER BY id ASC";
693
694
695
        let tasknames: Vec<(i32, String)> =
            self.query_map_many(query, &[&contest_id], |row| (row.get(0), row.get(1))).unwrap();

696
697
698
699
700
701
702
        let mut taskindex: ::std::collections::BTreeMap<i32, usize> = ::std::collections::BTreeMap::new();

        let n_tasks = tasknames.len();
        for (index, (i, _)) in tasknames.iter().enumerate() {
            taskindex.insert(*i, index);
        }

703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
        let query = "SELECT grade.taskgroup, grade.session, grade.grade, grade.validated, usergroup.id, usergroup.name,
                            usergroup.groupcode, usergroup.tag, student.id, student.username, student.logincode,
                            student.firstname, student.lastname
                     FROM grade
                     JOIN taskgroup ON grade.taskgroup = taskgroup.id
                     JOIN session AS student ON grade.session = student.id
                     JOIN usergroup ON student.managed_by = usergroup.id
                     WHERE usergroup.admin = $1
                     AND taskgroup.contest = $2
                     ORDER BY usergroup.id, student.id, taskgroup.id ASC";
        let gradeinfo =
            self.query_map_many(query, &[&session_id, &contest_id], |row| {
                    (Grade { taskgroup: row.get(0), user: row.get(1), grade: row.get(2), validated: row.get(3) },
                     Group { id: Some(row.get(4)),
                             name: row.get(5),
                             groupcode: row.get(6),
                             tag: row.get(7),
                             admin: session_id,
                             members: Vec::new() },
                     UserInfo { id: row.get(8),
                                username: row.get(9),
                                logincode: row.get(10),
                                firstname: row.get(11),
                                lastname: row.get(12) })
                })
                .unwrap();
        let mut gradeinfo_iter = gradeinfo.iter();
730
731

        if let Some(t /*Ok((grade, mut group, mut userinfo))*/) = gradeinfo_iter.next() {
732
            let (grade, mut group, mut userinfo) = t.clone();
733
734
735
736
737
738

            let mut grades: Vec<Grade> = vec![Default::default(); n_tasks];
            let mut users: Vec<(UserInfo, Vec<Grade>)> = Vec::new();
            let mut groups: Vec<(Group, Vec<(UserInfo, Vec<Grade>)>)> = Vec::new();

            let index = grade.taskgroup;
739
            grades[taskindex[&index]] = grade;
740
741

            for ggu in gradeinfo_iter {
742
743
                let (g, gr, ui) = ggu;
                if gr.id != group.id {
744
745
                    users.push((userinfo, grades));
                    userinfo = ui.clone();
746
747
                    grades = vec![Default::default(); n_tasks];

748
749
                    groups.push((group, users));
                    group = gr.clone();
750
751
                    users = Vec::new();
                } else if ui.id != userinfo.id {
752
753
                    users.push((userinfo, grades));
                    userinfo = ui.clone();
754
                    grades = vec![Default::default(); n_tasks];
755
                }
756
                let index = g.taskgroup;
757
                grades[taskindex[&index]] = *g;
758
            }
759
760
            users.push((userinfo, grades));
            groups.push((group, users));
761
762
763
764
765
766
767

            (tasknames.iter().map(|(_, name)| name.clone()).collect(), groups)
        } else {
            (Vec::new(), Vec::new()) // should those be default filled?
        }
    }
    fn get_contest_user_grades(&self, session_token: &str, contest_id: i32) -> Vec<Grade> {
768
769
770
771
        let query = "SELECT id, name
                     FROM taskgroup
                     WHERE contest = $1
                     ORDER BY id ASC";
772
773
        let tasknames: Vec<(i32, String)> =
            self.query_map_many(query, &[&contest_id], |row| (row.get(0), row.get(1))).unwrap();
774
775
776
777
778
779
780
        let mut taskindex: ::std::collections::BTreeMap<i32, usize> = ::std::collections::BTreeMap::new();

        let n_tasks = tasknames.len();
        for (index, (i, _)) in tasknames.iter().enumerate() {
            taskindex.insert(*i, index);
        }

781
782
783
784
785
786
787
788
789
790
791
792
793
794
        let query = "SELECT grade.taskgroup, grade.session, grade.grade, grade.validated
                     FROM grade
                     JOIN taskgroup ON grade.taskgroup = taskgroup.id
                     JOIN session ON session.id = grade.session
                     WHERE session.session_token = $1
                     AND taskgroup.contest = $2
                     ORDER BY taskgroup.id ASC";
        let gradeinfo =
            self.query_map_many(query, &[&session_token, &contest_id], |row| Grade { taskgroup: row.get(0),
                                                                                     user: row.get(1),
                                                                                     grade: row.get(2),
                                                                                     validated: row.get(3) })
                .unwrap();
        let gradeinfo_iter = gradeinfo.iter();
795
796
797
798
799

        let mut grades: Vec<Grade> = vec![Default::default(); n_tasks];

        for g in gradeinfo_iter {
            let index = g.taskgroup;
800
            grades[taskindex[&index]] = *g;
801
802
803
804
805
806
        }

        grades
    }

    fn get_taskgroup_user_grade(&self, session_token: &str, taskgroup_id: i32) -> Grade {
807
        let query = "SELECT grade.taskgroup, grade.session, grade.grade, grade.validated
808
809
810
811
                     FROM grade
                     JOIN session ON session.id = grade.session
                     WHERE session.session_token = $1
                     AND grade.taskgroup = $2";
812
813
814
815
816
817
        self.query_map_one(query, &[&session_token, &taskgroup_id], |row| Grade { taskgroup: row.get(0),
                                                                                  user: row.get(1),
                                                                                  grade: row.get(2),
                                                                                  validated: row.get(3) })
            .unwrap_or(None)
            .unwrap_or_default()
818
819
820
    }

    fn get_contest_list(&self) -> Vec<Contest> {
821
822
        let query = "SELECT id, location, filename, name, duration, public, start_date, end_date, min_grade, max_grade,
                            positionalnumber
823
                     FROM contest
824
                     ORDER BY positionalnumber";
825
826
827
828
829
830
831
832
        self.query_map_many(query, &[], |row| Contest { id: Some(row.get(0)),
                                                        location: row.get(1),
                                                        filename: row.get(2),
                                                        name: row.get(3),
                                                        duration: row.get(4),
                                                        public: row.get(5),
                                                        start: row.get(6),
                                                        end: row.get(7),
833
834
                                                        min_grade: row.get(8),
                                                        max_grade: row.get(9),
835
                                                        positionalnumber: row.get(10),
836
837
                                                        taskgroups: Vec::new() })
            .unwrap()
838
839
840
    }

    fn get_contest_by_id(&self, contest_id: i32) -> Contest {
841
        let query = "SELECT location, filename, name, duration, public, start_date, end_date, min_grade, max_grade
842
843
                     FROM contest
                     WHERE id = $1";
844
845
846
847
848
849
850
851
        self.query_map_one(query, &[&contest_id], |row| Contest { id: Some(contest_id),
                                                                  location: row.get(0),
                                                                  filename: row.get(1),
                                                                  name: row.get(2),
                                                                  duration: row.get(3),
                                                                  public: row.get(4),
                                                                  start: row.get(5),
                                                                  end: row.get(6),
852
853
                                                                  min_grade: row.get(7),
                                                                  max_grade: row.get(8),
854
                                                                  positionalnumber: None,
855
                                                                  taskgroups: Vec::new() })
856
857
858
859
860
            .unwrap()
            .unwrap() // TODO: Should return Option?
    }

    fn get_contest_by_id_complete(&self, contest_id: i32) -> Contest {
861
        let query = "SELECT contest.location, contest.filename, contest.name, contest.duration, contest.public,
862
863
                            contest.start_date, contest.end_date, contest.min_grade, contest.max_grade, taskgroup.id,
                            taskgroup.name, task.id, task.location, task.stars
864
865
866
867
                     FROM contest
                     JOIN taskgroup ON contest.id = taskgroup.contest
                     JOIN task ON taskgroup.id = task.taskgroup
                     WHERE contest.id = $1
868
                     ORDER BY taskgroup.positionalnumber";
869
870
871
872
873
874
875
876
877
878
        let taskgroupcontest =
            self.query_map_many(query, &[&contest_id], |row| {
                    (Contest { id: Some(contest_id),
                               location: row.get(0),
                               filename: row.get(1),
                               name: row.get(2),
                               duration: row.get(3),
                               public: row.get(4),
                               start: row.get(5),
                               end: row.get(6),
879
880
                               min_grade: row.get(7),
                               max_grade: row.get(8),
881
                               positionalnumber: None,
882
                               taskgroups: Vec::new() },
883
                     Taskgroup { id: Some(row.get(9)),
884
                                 contest: contest_id,
885
                                 name: row.get(10),
886
887
                                 positionalnumber: None,
                                 tasks: Vec::new() },
888
                     Task { id: Some(row.get(11)), taskgroup: row.get(9), location: row.get(12), stars: row.get(13) })
889
890
891
                })
                .unwrap();
        let mut taskgroupcontest_iter = taskgroupcontest.into_iter();
892
893
894
895

        let (mut contest, mut taskgroup, task) = taskgroupcontest_iter.next().unwrap();
        taskgroup.tasks.push(task);
        for tgc in taskgroupcontest_iter {
896
897
898
899
            let (_, tg, t) = tgc;
            if tg.id != taskgroup.id {
                contest.taskgroups.push(taskgroup);
                taskgroup = tg;
900
            }
901
            taskgroup.tasks.push(t);
902
903
904
905
906
907
        }
        contest.taskgroups.push(taskgroup);
        contest
    }

    fn get_contest_by_id_partial(&self, contest_id: i32) -> Contest {
908
        let query = "SELECT contest.location, contest.filename, contest.name, contest.duration, contest.public,
909
910
                            contest.start_date, contest.end_date, contest.min_grade, contest.max_grade, taskgroup.id,
                            taskgroup.name
911
912
913
                     FROM contest
                     JOIN taskgroup ON contest.id = taskgroup.contest
                     WHERE contest.id = $1";
914
915
916
917
918
919
920
921
922
        let taskgroupcontest = self.query_map_many(query, &[&contest_id], |row| {
                                       (Contest { id: Some(contest_id),
                                                  location: row.get(0),
                                                  filename: row.get(1),
                                                  name: row.get(2),
                                                  duration: row.get(3),
                                                  public: row.get(4),
                                                  start: row.get(5),
                                                  end: row.get(6),
923
924
                                                  min_grade: row.get(7),
                                                  max_grade: row.get(8),
925
                                                  positionalnumber: None,
926
                                                  taskgroups: Vec::new() },
927
                                        Taskgroup { id: Some(row.get(9)),
928
                                                    contest: contest_id,
929
                                                    name: row.get(10),
930
931
932
933
                                                    positionalnumber: None,
                                                    tasks: Vec::new() })
                                   })
                                   .unwrap();
934
        let mut taskgroupcontest_iter = taskgroupcontest.into_iter();
935
936
937
938

        let (mut contest, taskgroup) = taskgroupcontest_iter.next().unwrap();
        contest.taskgroups.push(taskgroup);
        for tgc in taskgroupcontest_iter {
939
940
            let (_, tg) = tgc;
            contest.taskgroups.push(tg);
941
942
943
944
945
        }
        contest
    }

    fn get_participation(&self, session: &str, contest_id: i32) -> Option<Participation> {
946
947
948
949
950
        let query = "SELECT session, start_date
                     FROM participation
                     JOIN session ON session.id = session
                     WHERE session.session_token = $1
                     AND contest = $2";
951
952
953
954
        self.query_map_one(query, &[&session, &contest_id], |row| Participation { contest: contest_id,
                                                                                  user: row.get(0),
                                                                                  start: row.get(1) })
            .ok()?
955
956
    }
    fn new_participation(&self, session: &str, contest_id: i32) -> Result<Participation, ()> {
957
958
959
960
961
        let query = "SELECT session, start_date
                     FROM participation
                     JOIN session ON session.id = session
                     WHERE session.session_token = $1
                     AND contest = $2";
962
963
        match self.query_map_one(query, &[&session, &contest_id], |_| {}).map_err(|_| ())? {
            Some(()) => Err(()),
964
965
966
            None => {
                let now = time::get_time();
                self.execute(
967
                             "INSERT INTO participation (contest, session, start_date)
968
                     SELECT $1, id, $2 FROM session WHERE session_token = $3",
969
970
971
                             &[&contest_id, &now, &session],
                )
                    .unwrap();
972
973
974
975
976
977

                Ok(self.get_participation(session, contest_id).unwrap()) // TODO: This errors if not logged in …
            }
        }
    }
    fn get_task_by_id(&self, task_id: i32) -> Task {
978
979
980
        let query = "SELECT location, stars, taskgroup
                     FROM task
                     WHERE id = $1";
981
982
983
984
        self.query_map_one(query, &[&task_id], |row| Task { id: Some(task_id),
                                                            taskgroup: row.get(2),
                                                            location: row.get(0),
                                                            stars: row.get(1) })
985
986
987
988
            .unwrap()
            .unwrap()
    }
    fn get_task_by_id_complete(&self, task_id: i32) -> (Task, Taskgroup, Contest) {
989
990
        let query = "SELECT task.location, task.stars, taskgroup.id, taskgroup.name, contest.id, contest.location,
                            contest.filename, contest.name, contest.duration, contest.public, contest.start_date,
991
                            contest.end_date, contest.min_grade, contest.max_grade
992
993
994
995
                     FROM contest
                     JOIN taskgroup ON taskgroup.contest = contest.id
                     JOIN task ON task.taskgroup = taskgroup.id
                     WHERE task.id = $1";
996
997
        self.query_map_one(query, &[&task_id], |row| {
                (Task { id: Some(task_id), taskgroup: row.get(2), location: row.get(0), stars: row.get(1) },
998
999
1000
1001
1002
                 Taskgroup { id: Some(row.get(2)),
                             contest: row.get(4),
                             name: row.get(3),
                             positionalnumber: None,
                             tasks: Vec::new() },
1003
1004
1005
1006
1007
1008
1009
1010
                 Contest { id: Some(row.get(4)),
                           location: row.get(5),
                           filename: row.get(6),
                           name: row.get(7),
                           duration: row.get(8),
                           public: row.get(9),
                           start: row.get(10),
                           end: row.get(11),
1011
1012
                           min_grade: row.get(12),
                           max_grade: row.get(13),
1013
                           positionalnumber: None,
1014
1015
1016
1017
                           taskgroups: Vec::new() })
            })
            .unwrap()
            .unwrap()
1018
1019
1020
1021
    }

    fn get_submission_to_validate(&self, tasklocation: &str, subtask: Option<&str>) -> i32 {
        match subtask {
1022
            Some(st) => {
1023
1024
1025
1026
1027
1028
1029
                let query = "SELECT id
                             FROM submission
                             JOIN task ON submission.task = task.id
                             WHERE task.location = $1
                             AND subtask_identifier = $2
                             AND needs_validation = 1
                             LIMIT 1";
1030
1031
1032
                self.query_map_one(query, &[&tasklocation, &st], |row| row.get(0)).unwrap().unwrap()
            }
            None => {
1033
1034
1035
1036
1037
1038
                let query = "SELECT id
                             FROM submission
                             JOIN task ON submission.task = task.id
                             WHERE task.location = $1
                             AND needs_validation = 1
                             LIMIT 1";
1039
1040
                self.query_map_one(query, &[&tasklocation], |row| row.get(0)).unwrap().unwrap()
            }
1041
1042
1043
1044
        }
    }

    fn find_next_submission_to_validate(&self, userid: i32, taskgroupid: i32) {
1045
1046
1047
1048
1049
1050
1051
        let query = "SELECT id, validated
                     FROM submission
                     JOIN task ON submission.task = task.id
                     WHERE task.taskgroup = $1
                     AND submission.session = $2
                     ORDER BY value DESC id DESC
                     LIMIT 1";
1052
1053
        let (id, validated): (i32, bool) =
            self.query_map_one(query, &[&taskgroupid, &userid], |row| (row.get(0), row.get(1))).unwrap().unwrap();
1054
        if !validated {
1055
1056
1057
            let query = "UPDATE submission
                         SET needs_validation = 1
                         WHERE id = $1";
1058
            self.execute(query, &[&id]).unwrap();
1059
1060
1061
1062
1063
1064
        }
    }

    fn add_group(&self, group: &mut Group) { group.save(self); }

    fn get_groups(&self, session_id: i32) -> Vec<Group> {
1065
1066
1067
        let query = "SELECT id, name, groupcode, tag
                     FROM usergroup
                     WHERE admin = $1";
1068
1069
1070
1071
1072
1073
        self.query_map_many(query, &[&session_id], |row| Group { id: Some(row.get(0)),
                                                                 name: row.get(1),
                                                                 groupcode: row.get(2),
                                                                 tag: row.get(3),
                                                                 admin: session_id,
                                                                 members: Vec::new() })
1074
1075
1076
1077
1078
1079
            .unwrap()
    }
    fn get_groups_complete(&self, _session_id: i32) -> Vec<Group> {
        unimplemented!();
    }
    fn get_group_complete(&self, group_id: i32) -> Option<Group> {
1080
1081
1082
        let query = "SELECT name, groupcode, tag, admin
                     FROM usergroup
                     WHERE id  = $1";
1083
1084
1085
1086
1087
1088
        let mut group = self.query_map_one(query, &[&group_id], |row| Group { id: Some(group_id),
                                                                              name: row.get(0),
                                                                              groupcode: row.get(1),
                                                                              tag: row.get(2),
                                                                              admin: row.get(3),
                                                                              members: Vec::new() })
1089
1090
1091
                            .unwrap()
                            .unwrap(); // TODO handle error

1092
1093
1094
1095
1096
1097
1098
1099
1100
1101
1102
1103
1104
1105
1106
1107
1108
1109
1110
1111
1112
1113
1114
1115
1116
1117
1118
1119
1120
1121
1122
1123
1124
1125
1126
        let query = "SELECT id, session_token, csrf_token, last_login, last_activity, permanent_login, username,
                            password, logincode, email, email_unconfirmed, email_confirmationcode, firstname, lastname,
                            street, zip, city, nation, grade, is_teacher, oauth_provider, oauth_foreign_id, salt
                     FROM session
                     WHERE managed_by = $1";
        group.members = self.query_map_many(query, &[&group_id], |row| SessionUser { id: row.get(0),
                                                                                     session_token: row.get(1),
                                                                                     csrf_token: row.get(2),
                                                                                     last_login: row.get(3),
                                                                                     last_activity: row.get(4),
                                                                                     permanent_login: row.get(5),

                                                                                     username: row.get(6),
                                                                                     password: row.get(7),
                                                                                     salt: row.get(22),
                                                                                     logincode: row.get(8),
                                                                                     email: row.get(9),
                                                                                     email_unconfirmed: row.get(10),
                                                                                     email_confirmationcode:
                                                                                         row.get(11),

                                                                                     firstname: row.get(12),
                                                                                     lastname: row.get(13),
                                                                                     street: row.get(14),
                                                                                     zip: row.get(15),
                                                                                     city: row.get(16),
                                                                                     nation: row.get(17),
                                                                                     grade: row.get(18),

                                                                                     is_teacher: row.get(19),
                                                                                     managed_by: Some(group_id),

                                                                                     oauth_provider: row.get(20),
                                                                                     oauth_foreign_id: row.get(21) })
                            .unwrap();
1127
1128
        Some(group)
    }
1129

1130
    fn reset_all_contest_visibilities(&self) { self.execute("UPDATE contest SET public = $1", &[&false]).unwrap(); }
1131
}