derivantes/lib/derivantes_web/controllers/user_session_controller.ex
2024-07-15 10:13:56 -03:00

43 lines
1.3 KiB
Elixir
Executable File

defmodule DerivantesWeb.UserSessionController do
use DerivantesWeb, :controller
alias Derivantes.Accounts
alias DerivantesWeb.UserAuth
def create(conn, %{"_action" => "registered"} = params) do
create(conn, params, "Account created successfully!")
end
def create(conn, %{"_action" => "password_updated"} = params) do
conn
|> put_session(:user_return_to, ~p"/derivantes/settings")
|> create(params, "Password updated successfully!")
end
def create(conn, params) do
create(conn, params, "Welcome back!")
end
defp create(conn, %{"user" => user_params}, info) do
%{"matricula" => matricula, "password" => password} = user_params
if user = Accounts.get_user_by_matricula_and_password(matricula, password) do
conn
|> put_flash(:info, info)
|> UserAuth.log_in_user(user, user_params)
else
# In order to prevent user enumeration attacks, don't disclose whether the email is registered.
conn
|> put_flash(:error, "Invalid email or password")
|> put_flash(:matricula, String.slice(matricula, 0, 160))
|> redirect(to: ~p"/derivantes/log_in")
end
end
def delete(conn, _params) do
conn
|> put_flash(:info, "Logged out successfully.")
|> UserAuth.log_out_user()
end
end