golang-template/internal/handlers/signup.go
2026-08-17 11:15:45 +03:00

83 lines
1.9 KiB
Go

package handlers
import (
"encoding/json"
"go-backend/internal/auth"
"go-backend/internal/database/sqlc"
"log"
"net/http"
)
type SignUpRequest struct {
Username string `json:"username"`
Password string `json:"password"`
Email string `json:"email"`
}
func (h *Handler) SignUpHandler(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodPost {
http.Error(w, "Method not allowed", http.StatusMethodNotAllowed)
return
}
var req SignUpRequest
decoder := json.NewDecoder(r.Body)
err := decoder.Decode(&req)
if err != nil {
http.Error(w, "Invalid request body", http.StatusBadRequest)
return
}
if req.Username == "" || req.Password == "" || req.Email == "" {
http.Error(w, "Invalid request body", http.StatusBadRequest)
return
}
user, err := h.users.FindByUsername(r.Context(), req.Username)
if err != nil {
http.Error(w, "Internal server error", http.StatusInternalServerError)
return
}
if user != nil {
http.Error(w, "Username already taken", http.StatusBadRequest)
return
}
hashedPassword, err := auth.HashPassword(req.Password)
if err != nil {
http.Error(w, "Internal server error", http.StatusInternalServerError)
return
}
user, err = h.users.CreateUser(r.Context(), sqlc.InsertUserParams{Username: req.Username, Email: req.Email, PasswordHash: hashedPassword})
if err != nil {
http.Error(w, "Internal server error", http.StatusInternalServerError)
return
}
session, err := h.auth.CreateSession(r.Context(), user.ID)
if err != nil {
log.Printf("Error creating session: %v", err)
http.Error(w, "Internal server error", http.StatusInternalServerError)
return
}
cookie := &http.Cookie{
Name: "session",
Value: session.Token,
HttpOnly: true,
SameSite: http.SameSiteLaxMode,
MaxAge: 86400, // 24 hours
Path: "/",
}
http.SetCookie(w, cookie)
w.WriteHeader(http.StatusOK)
w.Write([]byte("Success"))
}