public UserRegisterQuery() {} // required for Gson
@Override
protected Response internalExecute(HttpServletRequest request, Session databaseSession) {
Response response = null;
User user = null;
HttpSession httpSession = request.getSession();
if( null != httpSession.getAttribute("currentUser") ) {
return new Response(ResponseStatus.FAIL, "You are already logged-in");
}
try {
// wow, how unnecessary is to store roles in the database...
Criteria userRoleCriteria = databaseSession.createCriteria(Role.class).add(Restrictions.eq("description", "User"));
Role userRole = (Role) userRoleCriteria.uniqueResult();
if (userRole == null) {
return new Response(ResponseStatus.FAIL, "User role does not exist, database failure.");
}
this.username = XssHandler.escape(this.username);
this.fullname = XssHandler.escape(this.fullname);
user = new User();
user.setRole(userRole);
user.setFullname(fullname);
user.setPassword(password);
user.setUsername(username);
Transaction transaction = databaseSession.beginTransaction();
try {
databaseSession.save(user);
transaction.commit();