user.js 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422
  1. let bcrypt = require('bcryptjs')
  2. let multer = require('multer')
  3. let express = require('express')
  4. let router = express.Router()
  5. const Errors = require('../lib/errors.js')
  6. let {
  7. User, Post, ProfilePicture, AdminToken, Thread, Category, Sequelize, Ip, Ban
  8. } = require('../models')
  9. let pagination = require('../lib/pagination.js')
  10. function setUserSession(req, res, username, UserId, admin) {
  11. req.session.loggedIn = true
  12. req.session.username = username
  13. req.session.UserId = UserId
  14. res.cookie('username', username)
  15. //Not for security purposes, just so client side can determine
  16. //to show certain parts of ui or not (i.e. could trivially be spoofed
  17. //but the server would not accept any api requests)
  18. res.cookie('admin', !!admin)
  19. if(admin) { req.session.admin = true }
  20. }
  21. router.post('/', async (req, res) => {
  22. try {
  23. await Ban.isIpBanned(req.ip)
  24. let userParams = {
  25. username: req.body.username,
  26. hash: req.body.password,
  27. admin: false
  28. }
  29. if(req.body.admin && await User.canBeAdmin(req.body.token)) {
  30. userParams.admin = true
  31. }
  32. let user = await User.create(userParams)
  33. await Ip.createIfNotExists(req.ip, user)
  34. setUserSession(req, res, user.username, user.id, userParams.admin)
  35. res.json(user.toJSON())
  36. } catch (e) {
  37. if(e instanceof Sequelize.ValidationError) {
  38. res.status(400)
  39. res.json(e)
  40. } else if (e.name in Errors) {
  41. res.status(401)
  42. res.json({
  43. errors: [e]
  44. })
  45. } else {
  46. console.log(e)
  47. res.status(500)
  48. res.json({
  49. errors: [Errors.unknown]
  50. })
  51. }
  52. }
  53. })
  54. router.get('/:username', async (req, res) => {
  55. try {
  56. let queryObj = {
  57. attributes: { exclude: ['hash'] },
  58. where: { username: req.params.username }
  59. }
  60. if(req.query.posts) {
  61. let { from, limit } = pagination.getPaginationProps(req.query, true)
  62. let postInclude = {
  63. model: Post,
  64. include: Post.includeOptions(),
  65. limit,
  66. order: [['id', 'DESC']]
  67. }
  68. if(from !== null) {
  69. postInclude.where = { id: { $lte: from } }
  70. }
  71. queryObj.include = [postInclude]
  72. let user = await User.findOne(queryObj)
  73. if(!user) throw Errors.accountDoesNotExist
  74. let meta = await user.getMeta(limit)
  75. res.json(Object.assign( user.toJSON(limit), { meta } ))
  76. } else if(req.query.threads) {
  77. let queryString = ''
  78. Object.keys(req.query).forEach(query => {
  79. queryString += `&${query}=${req.query[query]}`
  80. })
  81. res.redirect('/api/v1/category/ALL?username=' + req.params.username + queryString)
  82. } else {
  83. let user = await User.findOne(queryObj)
  84. if(!user) throw Errors.accountDoesNotExist
  85. res.json(user.toJSON())
  86. }
  87. } catch (err) {
  88. if(err === Errors.accountDoesNotExist) {
  89. res.status(400)
  90. res.json({ errors: [err] })
  91. } else {
  92. console.log(err)
  93. res.status(500)
  94. res.json({
  95. errors: [Errors.unknown]
  96. })
  97. }
  98. }
  99. })
  100. router.post('/:username/login', async (req, res) => {
  101. try {
  102. await Ban.isIpBanned(req.ip, req.params.username)
  103. let user = await User.findOne({ where: {
  104. username: req.params.username
  105. }})
  106. if(user) {
  107. if(await user.comparePassword(req.body.password)) {
  108. await Ip.createIfNotExists(req.ip, user)
  109. setUserSession(req, res, user.username, user.id, user.admin)
  110. res.json({
  111. username: user.username,
  112. admin: user.admin,
  113. success: true
  114. })
  115. } else {
  116. res.status(401)
  117. res.json({
  118. errors: [Errors.invalidLoginCredentials]
  119. })
  120. }
  121. } else {
  122. res.status(401)
  123. res.json({
  124. errors: [Errors.invalidLoginCredentials]
  125. })
  126. }
  127. } catch (err) {
  128. if(err instanceof Sequelize.ValidationError) {
  129. res.status(400)
  130. res.json(err)
  131. } else {
  132. console.log(err)
  133. res.status(500)
  134. res.json({
  135. errors: [Errors.unknown]
  136. })
  137. }
  138. }
  139. })
  140. router.post('/:username/logout', async (req, res) => {
  141. req.session.destroy(() => {
  142. res.clearCookie('username')
  143. res.clearCookie('admin')
  144. res.json({
  145. success: true
  146. })
  147. })
  148. })
  149. router.get('/:username/picture', async (req, res) => {
  150. try {
  151. let user = await User.findOne({
  152. where: {
  153. username: req.params.username
  154. }
  155. })
  156. if(!user) throw Errors.accountDoesNotExist
  157. let picture = await ProfilePicture.findOne({
  158. where: {
  159. UserId: user.id
  160. }
  161. })
  162. if(!picture) {
  163. res.status(404)
  164. res.end('')
  165. } else {
  166. res.writeHead(200, {
  167. 'Content-Type': picture.mimetype,
  168. 'Content-disposition': 'attachment;filename=profile',
  169. 'Content-Length': picture.file.length
  170. })
  171. res.end(new Buffer(picture.file, 'binary'))
  172. }
  173. } catch (e) {
  174. if(e === Errors.accountDoesNotExist) {
  175. res.status(400)
  176. res.json({ errors: [e] })
  177. } else {
  178. console.log(e)
  179. res.status(500)
  180. res.json({
  181. errors: [Errors.unknown]
  182. })
  183. }
  184. }
  185. })
  186. router.all('*', (req, res, next) => {
  187. if(req.session.username) {
  188. next()
  189. } else {
  190. res.status(401)
  191. res.json({
  192. errors: [Errors.requestNotAuthorized]
  193. })
  194. }
  195. })
  196. let upload = multer({ storage: multer.memoryStorage() })
  197. router.post('/:username/picture', upload.single('picture'), async (req, res) => {
  198. try {
  199. if(req.session.username !== req.params.username) {
  200. throw Errors.requestNotAuthorized
  201. } else {
  202. let user = await User.findById(req.session.UserId)
  203. let picture = await ProfilePicture.findOne({
  204. where: { UserId: user.id}
  205. })
  206. let pictureObj = {
  207. file: req.file.buffer,
  208. mimetype: req.file.mimetype
  209. }
  210. //No picture set yet
  211. if(!picture) {
  212. picture = await ProfilePicture.create(pictureObj)
  213. await picture.setUser(user)
  214. } else {
  215. await picture.update(pictureObj)
  216. }
  217. //Add random query to end to force browser to reload background images
  218. await user.update({
  219. picture: '/api/v1/user/' + req.session.username + '/picture?rand=' + Date.now()
  220. })
  221. res.json(user.toJSON())
  222. }
  223. } catch (e) {
  224. if(e === Errors.requestNotAuthorized) {
  225. res.status(401)
  226. res.json({
  227. errors: [e]
  228. })
  229. } else if(e instanceof Sequelize.ValidationError) {
  230. res.status(400)
  231. res.json(e)
  232. } else {
  233. console.log(e)
  234. res.status(500)
  235. res.json({
  236. errors: [Errors.unknown]
  237. })
  238. }
  239. }
  240. })
  241. router.delete('/:username/picture', async (req, res) => {
  242. try {
  243. if(req.session.username !== req.params.username) {
  244. throw Errors.requestNotAuthorized
  245. } else {
  246. let user = await User.findById(req.session.UserId)
  247. let picture = await ProfilePicture.findOne({
  248. where: { UserId: user.id}
  249. })
  250. await user.update({
  251. picture: null
  252. })
  253. await picture.destroy()
  254. res.json(user.toJSON())
  255. }
  256. } catch (e) {
  257. if(e === Errors.requestNotAuthorized) {
  258. res.status(401)
  259. res.json({
  260. errors: [e]
  261. })
  262. } else {
  263. console.log(e)
  264. res.status(500)
  265. res.json({
  266. errors: [Errors.unknown]
  267. })
  268. }
  269. }
  270. })
  271. router.put('/:username', async (req, res) => {
  272. try {
  273. if(req.session.username !== req.params.username) {
  274. throw Errors.requestNotAuthorized
  275. }
  276. if(req.body.description !== undefined) {
  277. let user = await User.update({ description: req.body.description }, { where: {
  278. username: req.session.username
  279. }})
  280. res.json({ success: true })
  281. } else if(
  282. req.body.currentPassword !== undefined &&
  283. req.body.newPassword !== undefined
  284. ) {
  285. let user = await User.findOne({where: {
  286. username: req.session.username
  287. }})
  288. await user.updatePassword(req.body.currentPassword, req.body.newPassword)
  289. res.json({ success: true })
  290. } else {
  291. res.json({ success: false })
  292. }
  293. } catch (e) {
  294. if(e.name in Errors) {
  295. res.status(400)
  296. res.json({ errors: [e] })
  297. } else if(e instanceof Sequelize.ValidationError) {
  298. res.status(400)
  299. res.json(e)
  300. } else {
  301. console.log(e)
  302. res.status(500)
  303. res.json({errors: Errors.unknown })
  304. }
  305. }
  306. })
  307. router.delete('/:username', async (req, res) => {
  308. try {
  309. if(req.session.username !== req.params.username) {
  310. throw Errors.requestNotAuthorized
  311. }
  312. let user = await User.findOne({ where: {
  313. username: req.session.username
  314. }})
  315. await user.destroy()
  316. req.session.destroy(() => {
  317. res.clearCookie('username')
  318. res.clearCookie('admin')
  319. res.json({ success: true })
  320. })
  321. } catch (e) {
  322. if(e.name in Errors) {
  323. res.status(400)
  324. res.json({ errors: [e] })
  325. } else {
  326. console.log(e)
  327. res.status(500)
  328. res.json({errors: Errors.unknown })
  329. }
  330. }
  331. })
  332. router.all('*', (req, res, next) => {
  333. if(req.session.admin) {
  334. next()
  335. } else {
  336. res.status(401)
  337. res.json({
  338. errors: [Errors.requestNotAuthorized]
  339. })
  340. }
  341. })
  342. router.get('/', async (req, res) => {
  343. try {
  344. if(req.query.admin) {
  345. let admins = await User.findAll({
  346. where: { admin: true },
  347. attributes: {
  348. exclude: ['hash']
  349. }
  350. })
  351. res.json(admins)
  352. } else {
  353. res.json({})
  354. }
  355. } catch (e) {
  356. console.log(e)
  357. res.json({
  358. errors: [Errors.unknown]
  359. })
  360. }
  361. })
  362. module.exports = router