user.js 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353
  1. let bcrypt = require('bcryptjs')
  2. let multer = require('multer')
  3. let express = require('express')
  4. let router = express.Router()
  5. const Errors = require('../lib/errors.js')
  6. let {
  7. User, Post, ProfilePicture, AdminToken, Thread, Category, Sequelize, Ip, Ban, sequelize
  8. } = require('../models')
  9. let pagination = require('../lib/pagination.js')
  10. function setUserSession(req, res, username, UserId, admin) {
  11. req.session.loggedIn = true
  12. req.session.username = username
  13. req.session.UserId = UserId
  14. res.cookie('username', username)
  15. //Not for security purposes, just so client side can determine
  16. //to show certain parts of ui or not (i.e. could trivially be spoofed
  17. //but the server would not accept any api requests)
  18. res.cookie('admin', !!admin)
  19. if(admin) { req.session.admin = true }
  20. }
  21. router.post('/', async (req, res, next) => {
  22. try {
  23. await Ban.isIpBanned(req.ip)
  24. let userParams = {
  25. username: req.body.username,
  26. hash: req.body.password,
  27. admin: false
  28. }
  29. if(req.body.admin && await User.canBeAdmin(req.body.token)) {
  30. userParams.admin = true
  31. }
  32. let user = await User.create(userParams)
  33. await Ip.createIfNotExists(req.ip, user)
  34. setUserSession(req, res, user.username, user.id, userParams.admin)
  35. res.json(user.toJSON())
  36. } catch (e) { next(e) }
  37. })
  38. router.get('/:username', async (req, res, next) => {
  39. try {
  40. let queryObj = {
  41. attributes: { exclude: ['hash'] },
  42. where: { username: req.params.username }
  43. }
  44. if(req.query.posts) {
  45. let { from, limit } = pagination.getPaginationProps(req.query, true)
  46. let postInclude = {
  47. model: Post,
  48. include: Post.includeOptions(),
  49. limit,
  50. order: [['id', 'DESC']]
  51. }
  52. if(from !== null) {
  53. postInclude.where = { id: { $lte: from } }
  54. }
  55. queryObj.include = [postInclude]
  56. let user = await User.findOne(queryObj)
  57. if(!user) throw Errors.accountDoesNotExist
  58. let meta = await user.getMeta(limit)
  59. res.json(Object.assign( user.toJSON(limit), { meta } ))
  60. } else if(req.query.threads) {
  61. let queryString = ''
  62. Object.keys(req.query).forEach(query => {
  63. queryString += `&${query}=${req.query[query]}`
  64. })
  65. res.redirect('/api/v1/category/ALL?username=' + req.params.username + queryString)
  66. } else {
  67. let user = await User.findOne(queryObj)
  68. if(!user) throw Errors.accountDoesNotExist
  69. res.json(user.toJSON())
  70. }
  71. } catch (err) { next(err) }
  72. })
  73. router.post('/:username/login', async (req, res, next) => {
  74. try {
  75. await Ban.isIpBanned(req.ip, req.params.username)
  76. let user = await User.findOne({ where: {
  77. username: req.params.username
  78. }})
  79. if(user) {
  80. if(await user.comparePassword(req.body.password)) {
  81. await Ip.createIfNotExists(req.ip, user)
  82. setUserSession(req, res, user.username, user.id, user.admin)
  83. res.json({
  84. username: user.username,
  85. admin: user.admin,
  86. success: true
  87. })
  88. } else {
  89. res.status(401)
  90. res.json({
  91. errors: [Errors.invalidLoginCredentials]
  92. })
  93. }
  94. } else {
  95. res.status(401)
  96. res.json({
  97. errors: [Errors.invalidLoginCredentials]
  98. })
  99. }
  100. } catch (err) { next(err) }
  101. })
  102. router.post('/:username/logout', async (req, res) => {
  103. req.session.destroy(() => {
  104. res.clearCookie('username')
  105. res.clearCookie('admin')
  106. res.json({
  107. success: true
  108. })
  109. })
  110. })
  111. router.get('/:username/picture', async (req, res, next) => {
  112. try {
  113. let user = await User.findOne({
  114. where: {
  115. username: req.params.username
  116. }
  117. })
  118. if(!user) throw Errors.accountDoesNotExist
  119. let picture = await ProfilePicture.findOne({
  120. where: {
  121. UserId: user.id
  122. }
  123. })
  124. if(!picture) {
  125. res.status(404)
  126. res.end('')
  127. } else {
  128. res.writeHead(200, {
  129. 'Content-Type': picture.mimetype,
  130. 'Content-disposition': 'attachment;filename=profile',
  131. 'Content-Length': picture.file.length
  132. })
  133. res.end(new Buffer(picture.file, 'binary'))
  134. }
  135. } catch (e) { next(e) }
  136. })
  137. router.all('*', (req, res, next) => {
  138. if(req.session.username) {
  139. next()
  140. } else {
  141. res.status(401)
  142. res.json({
  143. errors: [Errors.requestNotAuthorized]
  144. })
  145. }
  146. })
  147. let upload = multer({ storage: multer.memoryStorage() })
  148. router.post('/:username/picture', upload.single('picture'), async (req, res, next) => {
  149. try {
  150. if(req.session.username !== req.params.username) {
  151. throw Errors.requestNotAuthorized
  152. } else {
  153. let user = await User.findById(req.session.UserId)
  154. let picture = await ProfilePicture.findOne({
  155. where: { UserId: user.id}
  156. })
  157. let pictureObj = {
  158. file: req.file.buffer,
  159. mimetype: req.file.mimetype
  160. }
  161. //No picture set yet
  162. if(!picture) {
  163. picture = await ProfilePicture.create(pictureObj)
  164. await picture.setUser(user)
  165. } else {
  166. await picture.update(pictureObj)
  167. }
  168. //Add random query to end to force browser to reload background images
  169. await user.update({
  170. picture: '/api/v1/user/' + req.session.username + '/picture?rand=' + Date.now()
  171. })
  172. res.json(user.toJSON())
  173. }
  174. } catch (e) { next(e) }
  175. })
  176. router.delete('/:username/picture', async (req, res, next) => {
  177. try {
  178. if(req.session.username !== req.params.username) {
  179. throw Errors.requestNotAuthorized
  180. } else {
  181. let user = await User.findById(req.session.UserId)
  182. let picture = await ProfilePicture.findOne({
  183. where: { UserId: user.id}
  184. })
  185. await user.update({
  186. picture: null
  187. })
  188. await picture.destroy()
  189. res.json(user.toJSON())
  190. }
  191. } catch (e) { next(e) }
  192. })
  193. router.put('/:username', async (req, res, next) => {
  194. try {
  195. if(req.session.username !== req.params.username) {
  196. throw Errors.requestNotAuthorized
  197. }
  198. if(req.body.description !== undefined) {
  199. let user = await User.update({ description: req.body.description }, { where: {
  200. username: req.session.username
  201. }})
  202. res.json({ success: true })
  203. } else if(
  204. req.body.currentPassword !== undefined &&
  205. req.body.newPassword !== undefined
  206. ) {
  207. let user = await User.findOne({where: {
  208. username: req.session.username
  209. }})
  210. await user.updatePassword(req.body.currentPassword, req.body.newPassword)
  211. res.json({ success: true })
  212. } else {
  213. res.json({ success: false })
  214. }
  215. } catch (e) { next(e) }
  216. })
  217. router.delete('/:username', async (req, res, next) => {
  218. try {
  219. if(req.session.username !== req.params.username) {
  220. throw Errors.requestNotAuthorized
  221. }
  222. let user = await User.findOne({ where: {
  223. username: req.session.username
  224. }})
  225. await user.destroy()
  226. req.session.destroy(() => {
  227. res.clearCookie('username')
  228. res.clearCookie('admin')
  229. res.json({ success: true })
  230. })
  231. } catch (e) { next(e) }
  232. })
  233. router.all('*', (req, res, next) => {
  234. if(req.session.admin) {
  235. next()
  236. } else {
  237. res.status(401)
  238. res.json({
  239. errors: [Errors.requestNotAuthorized]
  240. })
  241. }
  242. })
  243. router.get('/', async (req, res, next) => {
  244. try {
  245. let sortFields = {
  246. createdAt: 'X.id',
  247. username: 'X.username',
  248. threadCount: 'threadCount',
  249. postCount: 'postCount'
  250. };
  251. let offset = Number.isInteger(+req.query.offset) ? +req.query.offset : 0;
  252. let havingClause = '';
  253. if(req.query.role === 'admin') {
  254. havingClause = 'HAVING Users.admin = true';
  255. } else if(req.query.role === 'user') {
  256. havingClause = 'HAVING Users.admin = false';
  257. } else {
  258. havingClause = '';
  259. }
  260. if(req.query.search) {
  261. //I.e. if there is not already a HAVING clause
  262. if(!havingClause.length) {
  263. havingClause = 'HAVING ';
  264. } else {
  265. havingClause += ' AND ';
  266. }
  267. havingClause += 'Users.username LIKE $search';
  268. }
  269. let sql = `
  270. SELECT X.username, X.admin, X.createdAt, X.postCount, COUNT(Threads.id) as threadCount
  271. FROM (
  272. SELECT Users.*, COUNT(Posts.id) as postCount
  273. FROM Users
  274. LEFT OUTER JOIN Posts
  275. ON Users.id = Posts.UserId
  276. GROUP BY Users.id
  277. ${havingClause}
  278. ) as X
  279. LEFT OUTER JOIN threads
  280. ON X.id = Threads.UserId
  281. GROUP BY X.id
  282. ORDER BY ${sortFields[req.query.sort] || 'X.id'} ${req.query.order === 'asc' ? 'ASC' : 'DESC'}
  283. LIMIT 15
  284. OFFSET ${offset}
  285. `;
  286. let users = await sequelize.query(sql, {
  287. model: User,
  288. bind: { search: req.query.search + '%' }
  289. });
  290. res.json(users)
  291. } catch (e) { next(e) }
  292. })
  293. module.exports = router;