user.js 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415
  1. let bcrypt = require('bcryptjs')
  2. let multer = require('multer')
  3. let express = require('express')
  4. let router = express.Router()
  5. const Errors = require('../lib/errors.js')
  6. let {
  7. User, Post, ProfilePicture, AdminToken, Thread, Category, Sequelize, Ip, Ban
  8. } = require('../models')
  9. let pagination = require('../lib/pagination.js')
  10. function setUserSession(req, res, username, UserId, admin) {
  11. req.session.loggedIn = true
  12. req.session.username = username
  13. req.session.UserId = UserId
  14. res.cookie('username', username)
  15. //Not for security purposes, just so client side can determine
  16. //to show certain parts of ui or not (i.e. could trivially be spoofed
  17. //but the server would not accept any api requests)
  18. res.cookie('admin', !!admin)
  19. if(admin) { req.session.admin = true }
  20. }
  21. router.post('/', async (req, res) => {
  22. try {
  23. await Ban.isIpBanned(req.ip)
  24. let userParams = {
  25. username: req.body.username,
  26. hash: req.body.password,
  27. admin: false
  28. }
  29. if(req.body.admin && await User.canBeAdmin(req.body.token)) {
  30. userParams.admin = true
  31. }
  32. let user = await User.create(userParams)
  33. await Ip.createIfNotExists(req.ip, user)
  34. setUserSession(req, res, user.username, user.id, userParams.admin)
  35. res.json(user.toJSON())
  36. } catch (e) {
  37. if(e instanceof Sequelize.ValidationError) {
  38. res.status(400)
  39. res.json(e)
  40. } else if (e.name in Errors) {
  41. res.status(401)
  42. res.json({
  43. errors: [e]
  44. })
  45. } else {
  46. console.log(e)
  47. res.status(500)
  48. res.json({
  49. errors: [Errors.unknown]
  50. })
  51. }
  52. }
  53. })
  54. router.get('/:username', async (req, res) => {
  55. try {
  56. let queryObj = {
  57. attributes: { exclude: ['hash'] },
  58. where: { username: req.params.username }
  59. }
  60. if(req.query.posts) {
  61. let { from, limit } = pagination.getPaginationProps(req.query, true)
  62. let postInclude = {
  63. model: Post,
  64. include: Post.includeOptions(),
  65. limit,
  66. order: [['id', 'DESC']]
  67. }
  68. if(from !== null) {
  69. postInclude.where = { id: { $lte: from } }
  70. }
  71. queryObj.include = [postInclude]
  72. let user = await User.findOne(queryObj)
  73. if(!user) throw Errors.accountDoesNotExist
  74. let meta = await user.getMeta(limit)
  75. res.json(Object.assign( user.toJSON(limit), { meta } ))
  76. } else if(req.query.threads) {
  77. let queryString = ''
  78. Object.keys(req.query).forEach(query => {
  79. queryString += `&${query}=${req.query[query]}`
  80. })
  81. res.redirect('/api/v1/category/ALL?username=' + req.params.username + queryString)
  82. } else {
  83. let user = await User.findOne(queryObj)
  84. if(!user) throw Errors.accountDoesNotExist
  85. res.json(user.toJSON())
  86. }
  87. } catch (err) {
  88. if(err === Errors.accountDoesNotExist) {
  89. res.status(400)
  90. res.json({ errors: [err] })
  91. } else {
  92. console.log(err)
  93. res.status(500)
  94. res.json({
  95. errors: [Errors.unknown]
  96. })
  97. }
  98. }
  99. })
  100. router.post('/:username/login', async (req, res) => {
  101. try {
  102. await Ban.isIpBanned(req.ip, req.params.username)
  103. let user = await User.findOne({ where: {
  104. username: req.params.username
  105. }})
  106. if(user) {
  107. if(await user.comparePassword(req.body.password)) {
  108. await Ip.createIfNotExists(req.ip, user)
  109. setUserSession(req, res, user.username, user.id, user.admin)
  110. res.json({
  111. username: user.username,
  112. admin: user.admin,
  113. success: true
  114. })
  115. } else {
  116. res.status(401)
  117. res.json({
  118. errors: [Errors.invalidLoginCredentials]
  119. })
  120. }
  121. } else {
  122. res.status(401)
  123. res.json({
  124. errors: [Errors.invalidLoginCredentials]
  125. })
  126. }
  127. } catch (err) {
  128. if(err instanceof Sequelize.ValidationError) {
  129. res.status(400)
  130. res.json(err)
  131. } else {
  132. console.log(err)
  133. res.status(500)
  134. res.json({
  135. errors: [Errors.unknown]
  136. })
  137. }
  138. }
  139. })
  140. router.post('/:username/logout', async (req, res) => {
  141. req.session.destroy(() => {
  142. res.clearCookie('username')
  143. res.clearCookie('admin')
  144. res.json({
  145. success: true
  146. })
  147. })
  148. })
  149. router.get('/:username/picture', async (req, res) => {
  150. try {
  151. let user = await User.findOne({
  152. where: {
  153. username: req.params.username
  154. }
  155. })
  156. if(!user) throw Errors.accountDoesNotExist
  157. let picture = await ProfilePicture.findOne({
  158. where: {
  159. UserId: user.id
  160. }
  161. })
  162. res.writeHead(200, {
  163. 'Content-Type': picture.mimetype,
  164. 'Content-disposition': 'attachment;filename=profile',
  165. 'Content-Length': picture.file.length
  166. });
  167. res.end(new Buffer(picture.file, 'binary'));
  168. } catch (e) {
  169. if(err === Errors.accountDoesNotExist) {
  170. res.status(400)
  171. res.json({ errors: [err] })
  172. } else {
  173. console.log(err)
  174. res.status(500)
  175. res.json({
  176. errors: [Errors.unknown]
  177. })
  178. }
  179. }
  180. })
  181. router.all('*', (req, res, next) => {
  182. if(req.session.username) {
  183. next()
  184. } else {
  185. res.status(401)
  186. res.json({
  187. errors: [Errors.requestNotAuthorized]
  188. })
  189. }
  190. })
  191. let upload = multer({ storage: multer.memoryStorage() })
  192. router.post('/:username/picture', upload.single('picture'), async (req, res) => {
  193. try {
  194. if(req.session.username !== req.params.username) {
  195. throw Errors.requestNotAuthorized
  196. } else {
  197. let user = await User.findById(req.session.UserId)
  198. let picture = await ProfilePicture.findOne({
  199. where: { UserId: user.id}
  200. })
  201. let pictureObj = {
  202. file: req.file.buffer,
  203. mimetype: req.file.mimetype
  204. }
  205. //No picture set yet
  206. if(!picture) {
  207. picture = await ProfilePicture.create(pictureObj)
  208. await picture.setUser(user)
  209. await user.update({
  210. picture: '/api/v1/user/' + req.session.username + '/picture'
  211. })
  212. } else {
  213. await ProfilePicture.update(pictureObj)
  214. }
  215. res.json(user.toJSON())
  216. }
  217. } catch (e) {
  218. if(e === Errors.requestNotAuthorized) {
  219. res.status(401)
  220. res.json({
  221. errors: [e]
  222. })
  223. } else if(e instanceof Sequelize.ValidationError) {
  224. res.status(400)
  225. res.json(e)
  226. } else {
  227. console.log(e)
  228. res.status(500)
  229. res.json({
  230. errors: [Errors.unknown]
  231. })
  232. }
  233. }
  234. })
  235. router.delete('/:username/picture', async (req, res) => {
  236. try {
  237. if(req.session.username !== req.params.username) {
  238. throw Errors.requestNotAuthorized
  239. } else {
  240. let user = await User.findById(req.session.UserId)
  241. let picture = await ProfilePicture.findOne({
  242. where: { UserId: user.id}
  243. })
  244. await user.update({
  245. picture: null
  246. })
  247. await picture.destroy()
  248. res.json(user.toJSON())
  249. }
  250. } catch (e) {
  251. if(e === Errors.requestNotAuthorized) {
  252. res.status(401)
  253. res.json({
  254. errors: [e]
  255. })
  256. } else {
  257. console.log(e)
  258. res.status(500)
  259. res.json({
  260. errors: [Errors.unknown]
  261. })
  262. }
  263. }
  264. })
  265. router.put('/:username', async (req, res) => {
  266. try {
  267. if(req.session.username !== req.params.username) {
  268. throw Errors.requestNotAuthorized
  269. }
  270. if(req.body.description !== undefined) {
  271. let user = await User.update({ description: req.body.description }, { where: {
  272. username: req.session.username
  273. }})
  274. res.json({ success: true })
  275. } else if(
  276. req.body.currentPassword !== undefined &&
  277. req.body.newPassword !== undefined
  278. ) {
  279. let user = await User.findOne({where: {
  280. username: req.session.username
  281. }})
  282. await user.updatePassword(req.body.currentPassword, req.body.newPassword)
  283. res.json({ success: true })
  284. } else {
  285. res.json({ success: false })
  286. }
  287. } catch (e) {
  288. if(e.name in Errors) {
  289. res.status(400)
  290. res.json({ errors: [e] })
  291. } else if(e instanceof Sequelize.ValidationError) {
  292. res.status(400)
  293. res.json(e)
  294. } else {
  295. console.log(e)
  296. res.status(500)
  297. res.json({errors: Errors.unknown })
  298. }
  299. }
  300. })
  301. router.delete('/:username', async (req, res) => {
  302. try {
  303. if(req.session.username !== req.params.username) {
  304. throw Errors.requestNotAuthorized
  305. }
  306. let user = await User.findOne({ where: {
  307. username: req.session.username
  308. }})
  309. await user.destroy()
  310. req.session.destroy(() => {
  311. res.clearCookie('username')
  312. res.clearCookie('admin')
  313. res.json({ success: true })
  314. })
  315. } catch (e) {
  316. if(e.name in Errors) {
  317. res.status(400)
  318. res.json({ errors: [e] })
  319. } else {
  320. console.log(e)
  321. res.status(500)
  322. res.json({errors: Errors.unknown })
  323. }
  324. }
  325. })
  326. router.all('*', (req, res, next) => {
  327. if(req.session.admin) {
  328. next()
  329. } else {
  330. res.status(401)
  331. res.json({
  332. errors: [Errors.requestNotAuthorized]
  333. })
  334. }
  335. })
  336. router.get('/', async (req, res) => {
  337. try {
  338. if(req.query.admin) {
  339. let admins = await User.findAll({
  340. where: { admin: true },
  341. attributes: {
  342. exclude: ['hash']
  343. }
  344. })
  345. res.json(admins)
  346. } else {
  347. res.json({})
  348. }
  349. } catch (e) {
  350. console.log(e)
  351. res.json({
  352. errors: [Errors.unknown]
  353. })
  354. }
  355. })
  356. module.exports = router