user.js 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420
  1. let bcrypt = require('bcryptjs')
  2. let multer = require('multer')
  3. let express = require('express')
  4. let router = express.Router()
  5. const Errors = require('../lib/errors.js')
  6. let {
  7. User, Post, ProfilePicture, AdminToken, Thread, Category, Sequelize, Ip, Ban
  8. } = require('../models')
  9. let pagination = require('../lib/pagination.js')
  10. function setUserSession(req, res, username, UserId, admin) {
  11. req.session.loggedIn = true
  12. req.session.username = username
  13. req.session.UserId = UserId
  14. res.cookie('username', username)
  15. //Not for security purposes, just so client side can determine
  16. //to show certain parts of ui or not (i.e. could trivially be spoofed
  17. //but the server would not accept any api requests)
  18. res.cookie('admin', !!admin)
  19. if(admin) { req.session.admin = true }
  20. }
  21. router.post('/', async (req, res) => {
  22. try {
  23. await Ban.isIpBanned(req.ip)
  24. let userParams = {
  25. username: req.body.username,
  26. hash: req.body.password,
  27. admin: false
  28. }
  29. if(req.body.admin && await User.canBeAdmin(req.body.token)) {
  30. userParams.admin = true
  31. }
  32. let user = await User.create(userParams)
  33. await Ip.createIfNotExists(req.ip, user)
  34. setUserSession(req, res, user.username, user.id, userParams.admin)
  35. res.json(user.toJSON())
  36. } catch (e) {
  37. if(e instanceof Sequelize.ValidationError) {
  38. res.status(400)
  39. res.json(e)
  40. } else if (e.name in Errors) {
  41. res.status(401)
  42. res.json({
  43. errors: [e]
  44. })
  45. } else {
  46. console.log(e)
  47. res.status(500)
  48. res.json({
  49. errors: [Errors.unknown]
  50. })
  51. }
  52. }
  53. })
  54. router.get('/:username', async (req, res) => {
  55. try {
  56. let queryObj = {
  57. attributes: { exclude: ['hash'] },
  58. where: { username: req.params.username }
  59. }
  60. if(req.query.posts) {
  61. let { from, limit } = pagination.getPaginationProps(req.query, true)
  62. let postInclude = {
  63. model: Post,
  64. include: Post.includeOptions(),
  65. limit,
  66. order: [['id', 'DESC']]
  67. }
  68. if(from !== null) {
  69. postInclude.where = { id: { $lte: from } }
  70. }
  71. queryObj.include = [postInclude]
  72. let user = await User.findOne(queryObj)
  73. if(!user) throw Errors.accountDoesNotExist
  74. let meta = await user.getMeta(limit)
  75. res.json(Object.assign( user.toJSON(limit), { meta } ))
  76. } else if(req.query.threads) {
  77. let queryString = ''
  78. Object.keys(req.query).forEach(query => {
  79. queryString += `&${query}=${req.query[query]}`
  80. })
  81. res.redirect('/api/v1/category/ALL?username=' + req.params.username + queryString)
  82. } else {
  83. let user = await User.findOne(queryObj)
  84. if(!user) throw Errors.accountDoesNotExist
  85. res.json(user.toJSON())
  86. }
  87. } catch (err) {
  88. if(err === Errors.accountDoesNotExist) {
  89. res.status(400)
  90. res.json({ errors: [err] })
  91. } else {
  92. console.log(err)
  93. res.status(500)
  94. res.json({
  95. errors: [Errors.unknown]
  96. })
  97. }
  98. }
  99. })
  100. router.post('/:username/login', async (req, res) => {
  101. try {
  102. await Ban.isIpBanned(req.ip, req.params.username)
  103. let user = await User.findOne({ where: {
  104. username: req.params.username
  105. }})
  106. if(user) {
  107. if(await user.comparePassword(req.body.password)) {
  108. await Ip.createIfNotExists(req.ip, user)
  109. setUserSession(req, res, user.username, user.id, user.admin)
  110. res.json({
  111. username: user.username,
  112. admin: user.admin,
  113. success: true
  114. })
  115. } else {
  116. res.status(401)
  117. res.json({
  118. errors: [Errors.invalidLoginCredentials]
  119. })
  120. }
  121. } else {
  122. res.status(401)
  123. res.json({
  124. errors: [Errors.invalidLoginCredentials]
  125. })
  126. }
  127. } catch (err) {
  128. if(err instanceof Sequelize.ValidationError) {
  129. res.status(400)
  130. res.json(err)
  131. } else {
  132. console.log(err)
  133. res.status(500)
  134. res.json({
  135. errors: [Errors.unknown]
  136. })
  137. }
  138. }
  139. })
  140. router.post('/:username/logout', async (req, res) => {
  141. req.session.destroy(() => {
  142. res.clearCookie('username')
  143. res.clearCookie('admin')
  144. res.json({
  145. success: true
  146. })
  147. })
  148. })
  149. router.get('/:username/picture', async (req, res) => {
  150. try {
  151. let user = await User.findOne({
  152. where: {
  153. username: req.params.username
  154. }
  155. })
  156. if(!user) throw Errors.accountDoesNotExist
  157. let picture = await ProfilePicture.findOne({
  158. where: {
  159. UserId: user.id
  160. }
  161. })
  162. if(!picture) {
  163. res.status(404)
  164. res.end('')
  165. } else {
  166. res.writeHead(200, {
  167. 'Content-Type': picture.mimetype,
  168. 'Content-disposition': 'attachment;filename=profile',
  169. 'Content-Length': picture.file.length
  170. })
  171. res.end(new Buffer(picture.file, 'binary'))
  172. }
  173. } catch (e) {
  174. if(e === Errors.accountDoesNotExist) {
  175. res.status(400)
  176. res.json({ errors: [e] })
  177. } else {
  178. console.log(e)
  179. res.status(500)
  180. res.json({
  181. errors: [Errors.unknown]
  182. })
  183. }
  184. }
  185. })
  186. router.all('*', (req, res, next) => {
  187. if(req.session.username) {
  188. next()
  189. } else {
  190. res.status(401)
  191. res.json({
  192. errors: [Errors.requestNotAuthorized]
  193. })
  194. }
  195. })
  196. let upload = multer({ storage: multer.memoryStorage() })
  197. router.post('/:username/picture', upload.single('picture'), async (req, res) => {
  198. try {
  199. if(req.session.username !== req.params.username) {
  200. throw Errors.requestNotAuthorized
  201. } else {
  202. let user = await User.findById(req.session.UserId)
  203. let picture = await ProfilePicture.findOne({
  204. where: { UserId: user.id}
  205. })
  206. let pictureObj = {
  207. file: req.file.buffer,
  208. mimetype: req.file.mimetype
  209. }
  210. //No picture set yet
  211. if(!picture) {
  212. picture = await ProfilePicture.create(pictureObj)
  213. await picture.setUser(user)
  214. await user.update({
  215. picture: '/api/v1/user/' + req.session.username + '/picture'
  216. })
  217. } else {
  218. await picture.update(pictureObj)
  219. }
  220. res.json(user.toJSON())
  221. }
  222. } catch (e) {
  223. if(e === Errors.requestNotAuthorized) {
  224. res.status(401)
  225. res.json({
  226. errors: [e]
  227. })
  228. } else if(e instanceof Sequelize.ValidationError) {
  229. res.status(400)
  230. res.json(e)
  231. } else {
  232. console.log(e)
  233. res.status(500)
  234. res.json({
  235. errors: [Errors.unknown]
  236. })
  237. }
  238. }
  239. })
  240. router.delete('/:username/picture', async (req, res) => {
  241. try {
  242. if(req.session.username !== req.params.username) {
  243. throw Errors.requestNotAuthorized
  244. } else {
  245. let user = await User.findById(req.session.UserId)
  246. let picture = await ProfilePicture.findOne({
  247. where: { UserId: user.id}
  248. })
  249. await user.update({
  250. picture: null
  251. })
  252. await picture.destroy()
  253. res.json(user.toJSON())
  254. }
  255. } catch (e) {
  256. if(e === Errors.requestNotAuthorized) {
  257. res.status(401)
  258. res.json({
  259. errors: [e]
  260. })
  261. } else {
  262. console.log(e)
  263. res.status(500)
  264. res.json({
  265. errors: [Errors.unknown]
  266. })
  267. }
  268. }
  269. })
  270. router.put('/:username', async (req, res) => {
  271. try {
  272. if(req.session.username !== req.params.username) {
  273. throw Errors.requestNotAuthorized
  274. }
  275. if(req.body.description !== undefined) {
  276. let user = await User.update({ description: req.body.description }, { where: {
  277. username: req.session.username
  278. }})
  279. res.json({ success: true })
  280. } else if(
  281. req.body.currentPassword !== undefined &&
  282. req.body.newPassword !== undefined
  283. ) {
  284. let user = await User.findOne({where: {
  285. username: req.session.username
  286. }})
  287. await user.updatePassword(req.body.currentPassword, req.body.newPassword)
  288. res.json({ success: true })
  289. } else {
  290. res.json({ success: false })
  291. }
  292. } catch (e) {
  293. if(e.name in Errors) {
  294. res.status(400)
  295. res.json({ errors: [e] })
  296. } else if(e instanceof Sequelize.ValidationError) {
  297. res.status(400)
  298. res.json(e)
  299. } else {
  300. console.log(e)
  301. res.status(500)
  302. res.json({errors: Errors.unknown })
  303. }
  304. }
  305. })
  306. router.delete('/:username', async (req, res) => {
  307. try {
  308. if(req.session.username !== req.params.username) {
  309. throw Errors.requestNotAuthorized
  310. }
  311. let user = await User.findOne({ where: {
  312. username: req.session.username
  313. }})
  314. await user.destroy()
  315. req.session.destroy(() => {
  316. res.clearCookie('username')
  317. res.clearCookie('admin')
  318. res.json({ success: true })
  319. })
  320. } catch (e) {
  321. if(e.name in Errors) {
  322. res.status(400)
  323. res.json({ errors: [e] })
  324. } else {
  325. console.log(e)
  326. res.status(500)
  327. res.json({errors: Errors.unknown })
  328. }
  329. }
  330. })
  331. router.all('*', (req, res, next) => {
  332. if(req.session.admin) {
  333. next()
  334. } else {
  335. res.status(401)
  336. res.json({
  337. errors: [Errors.requestNotAuthorized]
  338. })
  339. }
  340. })
  341. router.get('/', async (req, res) => {
  342. try {
  343. if(req.query.admin) {
  344. let admins = await User.findAll({
  345. where: { admin: true },
  346. attributes: {
  347. exclude: ['hash']
  348. }
  349. })
  350. res.json(admins)
  351. } else {
  352. res.json({})
  353. }
  354. } catch (e) {
  355. console.log(e)
  356. res.json({
  357. errors: [Errors.unknown]
  358. })
  359. }
  360. })
  361. module.exports = router