app.js 7.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214
  1. 'use strict';
  2. const express = require('express');
  3. const bodyParser = require('body-parser');
  4. const cookieParser = require('cookie-parser');
  5. const cors = require('cors');
  6. const config = require('config');
  7. const async = require('async');
  8. const logger = require('./logger');
  9. const mail = require('./mail');
  10. const request = require('request');
  11. const OAuth2 = require('oauth').OAuth2;
  12. const api = require('./api');
  13. const cache = require('./cache');
  14. const db = require('./db');
  15. let utils;
  16. const lib = {
  17. app: null,
  18. server: null,
  19. init: (cb) => {
  20. utils = require('./utils');
  21. let app = lib.app = express();
  22. lib.server = app.listen(config.get('serverPort'));
  23. app.use(cookieParser());
  24. app.use(bodyParser.json());
  25. app.use(bodyParser.urlencoded({ extended: true }));
  26. let corsOptions = Object.assign({}, config.get('cors'));
  27. app.use(cors(corsOptions));
  28. app.options('*', cors(corsOptions));
  29. let oauth2 = new OAuth2(
  30. config.get('apis.github.client'),
  31. config.get('apis.github.secret'),
  32. 'https://github.com/',
  33. 'login/oauth/authorize',
  34. 'login/oauth/access_token',
  35. null
  36. );
  37. let redirect_uri = config.get('serverDomain') + '/auth/github/authorize/callback';
  38. app.get('/auth/github/authorize', (req, res) => {
  39. let params = [
  40. `client_id=${config.get('apis.github.client')}`,
  41. `redirect_uri=${config.get('serverDomain')}/auth/github/authorize/callback`,
  42. `scope=user:email`
  43. ].join('&');
  44. res.redirect(`https://github.com/login/oauth/authorize?${params}`);
  45. });
  46. app.get('/auth/github/link', (req, res) => {
  47. let params = [
  48. `client_id=${config.get('apis.github.client')}`,
  49. `redirect_uri=${config.get('serverDomain')}/auth/github/authorize/callback`,
  50. `scope=user:email`,
  51. `state=${req.cookies.SID}`
  52. ].join('&');
  53. res.redirect(`https://github.com/login/oauth/authorize?${params}`);
  54. });
  55. function redirectOnErr (res, err){
  56. return res.redirect(`${config.get('domain')}/?err=${encodeURIComponent(err)}`);
  57. }
  58. app.get('/auth/github/authorize/callback', (req, res) => {
  59. let code = req.query.code;
  60. const state = req.query.state;
  61. oauth2.getOAuthAccessToken(code, {redirect_uri}, (err, access_token, refresh_token, results) => {
  62. if (!err) request.get({
  63. url: `https://api.github.com/user?access_token=${access_token}`,
  64. headers: {'User-Agent': 'request'}
  65. }, (err, httpResponse, body) => {
  66. if (err) return redirectOnErr(res, err.message);
  67. body = JSON.parse(body);
  68. if (state) {
  69. cache.hget('sessions', state, (err, session) => {
  70. if (err) return redirectOnErr(res, err.message);
  71. db.models.user.findOne({_id: session.userId}, (err, user) => {
  72. if (err) return redirectOnErr(res, err.message);
  73. if (!user) return redirectOnErr(res, 'Not logged in.');
  74. if (user.services.github && user.services.github.id) return redirectOnErr(res, 'Account already has GitHub linked.');
  75. db.models.user.update({_id: user._id}, {$set: {"services.github": {id: body.id, access_token}}}, (err) => {
  76. if (err) return redirectOnErr(res, err.message);
  77. cache.pub('user.linkGitHub', user._id);
  78. res.redirect(`${config.get('domain')}/settings`);
  79. });
  80. });
  81. });
  82. } else {
  83. db.models.user.findOne({'services.github.id': body.id}, (err, user) => {
  84. if (err) return redirectOnErr(res, 'err');
  85. if (user) {
  86. user.services.github.access_token = access_token;
  87. user.save(err => {
  88. if (err) return redirectOnErr(res, err.message);
  89. let sessionId = utils.guid();
  90. cache.hset('sessions', sessionId, cache.schemas.session(sessionId, user._id), err => {
  91. if (err) return redirectOnErr(res, err.message);
  92. let date = new Date();
  93. date.setTime(new Date().getTime() + (2 * 365 * 24 * 60 * 60 * 1000));
  94. res.cookie('SID', sessionId, {
  95. expires: date,
  96. secure: config.get("cookie.secure"),
  97. path: "/",
  98. domain: config.get("cookie.domain")
  99. });
  100. res.redirect(`${config.get('domain')}/`);
  101. });
  102. });
  103. } else {
  104. db.models.user.findOne({username: new RegExp(`^${body.login}$`, 'i')}, (err, user) => {
  105. if (err) return redirectOnErr(res, err.message);
  106. if (user) return redirectOnErr(res, 'An account with that username already exists.');
  107. else request.get({
  108. url: `https://api.github.com/user/emails?access_token=${access_token}`,
  109. headers: {'User-Agent': 'request'}
  110. }, (err, httpResponse, body2) => {
  111. if (err) return redirectOnErr(res, err.message);
  112. body2 = JSON.parse(body2);
  113. let address;
  114. if (!Array.isArray(body2)) return redirectOnErr(res, body2.message);
  115. body2.forEach(email => {
  116. if (email.primary) address = email.email.toLowerCase();
  117. });
  118. db.models.user.findOne({'email.address': address}, (err, user) => {
  119. let verificationToken = utils.generateRandomString(64);
  120. if (err) return redirectOnErr(res, err.message);
  121. if (user) return redirectOnErr(res, 'An account with that email address already exists.');
  122. else db.models.user.create({
  123. _id: utils.generateRandomString(12),//TODO Check if exists
  124. username: body.login,
  125. email: {
  126. address,
  127. verificationToken: verificationToken
  128. },
  129. services: {
  130. github: {id: body.id, access_token}
  131. }
  132. }, (err, user) => {
  133. if (err) return redirectOnErr(res, err.message);
  134. mail.schemas.verifyEmail(address, body.login, verificationToken);
  135. let sessionId = utils.guid();
  136. cache.hset('sessions', sessionId, cache.schemas.session(sessionId, user._id), err => {
  137. if (err) return redirectOnErr(res, err.message);
  138. let date = new Date();
  139. date.setTime(new Date().getTime() + (2 * 365 * 24 * 60 * 60 * 1000));
  140. res.cookie('SID', sessionId, {
  141. expires: date,
  142. secure: config.get("cookie.secure"),
  143. path: "/",
  144. domain: config.get("cookie.domain")
  145. });
  146. res.redirect(`${config.get('domain')}/`);
  147. });
  148. });
  149. });
  150. });
  151. });
  152. }
  153. });
  154. }
  155. });
  156. else return redirectOnErr(res, 'err');
  157. });
  158. });
  159. app.get('/auth/verify_email', (req, res) => {
  160. let code = req.query.code;
  161. async.waterfall([
  162. (next) => {
  163. if (!code) return next('Invalid code.');
  164. next();
  165. },
  166. (next) => {
  167. db.models.user.findOne({"email.verificationToken": code}, next);
  168. },
  169. (user, next) => {
  170. if (!user) return next('User not found.');
  171. if (user.email.verified) return next('This email is already verified.');
  172. db.models.user.update({"email.verificationToken": code}, {$set: {"email.verified": true}, $unset: {"email.verificationToken": ''}}, next);
  173. }
  174. ], (err) => {
  175. if (err) {
  176. let error = 'An error occurred.';
  177. if (typeof err === "string") error = err;
  178. else if (err.message) error = err.message;
  179. logger.error("VERIFY_EMAIL", `Verifying email failed. "${error}"`);
  180. return res.json({ status: 'failure', message: error});
  181. }
  182. logger.success("VERIFY_EMAIL", `Successfully verified email.`);
  183. res.redirect(config.get("domain"));
  184. });
  185. });
  186. cb();
  187. }
  188. };
  189. module.exports = lib;