app.js 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174
  1. 'use strict';
  2. const express = require('express');
  3. const bodyParser = require('body-parser');
  4. const cors = require('cors');
  5. const config = require('config');
  6. const async = require('async');
  7. const logger = require('./logger');
  8. const mail = require('./mail');
  9. const request = require('request');
  10. const OAuth2 = require('oauth').OAuth2;
  11. const api = require('./api');
  12. const cache = require('./cache');
  13. const db = require('./db');
  14. let utils;
  15. const lib = {
  16. app: null,
  17. server: null,
  18. init: (cb) => {
  19. utils = require('./utils');
  20. let app = lib.app = express();
  21. lib.server = app.listen(config.get('serverPort'));
  22. app.use(bodyParser.json());
  23. app.use(bodyParser.urlencoded({ extended: true }));
  24. let corsOptions = Object.assign({}, config.get('cors'));
  25. app.use(cors(corsOptions));
  26. app.options('*', cors(corsOptions));
  27. let oauth2 = new OAuth2(
  28. config.get('apis.github.client'),
  29. config.get('apis.github.secret'),
  30. 'https://github.com/',
  31. 'login/oauth/authorize',
  32. 'login/oauth/access_token',
  33. null
  34. );
  35. let redirect_uri = config.get('serverDomain') + '/auth/github/authorize/callback';
  36. app.get('/auth/github/authorize', (req, res) => {
  37. let params = [
  38. `client_id=${config.get('apis.github.client')}`,
  39. `redirect_uri=${config.get('serverDomain')}/auth/github/authorize/callback`,
  40. `scope=user:email`
  41. ].join('&');
  42. res.redirect(`https://github.com/login/oauth/authorize?${params}`);
  43. });
  44. function redirectOnErr (res, err){
  45. return res.redirect(`${config.get('domain')}/?err=${encodeURIComponent(err)}`);
  46. }
  47. app.get('/auth/github/authorize/callback', (req, res) => {
  48. let code = req.query.code;
  49. oauth2.getOAuthAccessToken(code, { redirect_uri }, (err, access_token, refresh_token, results) => {
  50. if (!err) request.get({
  51. url: `https://api.github.com/user?access_token=${access_token}`,
  52. headers: { 'User-Agent': 'request' }
  53. }, (err, httpResponse, body) => {
  54. if (err) return redirectOnErr(res, err.message);
  55. body = JSON.parse(body);
  56. db.models.user.findOne({'services.github.id': body.id}, (err, user) => {
  57. if (err) return redirectOnErr(res, 'err');
  58. if (user) {
  59. user.services.github.access_token = access_token;
  60. user.save(err => {
  61. if (err) return redirectOnErr(res, err.message);
  62. let sessionId = utils.guid();
  63. cache.hset('sessions', sessionId, cache.schemas.session(sessionId, user._id), err => {
  64. if (err) return redirectOnErr(res, err.message);
  65. let date = new Date();
  66. date.setTime(new Date().getTime() + (2 * 365 * 24 * 60 * 60 * 1000));
  67. res.cookie('SID', sessionId, {expires: date, secure: config.get("cookie.secure"), path: "/", domain: config.get("cookie.domain")});
  68. res.redirect(`${config.get('domain')}/`);
  69. });
  70. });
  71. } else {
  72. db.models.user.findOne({ username: new RegExp(`^${body.login}$`, 'i') }, (err, user) => {
  73. if (err) return redirectOnErr(res, err.message);
  74. if (user) return redirectOnErr(res, 'An account with that username already exists.');
  75. else request.get({
  76. url: `https://api.github.com/user/emails?access_token=${access_token}`,
  77. headers: {'User-Agent': 'request'}
  78. }, (err, httpResponse, body2) => {
  79. if (err) return redirectOnErr(res, err.message);
  80. body2 = JSON.parse(body2);
  81. let address;
  82. if (!Array.isArray(body2)) return redirectOnErr(res, body2.message);
  83. body2.forEach(email => {
  84. if (email.primary) address = email.email.toLowerCase();
  85. });
  86. db.models.user.findOne({'email.address': address}, (err, user) => {
  87. let verificationToken = utils.generateRandomString(64);
  88. if (err) return redirectOnErr(res, err.message);
  89. if (user) return redirectOnErr(res, 'An account with that email address already exists.');
  90. else db.models.user.create({
  91. _id: utils.generateRandomString(12),//TODO Check if exists
  92. username: body.login,
  93. email: {
  94. address,
  95. verificationToken: verificationToken
  96. },
  97. services: {
  98. github: {id: body.id, access_token}
  99. }
  100. }, (err, user) => {
  101. if (err) return redirectOnErr(res, err.message);
  102. mail.schemas.verifyEmail(address, body.login, verificationToken);
  103. let sessionId = utils.guid();
  104. cache.hset('sessions', sessionId, cache.schemas.session(sessionId, user._id), err => {
  105. if (err) return redirectOnErr(res, err.message);
  106. let date = new Date();
  107. date.setTime(new Date().getTime() + (2 * 365 * 24 * 60 * 60 * 1000));
  108. res.cookie('SID', sessionId, {expires: date, secure: config.get("cookie.secure"), path: "/", domain: config.get("cookie.domain")});
  109. res.redirect(`${config.get('domain')}/`);
  110. });
  111. });
  112. });
  113. });
  114. });
  115. }
  116. });
  117. });
  118. else return redirectOnErr(res, 'err');
  119. });
  120. });
  121. app.get('/auth/verify_email', (req, res) => {
  122. let code = req.query.code;
  123. async.waterfall([
  124. (next) => {
  125. if (!code) return next('Invalid code.');
  126. next();
  127. },
  128. (next) => {
  129. db.models.user.findOne({"email.verificationToken": code}, next);
  130. },
  131. (user, next) => {
  132. if (!user) return next('User not found.');
  133. if (user.email.verified) return next('This email is already verified.');
  134. db.models.user.update({"email.verificationToken": code}, {$set: {"email.verified": true}, $unset: {"email.verificationToken": ''}}, next);
  135. }
  136. ], (err) => {
  137. if (err) {
  138. let error = 'An error occurred.';
  139. if (typeof err === "string") error = err;
  140. else if (err.message) error = err.message;
  141. logger.error("VERIFY_EMAIL", `Verifying email failed. "${error}"`);
  142. return res.json({ status: 'failure', message: error});
  143. }
  144. logger.success("VERIFY_EMAIL", `Successfully verified email.`);
  145. res.redirect(config.get("domain"));
  146. });
  147. });
  148. cb();
  149. }
  150. };
  151. module.exports = lib;