app.js 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237
  1. 'use strict';
  2. const coreClass = require("../core");
  3. const express = require('express');
  4. const bodyParser = require('body-parser');
  5. const cookieParser = require('cookie-parser');
  6. const cors = require('cors');
  7. const config = require('config');
  8. const async = require('async');
  9. const request = require('request');
  10. const OAuth2 = require('oauth').OAuth2;
  11. module.exports = class extends coreClass {
  12. initialize() {
  13. return new Promise((resolve, reject) => {
  14. const logger = this.logger,
  15. mail = this.moduleManager.modules["mail"],
  16. cache = this.moduleManager.modules["cache"],
  17. db = this.moduleManager.modules["db"];
  18. this.utils = this.moduleManager.modules["utils"];
  19. let app = this.app = express();
  20. this.server = app.listen(config.get('serverPort'));
  21. app.use(cookieParser());
  22. app.use(bodyParser.json());
  23. app.use(bodyParser.urlencoded({ extended: true }));
  24. let corsOptions = Object.assign({}, config.get('cors'));
  25. app.use(cors(corsOptions));
  26. app.options('*', cors(corsOptions));
  27. let oauth2 = new OAuth2(
  28. config.get('apis.github.client'),
  29. config.get('apis.github.secret'),
  30. 'https://github.com/',
  31. 'login/oauth/authorize',
  32. 'login/oauth/access_token',
  33. null
  34. );
  35. let redirect_uri = config.get('serverDomain') + '/auth/github/authorize/callback';
  36. app.get('/auth/github/authorize', async (req, res) => {
  37. try { await this._validateHook(); } catch { return; }
  38. let params = [
  39. `client_id=${config.get('apis.github.client')}`,
  40. `redirect_uri=${config.get('serverDomain')}/auth/github/authorize/callback`,
  41. `scope=user:email`
  42. ].join('&');
  43. res.redirect(`https://github.com/login/oauth/authorize?${params}`);
  44. });
  45. app.get('/auth/github/link', async (req, res) => {
  46. try { await this._validateHook(); } catch { return; }
  47. let params = [
  48. `client_id=${config.get('apis.github.client')}`,
  49. `redirect_uri=${config.get('serverDomain')}/auth/github/authorize/callback`,
  50. `scope=user:email`,
  51. `state=${req.cookies.SID}`
  52. ].join('&');
  53. res.redirect(`https://github.com/login/oauth/authorize?${params}`);
  54. });
  55. function redirectOnErr (res, err){
  56. return res.redirect(`${config.get('domain')}/?err=${encodeURIComponent(err)}`);
  57. }
  58. app.get('/auth/github/authorize/callback', async (req, res) => {
  59. try { await this._validateHook(); } catch { return; }
  60. let code = req.query.code;
  61. let access_token;
  62. let body;
  63. let address;
  64. const state = req.query.state;
  65. async.waterfall([
  66. (next) => {
  67. oauth2.getOAuthAccessToken(code, {redirect_uri}, next);
  68. },
  69. (_access_token, refresh_token, results, next) => {
  70. access_token = _access_token;
  71. request.get({
  72. url: `https://api.github.com/user?access_token=${access_token}`,
  73. headers: {'User-Agent': 'request'}
  74. }, next);
  75. },
  76. (httpResponse, _body, next) => {
  77. body = _body = JSON.parse(_body);
  78. if (state) {
  79. return async.waterfall([
  80. (next) => {
  81. cache.hget('sessions', state, next);
  82. },
  83. (session, next) => {
  84. if (!session) return next('Invalid session.');
  85. db.models.user.findOne({_id: session.userId}, next);
  86. },
  87. (user, next) => {
  88. if (!user) return next('User not found.');
  89. if (user.services.github && user.services.github.id) return next('Account already has GitHub linked.');
  90. db.models.user.updateOne({_id: user._id}, {$set: {"services.github": {id: body.id, access_token}}}, {runValidators: true}, (err) => {
  91. if (err) return next(err);
  92. next(null, user, body);
  93. });
  94. },
  95. (user) => {
  96. cache.pub('user.linkGitHub', user._id);
  97. res.redirect(`${config.get('domain')}/settings`);
  98. }
  99. ], next);
  100. }
  101. db.models.user.findOne({'services.github.id': body.id}, (err, user) => {
  102. next(err, user, body);
  103. });
  104. },
  105. (user, body, next) => {
  106. if (user) {
  107. user.services.github.access_token = access_token;
  108. return user.save(() => {
  109. next(true, user._id);
  110. });
  111. }
  112. db.models.user.findOne({ username: new RegExp(`^${body.login}$`, 'i' )}, (err, user) => {
  113. next(err, user);
  114. });
  115. },
  116. (user, next) => {
  117. if (user) return next('An account with that username already exists.');
  118. request.get({
  119. url: `https://api.github.com/user/emails?access_token=${access_token}`,
  120. headers: {'User-Agent': 'request'}
  121. }, next);
  122. },
  123. (httpResponse, body2, next) => {
  124. body2 = JSON.parse(body2);
  125. if (!Array.isArray(body2)) return next(body2.message);
  126. body2.forEach(email => {
  127. if (email.primary) address = email.email.toLowerCase();
  128. });
  129. db.models.user.findOne({'email.address': address}, next);
  130. },
  131. (user, next) => {
  132. const verificationToken = this.utils.generateRandomString(64);
  133. if (user) return next('An account with that email address already exists.');
  134. db.models.user.create({
  135. _id: this.utils.generateRandomString(12),//TODO Check if exists
  136. username: body.login,
  137. email: {
  138. address,
  139. verificationToken: verificationToken
  140. },
  141. services: {
  142. github: {id: body.id, access_token}
  143. }
  144. }, next);
  145. },
  146. (user, next) => {
  147. mail.schemas.verifyEmail(address, body.login, user.email.verificationToken);
  148. next(null, user._id);
  149. }
  150. ], async (err, userId) => {
  151. if (err && err !== true) {
  152. err = await this.utils.getError(err);
  153. logger.error('AUTH_GITHUB_AUTHORIZE_CALLBACK', `Failed to authorize with GitHub. "${err}"`);
  154. return redirectOnErr(res, err);
  155. }
  156. const sessionId = await this.utils.guid();
  157. cache.hset('sessions', sessionId, cache.schemas.session(sessionId, userId), err => {
  158. if (err) return redirectOnErr(res, err.message);
  159. let date = new Date();
  160. date.setTime(new Date().getTime() + (2 * 365 * 24 * 60 * 60 * 1000));
  161. res.cookie('SID', sessionId, {
  162. expires: date,
  163. secure: config.get("cookie.secure"),
  164. path: "/",
  165. domain: config.get("cookie.domain")
  166. });
  167. logger.success('AUTH_GITHUB_AUTHORIZE_CALLBACK', `User "${userId}" successfully authorized with GitHub.`);
  168. res.redirect(`${config.get('domain')}/`);
  169. });
  170. });
  171. });
  172. app.get('/auth/verify_email', async (req, res) => {
  173. try { await this._validateHook(); } catch { return; }
  174. let code = req.query.code;
  175. async.waterfall([
  176. (next) => {
  177. if (!code) return next('Invalid code.');
  178. next();
  179. },
  180. (next) => {
  181. db.models.user.findOne({"email.verificationToken": code}, next);
  182. },
  183. (user, next) => {
  184. if (!user) return next('User not found.');
  185. if (user.email.verified) return next('This email is already verified.');
  186. db.models.user.updateOne({"email.verificationToken": code}, {$set: {"email.verified": true}, $unset: {"email.verificationToken": ''}}, {runValidators: true}, next);
  187. }
  188. ], (err) => {
  189. if (err) {
  190. let error = 'An error occurred.';
  191. if (typeof err === "string") error = err;
  192. else if (err.message) error = err.message;
  193. logger.error("VERIFY_EMAIL", `Verifying email failed. "${error}"`);
  194. return res.json({ status: 'failure', message: error});
  195. }
  196. logger.success("VERIFY_EMAIL", `Successfully verified email.`);
  197. res.redirect(`${config.get("domain")}?msg=Thank you for verifying your email`);
  198. });
  199. });
  200. resolve();
  201. });
  202. }
  203. }