app.js 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143
  1. 'use strict';
  2. const express = require('express');
  3. const bodyParser = require('body-parser');
  4. const cors = require('cors');
  5. const config = require('config');
  6. const request = require('request');
  7. const OAuth2 = require('oauth').OAuth2;
  8. const api = require('./api');
  9. const cache = require('./cache');
  10. const db = require('./db');
  11. let utils;
  12. const lib = {
  13. app: null,
  14. server: null,
  15. init: (cb) => {
  16. utils = require('./utils');
  17. let app = lib.app = express();
  18. lib.server = app.listen(8080);
  19. app.use(bodyParser.json());
  20. app.use(bodyParser.urlencoded({ extended: true }));
  21. let corsOptions = Object.assign({}, config.get('cors'));
  22. app.use(cors(corsOptions));
  23. app.options('*', cors(corsOptions));
  24. api(app);
  25. let oauth2 = new OAuth2(
  26. config.get('apis.github.client'),
  27. config.get('apis.github.secret'),
  28. 'https://github.com/',
  29. 'login/oauth/authorize',
  30. 'login/oauth/access_token',
  31. null
  32. );
  33. let redirect_uri = config.get('serverDomain') + '/auth/github/authorize/callback';
  34. app.get('/auth/github/authorize', (req, res) => {
  35. let params = [
  36. `client_id=${config.get('apis.github.client')}`,
  37. `redirect_uri=${config.get('serverDomain')}/auth/github/authorize/callback`,
  38. `scope=user:email`
  39. ].join('&');
  40. res.redirect(`https://github.com/login/oauth/authorize?${params}`);
  41. });
  42. function redirectOnErr (res, err){
  43. return res.redirect(`${config.get('domain')}/?err=${encodeURIComponent(err)}`);
  44. }
  45. app.get('/auth/github/authorize/callback', (req, res) => {
  46. let code = req.query.code;
  47. oauth2.getOAuthAccessToken(code, { redirect_uri }, (err, access_token, refresh_token, results) => {
  48. if (!err) request.get({
  49. url: `https://api.github.com/user?access_token=${access_token}`,
  50. headers: { 'User-Agent': 'request' }
  51. }, (err, httpResponse, body) => {
  52. if (err) return redirectOnErr(res, err.message);
  53. body = JSON.parse(body);
  54. db.models.user.findOne({'services.github.id': body.id}, (err, user) => {
  55. if (err) return redirectOnErr(res, 'err');
  56. if (user) {
  57. user.services.github.access_token = access_token;
  58. user.save(err => {
  59. if (err) return redirectOnErr(res, err.message);
  60. let sessionId = utils.guid();
  61. cache.hset('sessions', sessionId, cache.schemas.session(sessionId, user._id), err => {
  62. if (err) return redirectOnErr(res, err.message);
  63. let date = new Date();
  64. date.setTime(new Date().getTime() + (2 * 365 * 24 * 60 * 60 * 1000));
  65. res.cookie('SID', sessionId, {expires: date, secure: config.get("cookie.secure"), path: "/", domain: config.get("cookie.domain")});
  66. res.redirect(`${config.get('domain')}/`);
  67. });
  68. });
  69. } else {
  70. db.models.user.findOne({ username: new RegExp(`^${body.login}$`, 'i') }, (err, user) => {
  71. if (err) return redirectOnErr(res, err.message);
  72. if (user) return redirectOnErr(res, 'An account with that username already exists.');
  73. else request.get({
  74. url: `https://api.github.com/user/emails?access_token=${access_token}`,
  75. headers: {'User-Agent': 'request'}
  76. }, (err, httpResponse, body2) => {
  77. if (err) return redirectOnErr(res, err.message);
  78. body2 = JSON.parse(body2);
  79. let address;
  80. if (!Array.isArray(body2)) return redirectOnErr(res, body2.message);
  81. body2.forEach(email => {
  82. if (email.primary) address = email.email.toLowerCase();
  83. });
  84. db.models.user.findOne({'email.address': address}, (err, user) => {
  85. if (err) return redirectOnErr(res, err.message);
  86. if (user) return redirectOnErr(res, 'An account with that email address already exists.');
  87. else db.models.user.create({
  88. _id: utils.generateRandomString(12),//TODO Check if exists
  89. username: body.login,
  90. email: {
  91. address,
  92. verificationToken: utils.generateRandomString(64)
  93. },
  94. services: {
  95. github: {id: body.id, access_token}
  96. }
  97. }, (err, user) => {
  98. if (err) return redirectOnErr(res, err.message);
  99. //TODO Send verification email
  100. let sessionId = utils.guid();
  101. cache.hset('sessions', sessionId, cache.schemas.session(sessionId, user._id), err => {
  102. if (err) return redirectOnErr(res, err.message);
  103. let date = new Date();
  104. date.setTime(new Date().getTime() + (2 * 365 * 24 * 60 * 60 * 1000));
  105. res.cookie('SID', sessionId, {expires: date, secure: config.get("cookie.secure"), path: "/", domain: config.get("cookie.domain")});
  106. res.redirect(`${config.get('domain')}/`);
  107. });
  108. });
  109. });
  110. });
  111. });
  112. }
  113. });
  114. });
  115. else return redirectOnErr(res, 'err');
  116. });
  117. });
  118. cb();
  119. }
  120. };
  121. module.exports = lib;