app.js 7.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258
  1. 'use strict';
  2. const express = require('express');
  3. const bodyParser = require('body-parser');
  4. const cookieParser = require('cookie-parser');
  5. const cors = require('cors');
  6. const config = require('config');
  7. const async = require('async');
  8. const logger = require('./logger');
  9. const mail = require('./mail');
  10. const request = require('request');
  11. const OAuth2 = require('oauth').OAuth2;
  12. const api = require('./api');
  13. const cache = require('./cache');
  14. const db = require('./db');
  15. let utils;
  16. let initialized = false;
  17. let lockdown = false;
  18. const lib = {
  19. app: null,
  20. server: null,
  21. init: (cb) => {
  22. utils = require('./utils');
  23. let app = lib.app = express();
  24. lib.server = app.listen(config.get('serverPort'));
  25. app.use(cookieParser());
  26. app.use(bodyParser.json());
  27. app.use(bodyParser.urlencoded({ extended: true }));
  28. let corsOptions = Object.assign({}, config.get('cors'));
  29. app.use(cors(corsOptions));
  30. app.options('*', cors(corsOptions));
  31. let oauth2 = new OAuth2(
  32. config.get('apis.github.client'),
  33. config.get('apis.github.secret'),
  34. 'https://github.com/',
  35. 'login/oauth/authorize',
  36. 'login/oauth/access_token',
  37. null
  38. );
  39. let redirect_uri = config.get('serverDomain') + '/auth/github/authorize/callback';
  40. app.get('/auth/github/authorize', (req, res) => {
  41. if (lockdown) return res.json({status: 'failure', message: 'Lockdown'});
  42. let params = [
  43. `client_id=${config.get('apis.github.client')}`,
  44. `redirect_uri=${config.get('serverDomain')}/auth/github/authorize/callback`,
  45. `scope=user:email`
  46. ].join('&');
  47. res.redirect(`https://github.com/login/oauth/authorize?${params}`);
  48. });
  49. app.get('/auth/github/link', (req, res) => {
  50. if (lockdown) return res.json({status: 'failure', message: 'Lockdown'});
  51. let params = [
  52. `client_id=${config.get('apis.github.client')}`,
  53. `redirect_uri=${config.get('serverDomain')}/auth/github/authorize/callback`,
  54. `scope=user:email`,
  55. `state=${req.cookies[config.cookie.sidName]}`
  56. ].join('&');
  57. res.redirect(`https://github.com/login/oauth/authorize?${params}`);
  58. });
  59. function redirectOnErr (res, err){
  60. return res.redirect(`${config.get('domain')}/?err=${encodeURIComponent(err)}`);
  61. }
  62. app.get('/auth/github/authorize/callback', (req, res) => {
  63. if (lockdown) return res.json({status: 'failure', message: 'Lockdown'});
  64. let code = req.query.code;
  65. let access_token;
  66. let body;
  67. let address;
  68. const state = req.query.state;
  69. async.waterfall([
  70. (next) => {
  71. oauth2.getOAuthAccessToken(code, {redirect_uri}, next);
  72. },
  73. (_access_token, refresh_token, results, next) => {
  74. access_token = _access_token;
  75. request.get({
  76. url: `https://api.github.com/user?access_token=${access_token}`,
  77. headers: {'User-Agent': 'request'}
  78. }, next);
  79. },
  80. (httpResponse, _body, next) => {
  81. body = _body = JSON.parse(_body);
  82. if (state) {
  83. return async.waterfall([
  84. (next) => {
  85. cache.hget('sessions', state, next);
  86. },
  87. (session, next) => {
  88. if (!session) return next('Invalid session.');
  89. db.models.user.findOne({_id: session.userId}, next);
  90. },
  91. (linkingUser, next) => {
  92. if (!linkingUser) return next('User not found.');
  93. if (linkingUser.services.github && linkingUser.services.github.id) return next('Account already has GitHub linked.');
  94. db.models.user.findOne({"services.github.id": body.id}, (err, user) => {
  95. next(err, user, linkingUser);
  96. });
  97. },
  98. (user, linkingUser, next) => {
  99. if (user) return next('There is already an account that uses that GitHub account to log in.');
  100. db.models.user.update({_id: linkingUser._id}, {$set: {"services.github": {id: body.id, access_token}}}, {runValidators: true}, (err) => {
  101. if (err) return next(err);
  102. next(null, linkingUser, body);
  103. });
  104. },
  105. (user) => {
  106. cache.pub('user.linkGitHub', user._id);
  107. res.redirect(`${config.get('domain')}/settings`);
  108. }
  109. ], next);
  110. }
  111. db.models.user.findOne({'services.github.id': body.id}, (err, user) => {
  112. next(err, user, body);
  113. });
  114. },
  115. (user, body, next) => {
  116. if (user) {
  117. user.services.github.access_token = access_token;
  118. return user.save(() => {
  119. next(true, user._id);
  120. });
  121. }
  122. db.models.user.findOne({ username: new RegExp(`^${body.login}$`, 'i' )}, (err, user) => {
  123. next(err, user);
  124. });
  125. },
  126. (user, next) => {
  127. if (user) return next('An account with that username already exists.');
  128. request.get({
  129. url: `https://api.github.com/user/emails?access_token=${access_token}`,
  130. headers: {'User-Agent': 'request'}
  131. }, next);
  132. },
  133. (httpResponse, body2, next) => {
  134. body2 = JSON.parse(body2);
  135. if (!Array.isArray(body2)) return next(body2.message);
  136. body2.forEach(email => {
  137. if (email.primary) address = email.email.toLowerCase();
  138. });
  139. db.models.user.findOne({'email.address': address}, next);
  140. },
  141. (user, next) => {
  142. const verificationToken = utils.generateRandomString(64);
  143. if (user) return next('An account with that email address already exists.');
  144. db.models.user.create({
  145. _id: utils.generateRandomString(12),//TODO Check if exists
  146. username: body.login,
  147. email: {
  148. address,
  149. verificationToken: verificationToken
  150. },
  151. services: {
  152. github: {id: body.id, access_token}
  153. }
  154. }, next);
  155. },
  156. (user, next) => {
  157. mail.schemas.verifyEmail(address, body.login, user.email.verificationToken);
  158. next(null, user._id);
  159. }
  160. ], (err, userId) => {
  161. if (err && err !== true) {
  162. err = utils.getError(err);
  163. logger.error('AUTH_GITHUB_AUTHORIZE_CALLBACK', `Failed to authorize with GitHub. "${err}"`);
  164. return redirectOnErr(res, err);
  165. }
  166. const sessionId = utils.guid();
  167. cache.hset('sessions', sessionId, cache.schemas.session(sessionId, userId), err => {
  168. if (err) return redirectOnErr(res, err.message);
  169. let date = new Date();
  170. date.setTime(new Date().getTime() + (2 * 365 * 24 * 60 * 60 * 1000));
  171. res.cookie(config.cookie.sidName, sessionId, {
  172. expires: date,
  173. secure: config.get("cookie.secure"),
  174. path: "/",
  175. domain: config.get("cookie.domain")
  176. });
  177. logger.success('AUTH_GITHUB_AUTHORIZE_CALLBACK', `User "${userId}" successfully authorized with GitHub.`);
  178. res.redirect(`${config.get('domain')}/`);
  179. });
  180. });
  181. });
  182. app.get('/auth/verify_email', (req, res) => {
  183. let code = req.query.code;
  184. async.waterfall([
  185. (next) => {
  186. if (!code) return next('Invalid code.');
  187. next();
  188. },
  189. (next) => {
  190. db.models.user.findOne({"email.verificationToken": code}, next);
  191. },
  192. (user, next) => {
  193. if (!user) return next('User not found.');
  194. if (user.email.verified) return next('This email is already verified.');
  195. db.models.user.update({"email.verificationToken": code}, {$set: {"email.verified": true}, $unset: {"email.verificationToken": ''}}, {runValidators: true}, next);
  196. }
  197. ], (err) => {
  198. if (err) {
  199. let error = 'An error occurred.';
  200. if (typeof err === "string") error = err;
  201. else if (err.message) error = err.message;
  202. logger.error("VERIFY_EMAIL", `Verifying email failed. "${error}"`);
  203. return res.json({ status: 'failure', message: error});
  204. }
  205. logger.success("VERIFY_EMAIL", `Successfully verified email.`);
  206. res.redirect(config.get("domain"));
  207. });
  208. });
  209. initialized = true;
  210. if (lockdown) return this._lockdown();
  211. cb();
  212. },
  213. _lockdown: () => {
  214. lib.server.close();
  215. lockdown = true;
  216. }
  217. };
  218. module.exports = lib;