auth.js 1.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748
  1. 'use strict'
  2. /* global appdata, rights */
  3. const moment = require('moment-timezone')
  4. /**
  5. * Authentication middleware
  6. *
  7. * @param {Express Request} req Express Request object
  8. * @param {Express Response} res Express Response object
  9. * @param {Function} next Next callback function
  10. * @return {any} void
  11. */
  12. module.exports = (req, res, next) => {
  13. // Is user authenticated ?
  14. if (!req.isAuthenticated()) {
  15. if (req.app.locals.appconfig.public !== true) {
  16. return res.redirect('/login')
  17. } else {
  18. req.user = rights.guest
  19. res.locals.isGuest = true
  20. }
  21. } else {
  22. res.locals.isGuest = false
  23. }
  24. // Check permissions
  25. res.locals.rights = rights.check(req)
  26. if (!res.locals.rights.read) {
  27. return res.render('error-forbidden')
  28. }
  29. // Set i18n locale
  30. req.i18n.changeLanguage(req.user.lang)
  31. res.locals.userMoment = moment
  32. res.locals.userMoment.locale(req.user.lang)
  33. // Expose user data
  34. res.locals.user = req.user
  35. return next()
  36. }