123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224 |
- 'use strict'
- var express = require('express')
- var router = express.Router()
- const Promise = require('bluebird')
- const validator = require('validator')
- const _ = require('lodash')
- /**
- * Admin
- */
- router.get('/', (req, res) => {
- res.redirect('/admin/profile')
- })
- router.get('/profile', (req, res) => {
- if (res.locals.isGuest) {
- return res.render('error-forbidden')
- }
- res.render('pages/admin/profile', { adminTab: 'profile' })
- })
- router.post('/profile', (req, res) => {
- if (res.locals.isGuest) {
- return res.render('error-forbidden')
- }
- return db.User.findById(req.user.id).then((usr) => {
- usr.name = _.trim(req.body.name)
- if (usr.provider === 'local' && req.body.password !== '********') {
- let nPwd = _.trim(req.body.password)
- if (nPwd.length < 6) {
- return Promise.reject(new Error('New Password too short!'))
- } else {
- return db.User.hashPassword(nPwd).then((pwd) => {
- usr.password = pwd
- return usr.save()
- })
- }
- } else {
- return usr.save()
- }
- }).then(() => {
- return res.json({ msg: 'OK' })
- }).catch((err) => {
- res.status(400).json({ msg: err.message })
- })
- })
- router.get('/stats', (req, res) => {
- if (res.locals.isGuest) {
- return res.render('error-forbidden')
- }
- Promise.all([
- db.Entry.count(),
- db.UplFile.count(),
- db.User.count()
- ]).spread((totalEntries, totalUploads, totalUsers) => {
- return res.render('pages/admin/stats', {
- totalEntries, totalUploads, totalUsers, adminTab: 'stats'
- }) || true
- }).catch((err) => {
- throw err
- })
- })
- router.get('/users', (req, res) => {
- if (!res.locals.rights.manage) {
- return res.render('error-forbidden')
- }
- db.User.find({})
- .select('-password -rights')
- .sort('name email')
- .exec().then((usrs) => {
- res.render('pages/admin/users', { adminTab: 'users', usrs })
- })
- })
- router.get('/users/:id', (req, res) => {
- if (!res.locals.rights.manage) {
- return res.render('error-forbidden')
- }
- if (!validator.isMongoId(req.params.id)) {
- return res.render('error-forbidden')
- }
- db.User.findById(req.params.id)
- .select('-password -providerId')
- .exec().then((usr) => {
- let usrOpts = {
- canChangeEmail: (usr.email !== 'guest' && usr.provider === 'local' && usr.email !== req.app.locals.appconfig.admin),
- canChangeName: (usr.email !== 'guest'),
- canChangePassword: (usr.email !== 'guest' && usr.provider === 'local'),
- canChangeRole: (usr.email !== 'guest' && !(usr.provider === 'local' && usr.email === req.app.locals.appconfig.admin)),
- canBeDeleted: (usr.email !== 'guest' && !(usr.provider === 'local' && usr.email === req.app.locals.appconfig.admin))
- }
- res.render('pages/admin/users-edit', { adminTab: 'users', usr, usrOpts })
- })
- })
- /**
- * Create / Authorize a new user
- */
- router.post('/users/create', (req, res) => {
- if (!res.locals.rights.manage) {
- return res.status(401).json({ msg: 'Unauthorized' })
- }
- let nUsr = {
- email: _.trim(req.body.email),
- provider: _.trim(req.body.provider),
- password: req.body.password,
- name: _.trim(req.body.name)
- }
- if (!validator.isEmail(nUsr.email)) {
- return res.status(400).json({ msg: 'Invalid email address' })
- } else if (!validator.isIn(nUsr.provider, ['local', 'google', 'windowslive', 'facebook'])) {
- return res.status(400).json({ msg: 'Invalid provider' })
- } else if (nUsr.provider === 'local' && !validator.isLength(nUsr.password, { min: 6 })) {
- return res.status(400).json({ msg: 'Password too short or missing' })
- } else if (nUsr.provider === 'local' && !validator.isLength(nUsr.name, { min: 2 })) {
- return res.status(400).json({ msg: 'Name is missing' })
- }
- db.User.findOne({ email: nUsr.email, provider: nUsr.provider }).then(exUsr => {
- if (exUsr) {
- return res.status(400).json({ msg: 'User already exists!' }) || true
- }
- let pwdGen = (nUsr.provider === 'local') ? db.User.hashPassword(nUsr.password) : Promise.resolve(true)
- return pwdGen.then(nPwd => {
- if (nUsr.provider !== 'local') {
- nUsr.password = ''
- nUsr.name = '-- pending --'
- } else {
- nUsr.password = nPwd
- }
- nUsr.rights = [{
- role: 'read',
- path: '/',
- exact: false,
- deny: false
- }]
- return db.User.create(nUsr).then(() => {
- return res.json({ ok: true })
- })
- }).catch(err => {
- winston.warn(err)
- return res.status(500).json({ msg: err })
- })
- }).catch(err => {
- winston.warn(err)
- return res.status(500).json({ msg: err })
- })
- })
- router.post('/users/:id', (req, res) => {
- if (!res.locals.rights.manage) {
- return res.status(401).json({ msg: 'Unauthorized' })
- }
- if (!validator.isMongoId(req.params.id)) {
- return res.status(400).json({ msg: 'Invalid User ID' })
- }
- return db.User.findById(req.params.id).then((usr) => {
- usr.name = _.trim(req.body.name)
- usr.rights = JSON.parse(req.body.rights)
- if (usr.provider === 'local' && req.body.password !== '********') {
- let nPwd = _.trim(req.body.password)
- if (nPwd.length < 6) {
- return Promise.reject(new Error('New Password too short!'))
- } else {
- return db.User.hashPassword(nPwd).then((pwd) => {
- usr.password = pwd
- return usr.save()
- })
- }
- } else {
- return usr.save()
- }
- }).then(() => {
- return res.json({ msg: 'OK' })
- }).catch((err) => {
- res.status(400).json({ msg: err.message })
- })
- })
- /**
- * Delete / Deauthorize a user
- */
- router.delete('/users/:id', (req, res) => {
- if (!res.locals.rights.manage) {
- return res.status(401).json({ msg: 'Unauthorized' })
- }
- if (!validator.isMongoId(req.params.id)) {
- return res.status(400).json({ msg: 'Invalid User ID' })
- }
- return db.User.findByIdAndRemove(req.params.id).then(() => {
- return res.json({ msg: 'OK' })
- }).catch((err) => {
- res.status(500).json({ msg: err.message })
- })
- })
- router.get('/settings', (req, res) => {
- if (!res.locals.rights.manage) {
- return res.render('error-forbidden')
- }
- res.render('pages/admin/settings', { adminTab: 'settings' })
- })
- module.exports = router
|