-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsessions.js
More file actions
150 lines (130 loc) · 3.73 KB
/
sessions.js
File metadata and controls
150 lines (130 loc) · 3.73 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
const express = require('express');
const helmet = require('helmet');
const cors = require('cors');
const bcrypt = require('bcryptjs');
const session = require('express-session'); // 1. added this
const KnexSessionStore = require('connect-session-knex')(session);
const db = require('./database/dbConfig.js');
const Users = require('./users/users-model.js');
const server = express();
// 3 added this
const sessionConfig = {
name: 'monkey',
secret: 'keep it secret, keep it safe!',
cookie: {
maxAge: 1000 * 60 * 60, // in ms
secure: false, // used over https only
},
httpOnly: true, // cannot access the cookie from js using document.cookie
resave: false,
saveUninitialized: false, // GDPR laws against setting cookies automatically
store: new KnexSessionStore({
knex: db,
tablename: 'sessions',
sidfieldname: 'sid',
createtable: true,
clearInterval: 1000 * 60 * 60, // in ms
}),
};
server.use(helmet());
server.use(express.json());
server.use(cors());
server.use(session(sessionConfig)); // 2. added this
server.get('/', (req, res) => {
res.send("It's alive!");
});
server.post('/api/register', (req, res) => {
let user = req.body;
// generate hash from user's password
const hash = bcrypt.hashSync(user.password, 10); // 2 ^ n
// override user.password with hash
user.password = hash;
Users.add(user)
.then(saved => {
req.session.user = saved;
res.status(201).json(saved);
})
.catch(error => {
res.status(500).json(error);
});
});
server.post('/api/login', (req, res) => {
let { username, password } = req.body;
Users.findBy({ username })
.first()
.then(user => {
// check that passwords match
if (user && bcrypt.compareSync(password, user.password)) {
req.session.user = user; // 4. this
res
.status(200)
.json({ message: `Welcome ${user.username}!, have a cookie...` });
} else {
res.status(401).json({ message: 'Invalid Credentials' });
}
})
.catch(error => {
res.status(500).json(error);
});
});
// 5. simplified this a lot
function restricted(req, res, next) {
if (req.session && req.session.user) {
next();
} else {
res.status(401).json({ message: 'You shall not pass!' });
}
}
// function restricted(req, res, next) {
// const { username, password } = req.headers;
// if (username && password) {
// Users.findBy({ username })
// .first()
// .then(user => {
// if (user && bcrypt.compareSync(password, user.password)) {
// next();
// } else {
// res.status(401).json({ message: 'Invalid Credentials' });
// }
// })
// .catch(error => {
// res.status(500).json({ message: 'Ran into an unexpected error' });
// });
// } else {
// res.status(400).json({ message: 'No credentials provided' });
// }
// }
// axios.get(url, { headers: { username, password } });
// protect this route, only authenticated users should see it
server.get('/api/users', restricted, (req, res) => {
Users.find()
.then(users => {
res.json(users);
})
.catch(err => res.send(err));
});
server.get('/users', restricted, async (req, res) => {
try {
const users = await Users.find();
res.json(users);
} catch (error) {
res.send(error);
}
});
server.get('/api/logout', (req, res) => {
if (req.session) {
req.session.destroy(err => {
if (err) {
res.send(
'you can checkout any time you like, but you can never leave....'
);
} else {
res.send('bye, thanks for playing');
}
});
} else {
res.end();
}
});
const port = process.env.PORT || 5000;
server.listen(port, () => console.log(`\n** Running on port ${port} **\n`));