forked from NodeBB/nodebb-plugin-write-api
-
Notifications
You must be signed in to change notification settings - Fork 0
/
middleware.js
75 lines (64 loc) · 1.95 KB
/
middleware.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
'use strict';
/* globals module, require */
var passport = require.main.require('passport'),
user = require.main.require('./src/user'),
errorHandler = require('./lib/errorHandler'),
Middleware = {};
Middleware.requireUser = function(req, res, next) {
passport.authenticate('bearer', { session: false }, function(err, user) {
if (err) { return next(err); }
if (!user) { return errorHandler.respond(401, res); }
// If the token received was a master token, a _uid must also be present for all calls
if (user.hasOwnProperty('uid')) {
req.login(user, function(err) {
if (err) { return errorHandler.respond(500, res); }
next();
});
} else if (user.hasOwnProperty('master') && user.master === true) {
if (req.body.hasOwnProperty('_uid')) {
user.uid = req.body._uid;
delete user.master;
req.login(user, function(err) {
if (err) { return errorHandler.respond(500, res); }
next();
});
} else {
res.status(400).json(errorHandler.generate(
400, 'params-missing',
'Required parameters were missing from this API call, please see the "params" property',
['_uid']
));
}
} else {
return errorHandler.respond(500, res);
}
})(req, res, next);
};
Middleware.requireAdmin = function(req, res, next) {
if (!req.user) {
return errorHandler.respond(401, res);
}
user.isAdministrator(req.user.uid, function(err, isAdmin) {
if (err || !isAdmin) {
return errorHandler.respond(401, res);
}
next();
});
};
Middleware.exposeUid = function(req, res, next) {
if (req.params.hasOwnProperty('userslug')) {
user.getUidByUserslug(req.params.userslug, function(err, uid) {
if (err) {
return errorHandler.respond(500, res);
} else if (uid === null) {
// If exposed uid is null, then that *specifically* means that the passed in userslug is garbage
return errorHandler.respond(404, res);
}
res.locals.uid = uid;
next();
})
} else {
next();
}
};
module.exports = Middleware;