-
Notifications
You must be signed in to change notification settings - Fork 0
/
app.js
146 lines (123 loc) · 3.83 KB
/
app.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
const createError = require("http-errors");
const express = require("express");
const path = require("path");
const cookieParser = require("cookie-parser");
const logger = require("morgan");
const mongoose = require("mongoose");
require("dotenv").config();
const app = express();
const debug = require("debug")("app");
const compression = require('compression')
const helmet = require('helmet')
const cors = require('cors')
app.use(express.static('uploads'));
//allowing access from anaywhere
app.options('*', cors())
app.use(cors())
//connecting to database
mongoose.set("strictQuery", false);
const mongoDB = process.env.DATABASE_URI;
main().catch((err) => console.log(err));
async function main() {
await mongoose.connect(mongoDB);
}
//
//setting up protection
app.use(helmet.contentSecurityPolicy({
directives:{
"script-src":["'self'","'unsafe-inline'"],
scriptSrcAttr: ["'self'", "'unsafe-inline'"],
"img-src":["'self'","cdn.shopify.com"]
}
}))
//setting up requests rate limit
const RateLimit = require('express-rate-limit')
const limiter = RateLimit({
windowMs:1 * 60 * 1000,// 1MINUTE
max:50
})
app.use(limiter)
// view engine setup
app.set("views", path.join(__dirname, "views"));
app.set("view engine", "ejs");
//initializing session
const passport = require('passport')
const session = require('express-session')
app.use(session({secret:"cats", resave:false, saveUninitialized:true}))
app.use(passport.initialize())
app.use(passport.session())
app.use(express.urlencoded({ extended: true }));
//optimizing response sent to the user
app.use(compression())
app.use(logger("dev"));
app.use(express.json());
app.use(cookieParser());
app.use(express.static(path.join(__dirname, "public")));
//setting up authentication
const LocalStrategy = require('passport-local')
const userModel = require('./models/user')
passport.serializeUser(function(user,done){
done(null,user.id)
})
passport.deserializeUser(async function(id,done){
try{
const user = await userModel.findById(id)
done(null,user)
}catch(err){
done(err)
}
})
passport.use(new LocalStrategy(async(username, password, done)=>{
try{
const bcrypt = require('bcryptjs')
console.log('user',username)
const user = await userModel.findOne({username:username})
if(!user){
console.log('wrong username')
return done(null, false,{ msg:'user does not exist. please check your username and try again.'})
}
const match =await bcrypt.compare(password,user.password)
if(!match){
console.log('wrong password')
return done(null, false,{ msg:'wrong password. please try again.'})
}
console.log('found')
return done(null,user)
}catch(err){
return done(err)
}
}))
//Routing
const indexRouter = require("./routes/index");
const collectionRouter = require("./routes/collection");
const itemRouter = require("./routes/item");
const signUpRouter = require("./routes/sign-up")
const logInRouter = require('./routes/log-in')
app.use("/",express.static(path.join(__dirname, "uploads")),indexRouter);
app.use("/collection", express.static(path.join(__dirname, "uploads")),collectionRouter);
app.use("/item",express.static(path.join(__dirname, "uploads")),itemRouter);
app.use("/sign-up",signUpRouter)
app.use("/log-in",logInRouter)
app.use("/log-out",async(req,res,next)=>{
req.logout(function(err){
if(err){
return next(err)
}
res.redirect('/')
})
})
// catch 404 and forward to error handler
app.use(function (req, res, next) {
next(createError(404));
})
// error handler
app.use(function (err, req, res, next) {
// set locals, only providing error in development
res.locals.message = err.message;
res.locals.error = req.app.get("env") === "development" ? err : {};
console.log(err)
// render the error page
res.status(err.status || 500);
res.send({error:err});
});
module.exports = app;