|
1 | | -exports.verifyUser = (req, res, next) => { |
2 | | - |
3 | | - console.log(req.signedCookies); |
4 | | - |
5 | | - if(!req.signedCookies.user) { |
6 | | - var authHeader = req.headers.authorization; |
7 | | - |
8 | | - if(!authHeader) { |
9 | | - var err = new Error('You are not authosrised'); |
10 | | - res.setHeader('WWW-Authenticate', 'Basic'); |
11 | | - err.status = 401; |
12 | | - return next(err); |
13 | | - } |
14 | | - |
15 | | - var auth = new Buffer.from(authHeader.split(' ')[1], 'base64').toString().split(":"); |
16 | | - var username = auth[0]; |
17 | | - var password = auth[1]; |
18 | | - |
19 | | - if (username === 'admin' && password === 'password') { |
20 | | - res.cookie('user', 'admin', {signed: true}) |
21 | | - next(); |
22 | | - } |
23 | | - else { |
24 | | - var err = new Error('password is incorrect'); |
25 | | - res.setHeader('WWW-Authenticate', 'Basic'); |
26 | | - err.status = 401; |
27 | | - return next(err); |
28 | | - } |
29 | | - } |
| 1 | +const passport = require("passport"); |
| 2 | +const LocalStrategy = require("passport-local").Strategy; |
| 3 | +const JwtStrategy = require("passport-jwt").Strategy; |
| 4 | +const ExtractJwt = require("passport-jwt").ExtractJwt; |
| 5 | +const jwt = require("jsonwebtoken"); |
| 6 | + |
| 7 | +const User = require("./models/Users"); |
| 8 | + |
| 9 | +const { comparePassword } = require("./Utils/utils"); |
| 10 | + |
| 11 | +passport.use( |
| 12 | + new LocalStrategy(function (username, password, done) { |
| 13 | + User.findOne( |
| 14 | + { username: username }, |
| 15 | + "username isAdmin passwordHash passwordSalt", |
| 16 | + async function (err, user) { |
| 17 | + if (err) { |
| 18 | + return done(err); |
| 19 | + } |
| 20 | + |
| 21 | + if (!user) { |
| 22 | + return done(null, false, { message: "Incorrect Username." }); |
| 23 | + } |
| 24 | + const verifyPassword = await comparePassword( |
| 25 | + user.passwordHash, |
| 26 | + user.passwordSalt, |
| 27 | + password |
| 28 | + ); |
| 29 | + if (!verifyPassword) { |
| 30 | + return done(null, false, { message: "Incorrect password." }); |
| 31 | + } |
| 32 | + |
| 33 | + return done(null, user); |
| 34 | + } |
| 35 | + ); |
| 36 | + }) |
| 37 | +); |
| 38 | + |
| 39 | +passport.serializeUser(function (user, done) { |
| 40 | + done(null, user.id); |
| 41 | +}); |
| 42 | + |
| 43 | +passport.deserializeUser(function (id, done) { |
| 44 | + User.findById(id, function (err, user) { |
| 45 | + done(err, user); |
| 46 | + }); |
| 47 | +}); |
| 48 | + |
| 49 | +exports.generateToken = function (user) { |
| 50 | + return jwt.sign(user, process.env.TokenSecret, { expiresIn: 36000 }); |
| 51 | +}; |
| 52 | + |
| 53 | +let opts = {}; |
| 54 | +opts.jwtFromRequest = ExtractJwt.fromAuthHeaderAsBearerToken(); |
| 55 | +opts.secretOrKey = process.env.TokenSecret; |
30 | 56 |
|
31 | | - else { |
32 | | - if(req.signedCookies.user === 'admin') { |
33 | | - next(); |
34 | | - } |
35 | | - else { |
36 | | - var err = new Error('cookie is invalid'); |
| 57 | +passport.use( |
| 58 | + new JwtStrategy(opts, (jwt_payload, done) => { |
| 59 | + User.findOne({ _id: jwt_payload._id }, "username isAdmin", (err, user) => { |
| 60 | + if (err) { |
| 61 | + return done(err, false); |
| 62 | + } else if (user) { |
| 63 | + return done(null, user); |
| 64 | + } else { |
| 65 | + return done(null, false); |
| 66 | + } |
| 67 | + }); |
| 68 | + }) |
| 69 | +); |
37 | 70 |
|
38 | | - err.status = 401; |
39 | | - return next(err); |
40 | | - } |
| 71 | +exports.verifyUser = passport.authenticate("jwt", { session: false }); |
| 72 | +exports.verifyAdmin = (req, res, next) => { |
| 73 | + if (req.user && req.user.isAdmin) { |
| 74 | + return next(); |
| 75 | + } else { |
| 76 | + err = new Error("You are not Authorized to perform this operation"); |
| 77 | + err.status = 403; |
| 78 | + return next(err); |
41 | 79 | } |
42 | | -} |
| 80 | +}; |
0 commit comments