This repository has been archived on 2022-11-26. You can view files and clone it, but cannot push or open issues or pull requests.
IcyNet.eu/server/routes/oauth2.js

73 lines
1.6 KiB
JavaScript
Raw Normal View History

2017-08-23 20:13:45 +00:00
import express from 'express'
import UAPI from '../api'
2017-08-23 20:13:45 +00:00
import OAuth2 from '../api/oauth2'
2017-08-23 22:25:52 +00:00
import RateLimit from 'express-rate-limit'
2017-08-23 20:13:45 +00:00
import wrap from '../../scripts/asyncRoute'
let router = express.Router()
let oauth = new OAuth2()
router.use(oauth.express())
2017-08-23 22:25:52 +00:00
let oauthLimiter = new RateLimit({
windowMs: 5 * 60 * 1000, // 5 minutes
2017-08-27 11:48:47 +00:00
max: 10,
2017-08-23 22:25:52 +00:00
delayMs: 0
})
router.use(oauthLimiter)
2017-08-23 20:13:45 +00:00
function ensureLoggedIn (req, res, next) {
2017-08-25 11:37:34 +00:00
if (req.session.user) return next()
req.session.redirectUri = req.originalUrl
res.redirect('/login')
2017-08-23 20:13:45 +00:00
}
2017-08-27 11:48:47 +00:00
// Generic OAuth2 endpoints
2017-08-23 20:13:45 +00:00
router.use('/authorize', ensureLoggedIn, oauth.controller.authorization)
router.post('/token', oauth.controller.token)
router.post('/introspect', oauth.controller.introspection)
2017-08-27 11:48:47 +00:00
// Protected user information resource
2017-08-23 20:13:45 +00:00
router.get('/user', oauth.bearer, wrap(async (req, res) => {
let accessToken = req.oauth2.accessToken
let user = await UAPI.User.get(accessToken.user_id)
2017-08-24 10:52:12 +00:00
2017-08-23 20:13:45 +00:00
if (!user) {
return res.status(404).jsonp({
error: 'No such user'
})
}
let udata = {
id: user.id,
uuid: user.uuid,
2017-08-24 10:52:12 +00:00
username: user.username,
display_name: user.display_name,
2017-08-23 20:13:45 +00:00
avatar_file: user.avatar_file
}
2017-08-24 10:52:12 +00:00
// Include Email
if (accessToken.scope.indexOf('email') !== -1) {
2017-08-23 20:13:45 +00:00
udata.email = user.email
}
2017-08-24 10:52:12 +00:00
// Include privilege number
if (accessToken.scope.indexOf('privilege') !== -1) {
2017-08-23 20:13:45 +00:00
udata.privilege = user.nw_privilege
}
res.jsonp(udata)
}))
router.use((err, req, res, next) => {
if (err && err instanceof oauth.error) {
return oauth.response.error(req, res, err, req.body.redirectUri)
}
next()
})
module.exports = router