routes.js 16.4 KB
Newer Older
1
2
3
4
const fs = require('fs')
const SamlStrategy = require('passport-saml').Strategy
const dbconn = require('./dbconn')
const methods = require('./methods')
Rosanny Sihombing's avatar
Rosanny Sihombing committed
5
// pwd encryption
6
7
const bcrypt = require('bcryptjs')
const saltRounds = 10
Rosanny Sihombing's avatar
Rosanny Sihombing committed
8
// forgot pwd
9
10
11
const async = require('async')
const crypto = require('crypto')
const nodemailer = require('nodemailer')
Rosanny Sihombing's avatar
Rosanny Sihombing committed
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42

module.exports = function (app, config, passport) {

  // =========== PASSPORT =======
  passport.serializeUser(function (user, done) {
    done(null, user);
  });

  passport.deserializeUser(function (user, done) {
    done(null, user);
  });

  var samlStrategy = new SamlStrategy({
      // URL that goes from the Identity Provider -> Service Provider
      callbackUrl: config.passport.saml.path,
      // Base address to call logout requests
      logoutUrl: config.passport.saml.logoutUrl,
      
      entryPoint: config.passport.saml.entryPoint,
      issuer: config.passport.saml.issuer,
      identifierFormat: null,
      
      // Service Provider private key
      decryptionPvk: fs.readFileSync(__dirname + '/cert/key.pem', 'utf8'),
      // Service Provider Certificate
      privateCert: fs.readFileSync(__dirname + '/cert/key.pem', 'utf8'),
      // Identity Provider's public key
      cert: fs.readFileSync(__dirname + '/cert/cert_idp.pem', 'utf8'),
      
      validateInResponseTo: false,
      disableRequestedAuthnContext: true
43
44
45
46
47
48
49
50
  },
  function (profile, done) {
    return done(null, {
      id: profile.nameID,
      idFormat: profile.nameIDFormat,
      email: profile.email,
      firstName: profile.givenName,
      lastName: profile.sn
Rosanny Sihombing's avatar
Rosanny Sihombing committed
51
    });
52
  });
Rosanny Sihombing's avatar
Rosanny Sihombing committed
53
54
  
  passport.use(samlStrategy);
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88

  // ============= SAML ==============
  app.post(config.passport.saml.path,
    passport.authenticate(config.passport.strategy,
      {
        failureRedirect: '/',
        failureFlash: true
      }),
    function (req, res) {
      res.redirect('/');
    }
  );

  // to generate Service Provider's XML metadata
  app.get('/saml/metadata', 
    function(req, res) {
      res.type('application/xml');
      var spMetadata = samlStrategy.generateServiceProviderMetadata(fs.readFileSync(__dirname + '/cert/cert.pem', 'utf8'));
      res.status(200).send(spMetadata);
    }
  );

  // ======== NODEMAILER ====================
  var smtpTransport = nodemailer.createTransport({
    host: config.mailer.host,
    secureConnection: config.mailer.secureConnection,
    port: config.mailer.port,
    auth: {
      user: config.mailer.authUser,
      pass: config.mailer.authPass
    },
    tls: {
        ciphers: config.mailer.tlsCiphers
    } 
Rosanny Sihombing's avatar
Rosanny Sihombing committed
89
  });
90
91
92
93
94
95
96
97
98
  
  var mailOptions = {
    to: "",
    from: config.mailer.from,
    subject: "",
    text: ""
  };
  
  // ======== APP ROUTES ====================
Rosanny Sihombing's avatar
Rosanny Sihombing committed
99
100
101
102
103
104
105
  app.get('/', function (req, res) {
    res.redirect('/profile')
  });

  app.get('/login',
    passport.authenticate(config.passport.strategy,
      {
106
107
        successRedirect: '/account/',
        failureRedirect: '/account/login'
Rosanny Sihombing's avatar
Rosanny Sihombing committed
108
109
110
      })
  );

111
112
  app.get('/logout', function (req, res) {
    if (req.user == null) {
113
      return res.redirect('/account/');
Rosanny Sihombing's avatar
Rosanny Sihombing committed
114
    }
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
    
    req.user.nameID = req.user.id;
    req.user.nameIDFormat = req.user.idFormat;
    return samlStrategy.logout(req, function(err, uri) {
      req.logout();
      
      if ( req.session ) {
        req.session.destroy((err) => {
          if(err) {
              return console.log(err);
          }
        });
      }
     
      return res.redirect(uri);
    });
  });
Rosanny Sihombing's avatar
Rosanny Sihombing committed
132
133

  app.get('/profile', function (req, res) {
134
135
136
137
138
139
140
141
142
    if (req.isAuthenticated()) {
      methods.getUserByEmail(req.user.email, function(data, err){
        if (!err) {
          res.render('profile', {
            user: data,
            email: req.user.email
          });
        }
      })
Rosanny Sihombing's avatar
Rosanny Sihombing committed
143
    } else {
144
      res.redirect('/account/login');
Rosanny Sihombing's avatar
Rosanny Sihombing committed
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
    }
  });

  app.get('/services', function (req, res) {
    if (req.isAuthenticated()) {
      async.waterfall([
        // get userId by email from userdb
        function(done) {
          methods.getUserIdByEmail(req.user.email, function(userId, err) {
            if (!err) {
              done(err, userId)
            }
          })
        },
        // get user-project-role from userdb
        function(userId, done) {
          methods.getUserProjectRole(userId, function(userProjects, err) {
            if (!err) {
              done(err, userProjects)
            }
          })
        },
        // get all projects from projectdb
        function(userProjects, done) {
          methods.getAllProjects(function(projectsOverview, err) {
            if (!err) {
              done(err, userProjects, projectsOverview)
            }
          })
        },
        // create JSON object of projects and user status for front-end
        function(userProjects, projectsOverview, done) {
          var allProjects = []  // JSON object
          
          var userProjectId = []  // array of user's project_id
          for (var i = 0; i < userProjects.length; i++) {
            userProjectId.push(userProjects[i].project_id)
          }

          for (var i = 0; i < projectsOverview.length; i++) {
            // check if projectId is exist in userProjectId[]
            var status = "You cannot access this service"
            if (userProjectId.indexOf(projectsOverview[i].id) > -1) {
              status = "You can access this service"
            }
            // add data to JSON object
            allProjects.push({
              id: projectsOverview[i].id,
              title: projectsOverview[i].title,
              summary: projectsOverview[i].onelinesummary,
              cp: projectsOverview[i].contact_email,
              userStatus: status
            });
          }

          // render the page
          res.render('services', {
            user: req.user,
            project: allProjects
          });
        }
      ])
    } else {
208
      res.redirect('/account/login');
Rosanny Sihombing's avatar
Rosanny Sihombing committed
209
210
211
212
213
    }
  });

  app.get('/security', function (req, res) {
    if (req.isAuthenticated()) {
214
      console.log(req.user)
Rosanny Sihombing's avatar
Rosanny Sihombing committed
215
216
217
218
      res.render('security', {
        user: req.user // useful for view engine, useless for HTML
      });
    } else {
219
      res.redirect('/account/login');
Rosanny Sihombing's avatar
Rosanny Sihombing committed
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
    }
  });

  app.post('/updateProfile', function (req, res) {
    var userData = {
      title: req.body.inputTitle,
      firstname: req.body.inputFirstname,
      lastname: req.body.inputLastname,
      email: req.body.inputEmail,
      organisation: req.body.inputOrganisation,
      industry: req.body.inputIndustry,
      speciality: req.body.inputSpeciality,
    }
    
    if (req.isAuthenticated()) {
      if (userData.email) {
Rosanny Sihombing's avatar
Rosanny Sihombing committed
236
        dbconn.user.query('UPDATE user SET ? WHERE email = "' +userData.email+'"', userData, function (err, rows, fields) {
Rosanny Sihombing's avatar
Rosanny Sihombing committed
237
238
239
240
241
242
243
            //if (err) throw err;
            if (err) {
              req.flash('error', "Failed");
            }
            else {
              req.flash('success', 'Profile updated!');
            }
244
            res.redirect('/account/profile');
Rosanny Sihombing's avatar
Rosanny Sihombing committed
245
246
247
        })
      }
    } else {
248
      res.redirect('/account/login');
Rosanny Sihombing's avatar
Rosanny Sihombing committed
249
250
251
252
253
254
255
256
    }
  });
  
  app.post('/changePwd', function (req, res) {
    if (req.isAuthenticated()) {
      var currPwd = req.body.inputCurrPwd
      var newPwd = req.body.inputNewPwd
      var retypePwd = req.body.inputConfirm
257
<<<<<<< 718d94b9d7028442893b0b248c85cffd5195be05
Rosanny Sihombing's avatar
Rosanny Sihombing committed
258

259
260
261
262
263
264
265
      methods.getUserIdByEmail(req.user.email, function(userId, err) {
        if (!err) {
          // Load hashed passwd from DB
          dbconn.user.query('SELECT password FROM credential WHERE user_id='+userId, function (err, rows, fields) {
            if (err) {
              res.redirect('/500')
              throw err
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
=======
      
      // Load hashed passwd from DB.
      dbconn.user.query('SELECT password FROM user WHERE email="'+req.user.email+'"', function (err, rows, fields) {
        if (err) {
          res.redirect('/account/500')
          throw err
        }
        var userPwd = rows[0].password

        // check if the password is correct
        bcrypt.compare(currPwd, userPwd, function(err, isMatch) {
          if (err) {
            res.redirect('/account/500')
            throw err
          }
          else if (!isMatch) {
            req.flash('error', "Sorry, your password was incorrect. Please double-check your password.")
            res.redirect('/account/security')
          } else {
            if ( newPwd != retypePwd ) {
              req.flash('error', "Passwords do no match. Please make sure you re-type your new password correctly.")
              res.redirect('/account/security')
            }
            else {
              // update password
              bcrypt.genSalt(saltRounds, function(err, salt) {
                bcrypt.hash(newPwd, salt, function(err, hash) {
                  methods.updatePassword(hash, req.user.email, function(err){
                    if (err) {
                      req.flash('error', "Database error: Password cannot be modified.")
                      throw err
                    }
                    else {
                      req.flash('success', "Pasword updated!")
                      console.log('pasword updated!')
                    }
                    res.redirect('/account/security')
                  })
                });
              });
>>>>>>> changed redirect paths relative to account
Rosanny Sihombing's avatar
Rosanny Sihombing committed
308
            }
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
            var userPwd = rows[0].password

            // check if the password is correct
            bcrypt.compare(currPwd, userPwd, function(err, isMatch) {
              if (err) {
                res.redirect('/500')
                throw err
              }
              else if (!isMatch) {
                req.flash('error', "Sorry, your password was incorrect. Please double-check your password.")
                res.redirect('/security')
              }
              else {
                if ( newPwd != retypePwd ) {
                  req.flash('error', "Passwords do no match. Please make sure you re-type your new password correctly.")
                  res.redirect('/security')
                }
                else {
                  // update password
                  bcrypt.genSalt(saltRounds, function(err, salt) {
                    bcrypt.hash(newPwd, salt, function(err, hash) {
                      var credentialData = {
                        password: hash,
                        user_id: userId
                      }
                      methods.updateCredential(credentialData, function(err){
                        if (err) {
                          req.flash('error', "Database error: Password cannot be modified.")
                          throw err
                        }
                        else {
                          req.flash('success', "Pasword updated!")
                          console.log('pasword updated!')
                        }
                        res.redirect('/security')
                      })
                    });
                  });
                }
              }
          }) 
Rosanny Sihombing's avatar
Rosanny Sihombing committed
350
        })
351
<<<<<<< 718d94b9d7028442893b0b248c85cffd5195be05
352
353
354
355
        }
      })  
    }
    else {
Rosanny Sihombing's avatar
Rosanny Sihombing committed
356
      res.redirect('/login');
357
358
359
360
361
=======
      })
    } else {
      res.redirect('/account/login');
>>>>>>> changed redirect paths relative to account
Rosanny Sihombing's avatar
Rosanny Sihombing committed
362
363
364
365
366
367
368
369
370
371
372
    }
  });

  app.get('/forgotPwd', function (req, res) {
    res.render('forgotPwd', {
      user: req.user
    });
  });

  app.post('/forgotPwd', function(req, res, next) {
    //methods.currentDate();
373

Rosanny Sihombing's avatar
Rosanny Sihombing committed
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
    var emailAddress = req.body.inputEmail;
    var emailContent = "Hi there,\n\n"+
      "we've received a request to reset your password. However, this email address is not on our database of registered users.\n\n"+
      "Thanks,\nM4_LAB Team";
    var emailSubject = "Account Access Attempted";
    
    async.waterfall([
      function(done) {
        crypto.randomBytes(20, function(err, buf) {
          var token = buf.toString('hex');
          done(err, token);
        });
      },
      function(token, done) {
        methods.checkUserEmail(emailAddress, function(err, user){
          if (user) {
            console.log("email: user found");
            emailSubject = "M4_LAB Password Reset";
            emailContent = "Hi User,\n\n"+
              "we've received a request to reset your password. If you didn't make the request, just ignore this email.\n\n"+
              "Otherwise, you can reset your password using this link: http://" + req.headers.host + "/reset/" + token + "\n" +
              "This password reset is only valid for 1 hour.\n\n"+
              "Thanks,\nM4_LAB Team"
            
398
399
400
401
402
403
            var credentialData = {
              user_id: user.id,
              resetPasswordToken: token,
              resetPasswordExpires: Date.now() + 3600000 // 1 hour
            }
            methods.updateCredential(credentialData, function(err) {
Rosanny Sihombing's avatar
Rosanny Sihombing committed
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
              done(err, token, user);
            });
          }
          else {
            done(err, null, null);
          }
        });
      },
      function(token, user, done) {
        mailOptions.to = emailAddress;
        mailOptions.subject = emailSubject;
        mailOptions.text = emailContent;
        smtpTransport.sendMail(mailOptions, function(err) {
          done(err, 'done');
        });
      }
    ], function(err) {
      if (err) {
        req.flash('error', 'An error occured. Please try again.');
      }
      else {
        req.flash('success', 'An e-mail has been sent to ' + emailAddress + ' with further instructions.');
      }
427
      res.redirect('/account/forgotPwd');
Rosanny Sihombing's avatar
Rosanny Sihombing committed
428
429
430
431
432
433
434
435
    });
  });

  app.get('/reset/:token', function(req, res) {
    methods.checkUserToken(req.params.token, function(err, user){
      //console.log(user);
      if (!user) {
        req.flash('error', 'Password reset token is invalid or has expired.');
436
        res.redirect('/account/forgotPwd');
Rosanny Sihombing's avatar
Rosanny Sihombing committed
437
438
439
440
441
442
443
444
445
446
      }
      else {
        res.render('reset');
      }
    });
  });

  app.post('/reset/:token', function(req, res) {
    methods.checkUserToken(req.params.token, function(err, user){
      if (user) {
447
        // encrypt password
Rosanny Sihombing's avatar
Rosanny Sihombing committed
448
        bcrypt.genSalt(saltRounds, function(err, salt) {
449
450
451
452
453
454
455
          bcrypt.hash(req.body.inputNewPwd, salt, function(err, hash) {
            var credentialData = {
              password: hash,
              user_id: user.user_id
            }
            // update password
            methods.updateCredential(credentialData, function(err){
Rosanny Sihombing's avatar
Rosanny Sihombing committed
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
              if (err) {
                req.flash('error', "Database error: Password cannot be modified.")
                throw err
              }
              else {
                req.flash('success', "Your pasword has been updated.")
                console.log('pasword updated!')
                // todo: send confirmation email
              }
            })
          });
        });
      }
      else {
        req.flash('error', "User not found.")
      }
    });
   
474
    res.redirect('/account/login')
Rosanny Sihombing's avatar
Rosanny Sihombing committed
475
476
  });

477
<<<<<<< 718d94b9d7028442893b0b248c85cffd5195be05
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
  // todo: user registration with captcha
  app.get('/registration', function(req, res) {
    res.render('registration')
  })

  app.post('/registration', function(req, res) {
    // TODO:
    // create gitlab account?
    // send email to activate profile?

    // user data
    var curDate = new Date()
    var userData = {
      title: req.body.inputTitle,
      firstname: req.body.inputFirstname,
      lastname: req.body.inputLastname,
      email: req.body.inputEmail,
      organisation: req.body.inputOrganisation,
      industry: req.body.inputIndustry,
      speciality: req.body.inputSpeciality,
      createdDate: curDate.toISOString().slice(0,10)
499
500
501
502
503
=======
  app.get('/logout', function (req, res) {
    if (req.user == null) {
      return res.redirect('/account/');
>>>>>>> changed redirect paths relative to account
Rosanny Sihombing's avatar
Rosanny Sihombing committed
504
    }
505
506
507
508
509
510
511
512
513
514
515
    // encrypt password
    bcrypt.genSalt(saltRounds, function(err, salt) {
      bcrypt.hash(req.body.inputPassword, salt, function(err, hash) {
        // create account
        var newAccount = {
          profile: userData,
          password: hash
        }
        methods.registerNewUser(newAccount, function(err){
          if (err) {
            req.flash('error', "Failed");
Rosanny Sihombing's avatar
Rosanny Sihombing committed
516
          }
517
518
519
520
521
522
          else {
            req.flash('success', 'Your account has been created. Please log in.');
          }
          res.redirect('/registration');
        })
      });
Rosanny Sihombing's avatar
Rosanny Sihombing committed
523
    });
524
  })
Rosanny Sihombing's avatar
Rosanny Sihombing committed
525

526
527
528
529
530
531
532
533
534
535
536
537
  app.get('/email/:email', function(req, res) {
    methods.checkUserEmail(req.params.email, function(err, user){
      if (!err) {
        if (user) {
          res.send(false)
        }
        else {
          res.send(true)
        }  
      }
    })
  })
Rosanny Sihombing's avatar
Rosanny Sihombing committed
538

539
};