codecombat/server/routes/auth.coffee

106 lines
3.7 KiB
CoffeeScript
Raw Normal View History

2014-01-03 13:32:13 -05:00
passport = require('passport')
winston = require('winston')
LocalStrategy = require('passport-local').Strategy
User = require('../users/User')
UserHandler = require('../users/user_handler')
config = require '../../server_config'
errors = require '../commons/errors'
mail = require '../commons/mail'
2014-01-03 13:32:13 -05:00
module.exports.setupRoutes = (app) ->
passport.serializeUser((user, done) -> done(null, user._id))
passport.deserializeUser((id, done) ->
User.findById(id, (err, user) -> done(err, user)))
passport.use(new LocalStrategy(
(username, password, done) ->
User.findOne({emailLower:username.toLowerCase()}).exec((err, user) ->
return done(err) if err
return done(null, false, {message:'not found', property:'email'}) if not user
passwordReset = (user.get('passwordReset') or '').toLowerCase()
if passwordReset and password.toLowerCase() is passwordReset
User.update {_id: user.get('_id')}, {passwordReset: ''}, {}, ->
return done(null, user)
hash = User.hashPassword(password)
unless user.get('passwordHash') is hash
return done(null, false, {message:'is wrong, wrong, wrong', property:'password'})
return done(null, user)
)
))
app.post('/auth/login', (req, res, next) ->
passport.authenticate('local', (err, user, info) ->
return next(err) if err
if not user
return errors.unauthorized(res, [{message:info.message, property:info.property}])
2014-01-03 13:32:13 -05:00
req.logIn(user, (err) ->
return next(err) if (err)
res.send(UserHandler.formatEntity(req, req.user))
return res.end()
)
)(req, res, next)
)
app.get('/auth/whoami', (req, res) ->
res.setHeader('Content-Type', 'text/json');
res.send(UserHandler.formatEntity(req, req.user))
res.end()
)
app.post('/auth/logout', (req, res) ->
req.logout()
res.end()
)
2014-01-03 13:32:13 -05:00
app.post('/auth/reset', (req, res) ->
unless req.body.email
return errors.badInput(res, [{message:'Need an email specified.', property:'email'}])
2014-01-03 13:32:13 -05:00
User.findOne({emailLower:req.body.email.toLowerCase()}).exec((err, user) ->
if not user
return errors.notFound(res, [{message:'not found.', property:'email'}])
2014-01-03 13:32:13 -05:00
user.set('passwordReset', Math.random().toString(36).slice(2,7).toUpperCase())
user.save (err) =>
return errors.serverError(res) if err
if config.isProduction
2014-01-03 13:32:13 -05:00
options = createMailOptions req.body.email, user.get('passwordReset')
mail.transport.sendMail options, (error, response) ->
2014-01-03 13:32:13 -05:00
if error
console.error "Error sending mail: #{error.message or error}"
return errors.serverError(res) if err
2014-01-03 13:32:13 -05:00
else
return res.end()
2014-01-06 15:14:12 -05:00
else
2014-02-02 18:02:47 -05:00
res.send user.get('passwordReset')
2014-01-06 15:14:12 -05:00
return res.end()
2014-01-03 13:32:13 -05:00
)
)
2014-01-17 13:47:42 -05:00
app.get '/auth/unsubscribe', (req, res) ->
email = req.query.email
unless req.query.email
return errors.badInput res, 'No email provided to unsubscribe.'
User.findOne({emailLower:req.query.email.toLowerCase()}).exec (err, user) ->
if not user
return errors.notFound res, "No user found with email '#{req.query.email}'"
user.set('emailSubscriptions', [])
user.save (err) =>
return errors.serverError res, 'Database failure.' if err
res.send "Unsubscribed #{req.query.email} from all CodeCombat emails. Sorry to see you go! <p><a href='/account/settings'>Account settings</a></p>"
res.end()
2014-01-03 13:32:13 -05:00
createMailOptions = (receiver, password) ->
# TODO: use email templates here
options =
from: config.mail.username
to: receiver
replyTo: config.mail.username
subject: "[CodeCombat] Password Reset"
text: "You can log into your account with: #{password}"
#