1
0
mirror of https://github.com/xuthus83/pigallery2.git synced 2025-01-14 14:43:17 +08:00
pigallery2/backend/middlewares/user/AuthenticationMWs.ts

186 lines
6.2 KiB
TypeScript
Raw Normal View History

2016-05-25 20:17:42 +02:00
///<reference path="../customtypings/ExtendedRequest.d.ts"/>
2018-03-30 15:30:30 -04:00
import {NextFunction, Request, Response} from 'express';
import {ErrorCodes, ErrorDTO} from '../../../common/entities/Error';
import {UserDTO, UserRoles} from '../../../common/entities/UserDTO';
import {ObjectManagerRepository} from '../../model/ObjectManagerRepository';
import {Config} from '../../../common/config/private/Config';
import {PasswordHelper} from '../../model/PasswordHelper';
import {Utils} from '../../../common/Utils';
2018-11-30 15:36:42 +01:00
import {QueryParams} from '../../../common/QueryParams';
export class AuthenticationMWs {
2017-07-13 23:39:09 +02:00
public static async tryAuthenticate(req: Request, res: Response, next: NextFunction) {
if (Config.Client.authenticationRequired === false) {
req.session.user = <UserDTO>{name: UserRoles[Config.Client.unAuthenticatedUserRole], role: Config.Client.unAuthenticatedUserRole};
2017-07-13 23:39:09 +02:00
return next();
}
try {
const user = await AuthenticationMWs.getSharingUser(req);
if (!!user) {
req.session.user = user;
return next();
}
} catch (err) {
}
return next();
}
2017-07-15 17:48:29 +02:00
2017-07-03 19:17:49 +02:00
public static async authenticate(req: Request, res: Response, next: NextFunction) {
if (Config.Client.authenticationRequired === false) {
req.session.user = <UserDTO>{name: UserRoles[Config.Client.unAuthenticatedUserRole], role: Config.Client.unAuthenticatedUserRole};
2017-07-03 19:17:49 +02:00
return next();
}
try {
const user = await AuthenticationMWs.getSharingUser(req);
if (!!user) {
req.session.user = user;
return next();
2017-07-03 19:17:49 +02:00
}
} catch (err) {
2017-07-15 12:47:11 +02:00
return next(new ErrorDTO(ErrorCodes.CREDENTIAL_NOT_FOUND, null, err));
2017-07-03 19:17:49 +02:00
}
if (typeof req.session.user === 'undefined') {
2017-07-15 12:47:11 +02:00
return next(new ErrorDTO(ErrorCodes.NOT_AUTHENTICATED));
}
if (req.session.rememberMe === true) {
req.sessionOptions.expires = new Date(Date.now() + Config.Server.sessionTimeout);
} else {
2018-11-30 15:36:42 +01:00
delete (req.sessionOptions.expires);
}
2017-07-03 19:17:49 +02:00
return next();
}
2016-05-09 17:04:56 +02:00
2018-03-30 15:30:30 -04:00
public static authoriseDirectory(req: Request, res: Response, next: NextFunction) {
if (req.session.user.permissions == null ||
req.session.user.permissions.length === 0 ||
req.session.user.permissions[0] === '/*') {
2018-03-30 15:30:30 -04:00
return next();
}
const directoryName = req.params.directory || '/';
if (UserDTO.isPathAvailable(directoryName, req.session.user.permissions) === true) {
2018-03-30 15:30:30 -04:00
return next();
}
return next(new ErrorDTO(ErrorCodes.PERMISSION_DENIED));
}
2017-07-03 19:17:49 +02:00
public static authorise(role: UserRoles) {
return (req: Request, res: Response, next: NextFunction) => {
if (req.session.user.role < role) {
2017-07-15 12:47:11 +02:00
return next(new ErrorDTO(ErrorCodes.NOT_AUTHORISED));
2017-07-03 19:17:49 +02:00
}
return next();
};
}
2018-03-30 15:30:30 -04:00
public static async shareLogin(req: Request, res: Response, next: NextFunction) {
if (Config.Client.Sharing.enabled === false) {
2017-07-03 19:17:49 +02:00
return next();
}
// not enough parameter
2018-11-30 15:36:42 +01:00
if ((!req.query[QueryParams.gallery.sharingKey_short] && !req.params[QueryParams.gallery.sharingKey_long])) {
2018-03-30 15:30:30 -04:00
return next(new ErrorDTO(ErrorCodes.INPUT_ERROR, 'no sharing key provided'));
}
2016-05-16 23:15:03 +02:00
2018-03-30 15:30:30 -04:00
try {
const password = (req.body ? req.body.password : null) || null;
const sharing = await ObjectManagerRepository.getInstance().SharingManager.findOne({
2018-11-30 15:36:42 +01:00
sharingKey: req.query[QueryParams.gallery.sharingKey_short] || req.params[QueryParams.gallery.sharingKey_long]
2018-03-30 15:30:30 -04:00
});
2018-05-16 17:47:32 -04:00
2018-03-30 15:30:30 -04:00
if (!sharing || sharing.expires < Date.now() ||
(Config.Client.Sharing.passwordProtected === true
2018-05-16 17:47:32 -04:00
&& (sharing.password)
&& !PasswordHelper.comparePassword(password, sharing.password))) {
2018-03-30 15:30:30 -04:00
return next(new ErrorDTO(ErrorCodes.CREDENTIAL_NOT_FOUND));
}
let path = sharing.path;
if (sharing.includeSubfolders === true) {
2018-03-30 15:30:30 -04:00
path += '*';
}
req.session.user = <UserDTO>{name: 'Guest', role: UserRoles.LimitedGuest, permissions: [path]};
2017-07-03 19:17:49 +02:00
return next();
2018-03-30 15:30:30 -04:00
} catch (err) {
return next(new ErrorDTO(ErrorCodes.GENERAL_ERROR, null, err));
2017-07-03 19:17:49 +02:00
}
2018-02-03 19:50:42 -05:00
2017-07-03 19:17:49 +02:00
}
2017-07-03 19:17:49 +02:00
public static inverseAuthenticate(req: Request, res: Response, next: NextFunction) {
if (typeof req.session.user !== 'undefined') {
2017-07-15 12:47:11 +02:00
return next(new ErrorDTO(ErrorCodes.ALREADY_AUTHENTICATED));
2017-07-03 19:17:49 +02:00
}
return next();
}
2017-07-03 19:17:49 +02:00
public static async login(req: Request, res: Response, next: NextFunction) {
// not enough parameter
if ((typeof req.body === 'undefined') ||
(typeof req.body.loginCredential === 'undefined') ||
(typeof req.body.loginCredential.username === 'undefined') ||
2017-07-03 19:17:49 +02:00
(typeof req.body.loginCredential.password === 'undefined')) {
2017-07-15 12:47:11 +02:00
return next(new ErrorDTO(ErrorCodes.INPUT_ERROR));
}
2017-07-03 19:17:49 +02:00
try {
// lets find the user
const user = Utils.clone(await ObjectManagerRepository.getInstance().UserManager.findOne({
2017-07-03 19:17:49 +02:00
name: req.body.loginCredential.username,
password: req.body.loginCredential.password
}));
delete (user.password);
req.session.user = user;
if (req.body.loginCredential.rememberMe) {
req.sessionOptions.expires = new Date(Date.now() + Config.Server.sessionTimeout);
}
2017-07-03 19:17:49 +02:00
return next();
2017-07-03 19:17:49 +02:00
} catch (err) {
2017-07-15 12:47:11 +02:00
return next(new ErrorDTO(ErrorCodes.CREDENTIAL_NOT_FOUND));
2016-05-16 23:15:03 +02:00
}
2017-07-03 19:17:49 +02:00
}
2018-03-30 15:30:30 -04:00
private static async getSharingUser(req: Request) {
if (Config.Client.Sharing.enabled === true &&
2018-11-30 15:36:42 +01:00
(!!req.params[QueryParams.gallery.sharingKey_short] || !!req.params[QueryParams.gallery.sharingKey_long])) {
2017-07-09 12:03:17 +02:00
const sharing = await ObjectManagerRepository.getInstance().SharingManager.findOne({
2018-11-30 15:36:42 +01:00
sharingKey: req.query[QueryParams.gallery.sharingKey_short] || req.params[QueryParams.gallery.sharingKey_long],
2017-07-09 12:03:17 +02:00
});
2018-03-30 15:30:30 -04:00
if (!sharing || sharing.expires < Date.now()) {
return null;
}
2018-05-16 17:47:32 -04:00
if (Config.Client.Sharing.passwordProtected === true && (sharing.password)) {
2018-03-30 15:30:30 -04:00
return null;
2017-07-09 12:03:17 +02:00
}
let path = sharing.path;
if (sharing.includeSubfolders === true) {
2018-03-30 15:30:30 -04:00
path += '*';
2017-07-09 12:03:17 +02:00
}
2018-03-30 15:30:30 -04:00
return <UserDTO>{name: 'Guest', role: UserRoles.LimitedGuest, permissions: [path]};
2017-07-09 12:03:17 +02:00
}
2018-03-30 15:30:30 -04:00
return null;
2017-07-09 12:03:17 +02:00
}
2017-07-03 19:17:49 +02:00
public static logout(req: Request, res: Response, next: NextFunction) {
delete req.session.user;
delete req.session.rememberMe;
2017-07-03 19:17:49 +02:00
return next();
}
}