2016-05-26 02:17:42 +08:00
|
|
|
///<reference path="../customtypings/ExtendedRequest.d.ts"/>
|
2016-03-20 00:31:42 +08:00
|
|
|
import {NextFunction, Request, Response} from "express";
|
2016-05-26 02:17:42 +08:00
|
|
|
import {Error, ErrorCodes} from "../../../common/entities/Error";
|
2016-12-27 23:09:47 +08:00
|
|
|
import {UserRoles, UserDTO} from "../../../common/entities/UserDTO";
|
2016-05-26 02:17:42 +08:00
|
|
|
import {ObjectManagerRepository} from "../../model/ObjectManagerRepository";
|
2016-07-07 18:26:36 +08:00
|
|
|
import {Config} from "../../config/Config";
|
2016-03-20 00:31:42 +08:00
|
|
|
|
2016-03-26 18:19:10 +08:00
|
|
|
export class AuthenticationMWs {
|
2016-03-20 00:31:42 +08:00
|
|
|
|
2016-12-27 23:09:47 +08:00
|
|
|
public static authenticate(req: Request, res: Response, next: NextFunction) {
|
2016-07-07 18:26:36 +08:00
|
|
|
if (Config.Client.authenticationRequired === false) {
|
2016-12-27 23:09:47 +08:00
|
|
|
req.session.user = <UserDTO>{name: "", role: UserRoles.Admin};
|
2016-12-27 06:36:38 +08:00
|
|
|
|
2016-07-07 18:26:36 +08:00
|
|
|
return next();
|
|
|
|
}
|
2016-05-17 05:15:03 +08:00
|
|
|
if (typeof req.session.user === 'undefined') {
|
|
|
|
return next(new Error(ErrorCodes.NOT_AUTHENTICATED));
|
2016-12-27 23:09:47 +08:00
|
|
|
}
|
2016-03-20 00:31:42 +08:00
|
|
|
return next();
|
|
|
|
}
|
2016-05-09 23:04:56 +08:00
|
|
|
|
2016-12-27 23:09:47 +08:00
|
|
|
public static authorise(role: UserRoles) {
|
|
|
|
return (req: Request, res: Response, next: NextFunction) => {
|
2016-03-20 00:31:42 +08:00
|
|
|
if (req.session.user.role < role) {
|
2016-03-26 18:19:10 +08:00
|
|
|
return next(new Error(ErrorCodes.NOT_AUTHORISED));
|
2016-03-20 00:31:42 +08:00
|
|
|
}
|
|
|
|
return next();
|
|
|
|
};
|
|
|
|
}
|
2016-05-09 23:04:56 +08:00
|
|
|
|
2016-12-27 23:09:47 +08:00
|
|
|
public static inverseAuthenticate(req: Request, res: Response, next: NextFunction) {
|
2016-03-20 00:31:42 +08:00
|
|
|
if (typeof req.session.user !== 'undefined') {
|
2016-03-26 18:19:10 +08:00
|
|
|
return next(new Error(ErrorCodes.ALREADY_AUTHENTICATED));
|
2016-03-20 00:31:42 +08:00
|
|
|
}
|
|
|
|
return next();
|
|
|
|
}
|
2016-05-09 23:04:56 +08:00
|
|
|
|
2016-12-27 23:09:47 +08:00
|
|
|
public static login(req: Request, res: Response, next: NextFunction) {
|
2016-03-20 00:31:42 +08:00
|
|
|
//not enough parameter
|
2016-05-09 23:04:56 +08:00
|
|
|
if ((typeof req.body === 'undefined') || (typeof req.body.loginCredential === 'undefined') || (typeof req.body.loginCredential.username === 'undefined') ||
|
2016-03-20 23:54:30 +08:00
|
|
|
(typeof req.body.loginCredential.password === 'undefined')) {
|
2016-03-20 00:31:42 +08:00
|
|
|
return next();
|
|
|
|
}
|
2016-05-17 05:15:03 +08:00
|
|
|
|
2016-03-20 00:31:42 +08:00
|
|
|
//lets find the user
|
2016-04-22 19:23:44 +08:00
|
|
|
ObjectManagerRepository.getInstance().getUserManager().findOne({
|
2016-05-09 23:04:56 +08:00
|
|
|
name: req.body.loginCredential.username,
|
|
|
|
password: req.body.loginCredential.password
|
2016-03-20 00:31:42 +08:00
|
|
|
}, (err, result) => {
|
|
|
|
if ((err) || (!result)) {
|
2016-12-27 23:09:47 +08:00
|
|
|
console.error(err);
|
2016-03-26 18:19:10 +08:00
|
|
|
return next(new Error(ErrorCodes.CREDENTIAL_NOT_FOUND));
|
2016-03-20 00:31:42 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
req.session.user = result;
|
|
|
|
|
|
|
|
return next();
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2016-12-27 23:09:47 +08:00
|
|
|
public static logout(req: Request, res: Response, next: NextFunction) {
|
2016-05-17 05:15:03 +08:00
|
|
|
delete req.session.user;
|
|
|
|
return next();
|
|
|
|
}
|
2016-03-20 00:31:42 +08:00
|
|
|
|
|
|
|
}
|