1
0
mirror of https://github.com/xuthus83/pigallery2.git synced 2025-01-14 14:43:17 +08:00
pigallery2/backend/middlewares/user/AuthenticationMWs.ts

67 lines
2.3 KiB
TypeScript
Raw Normal View History

2016-05-25 20:17:42 +02:00
///<reference path="../customtypings/ExtendedRequest.d.ts"/>
import {NextFunction, Request, Response} from "express";
2016-05-25 20:17:42 +02:00
import {Error, ErrorCodes} from "../../../common/entities/Error";
2017-06-04 15:25:08 +02:00
import {UserDTO, UserRoles} from "../../../common/entities/UserDTO";
2016-05-25 20:17:42 +02:00
import {ObjectManagerRepository} from "../../model/ObjectManagerRepository";
2017-06-04 15:25:08 +02:00
import {Config} from "../../../common/config/private/Config";
export class AuthenticationMWs {
2016-12-27 16:09:47 +01:00
public static authenticate(req: Request, res: Response, next: NextFunction) {
2016-07-07 12:26:36 +02:00
if (Config.Client.authenticationRequired === false) {
2016-12-27 16:09:47 +01:00
req.session.user = <UserDTO>{name: "", role: UserRoles.Admin};
2016-12-26 23:36:38 +01:00
2016-07-07 12:26:36 +02:00
return next();
}
2016-05-16 23:15:03 +02:00
if (typeof req.session.user === 'undefined') {
return next(new Error(ErrorCodes.NOT_AUTHENTICATED));
2016-12-27 16:09:47 +01:00
}
return next();
}
2016-05-09 17:04:56 +02:00
2016-12-27 16:09:47 +01:00
public static authorise(role: UserRoles) {
return (req: Request, res: Response, next: NextFunction) => {
if (req.session.user.role < role) {
return next(new Error(ErrorCodes.NOT_AUTHORISED));
}
return next();
};
}
2016-05-09 17:04:56 +02:00
2016-12-27 16:09:47 +01:00
public static inverseAuthenticate(req: Request, res: Response, next: NextFunction) {
if (typeof req.session.user !== 'undefined') {
return next(new Error(ErrorCodes.ALREADY_AUTHENTICATED));
}
return next();
}
2016-05-09 17:04:56 +02:00
2016-12-27 16:09:47 +01:00
public static login(req: Request, res: Response, next: NextFunction) {
//not enough parameter
2016-05-09 17:04:56 +02:00
if ((typeof req.body === 'undefined') || (typeof req.body.loginCredential === 'undefined') || (typeof req.body.loginCredential.username === 'undefined') ||
2016-03-20 16:54:30 +01:00
(typeof req.body.loginCredential.password === 'undefined')) {
return next();
}
2016-05-16 23:15:03 +02:00
//lets find the user
2016-04-22 13:23:44 +02:00
ObjectManagerRepository.getInstance().getUserManager().findOne({
2016-05-09 17:04:56 +02:00
name: req.body.loginCredential.username,
password: req.body.loginCredential.password
}, (err, result) => {
if ((err) || (!result)) {
2016-12-27 16:09:47 +01:00
console.error(err);
return next(new Error(ErrorCodes.CREDENTIAL_NOT_FOUND));
}
req.session.user = result;
return next();
});
}
2016-12-27 16:09:47 +01:00
public static logout(req: Request, res: Response, next: NextFunction) {
2016-05-16 23:15:03 +02:00
delete req.session.user;
return next();
}
}