UserInteractions.js 3.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104
  1. import bodyParser from "body-parser";
  2. import express from "express";
  3. import session from "express-session";
  4. import cwh from "./Singletons.js";
  5. export default function UserInteractions(opts) {
  6. async function sha256(message) {
  7. // encode as UTF-8
  8. const msgBuffer = new TextEncoder().encode(message);
  9. // hash the message
  10. const hashBuffer = await crypto.subtle.digest('SHA-256', msgBuffer);
  11. // convert ArrayBuffer to Array
  12. const hashArray = Array.from(new Uint8Array(hashBuffer));
  13. // convert bytes to hex string
  14. const hashHex = hashArray.map(b => b.toString(16).padStart(2, '0')).join('');
  15. return hashHex;
  16. }
  17. let app = opts.app;
  18. app.use(session({
  19. secret: "rtifhg5878fj",
  20. resave: false,
  21. saveUninitialized: false,
  22. cookie: {
  23. sameSite: "lax", secure: "auto"
  24. }
  25. }))
  26. app.use(bodyParser.json({"limit": "200mb"}));
  27. app.use(express.json());
  28. let db = opts.db;
  29. app.options("/*", (req, res) => {
  30. res.set(cwh).end("FUCK YOU CORS")
  31. })
  32. app.get("/userapi", (req, res) => {
  33. if (!req.session.uuid) {
  34. res.set(cwh).status(500).json({code: 500, R: "IO"})
  35. return
  36. }
  37. db.execute("SELECT username, email from user where uuid = ?", [req.session.uuid], (err, result) => {
  38. res.set(cwh).end(JSON.stringify({
  39. uuid: req.session.uuid,
  40. username: result[0].username,
  41. email: result[0].email,
  42. }));
  43. })
  44. })
  45. app.get("/logout", (req, res) => {
  46. req.session.destroy()
  47. res.set(cwh).status(200)
  48. })
  49. app.post("/login", async function (req, res) {
  50. if (!req.body.username || !req.body.password) {
  51. res.set(cwh).status(500).json({code: 500, R: "IO"})
  52. } else {
  53. db.execute("SELECT uuid from user where username = ? and password = ?", [req.body.username, await sha256(req.body.password)], function (err, result) {
  54. if (result.length === 0) {
  55. res.set(cwh).status(500).json({code: 500, R: "DNE"})
  56. return;
  57. }
  58. req.session.uuid = result[0].uuid;
  59. res.set(cwh).status(200).json({
  60. code: 200,
  61. R: "SS",
  62. uid: result[0].uuid
  63. });
  64. })
  65. }
  66. })
  67. app.post("/register", function (req, res) {
  68. db.execute("SELECT uuid FROM user WHERE username = ?", [req.body.username], async function (err, rows) {
  69. if (!req.body.username || !req.body.password) {
  70. res.set(cwh).status(500).json({code: 500, R: "PE"})
  71. return;
  72. }
  73. if (err) {
  74. console.log(err);
  75. res.set(cwh).status(500).json({code: 500, R: "UNE"});
  76. return;
  77. }
  78. if (rows.length === 0) {
  79. db.execute("INSERT INTO user (uuid, username, email, password, avatar, time) values (?,?,?,?,?,?)", [crypto.randomUUID(), req.body.username, !req.body.email ? null : req.body.email, await sha256(req.body.password), null, Date.now()]);
  80. res.status(200).set(cwh).json({code: 200, R: "SS"});
  81. return;
  82. }
  83. res.set(cwh).status(500).json({code: 500, R: "UE"});
  84. return;
  85. })
  86. })
  87. }