| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | 'use strict'; | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-31 17:06:13 -04:00
										 |  |  | const router = require('express').Router(); | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | const middleware = require('../../middleware'); | 
					
						
							| 
									
										
										
										
											2020-03-30 13:16:29 -04:00
										 |  |  | const controllers = require('../../controllers'); | 
					
						
							| 
									
										
										
										
											2020-03-31 17:06:13 -04:00
										 |  |  | const routeHelpers = require('../helpers'); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | const setupApiRoute = routeHelpers.setupApiRoute; | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-31 17:06:13 -04:00
										 |  |  | // eslint-disable-next-line no-unused-vars
 | 
					
						
							|  |  |  | function guestRoutes() { | 
					
						
							|  |  |  | 	// like registration, login...
 | 
					
						
							|  |  |  | } | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-31 17:06:13 -04:00
										 |  |  | function authenticatedRoutes() { | 
					
						
							|  |  |  | 	const middlewares = [middleware.authenticate]; | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-31 17:06:13 -04:00
										 |  |  | 	setupApiRoute(router, '/', middleware, [...middlewares, middleware.checkRequired.bind(null, ['username']), middleware.isAdmin], 'post', controllers.write.users.create); | 
					
						
							|  |  |  | 	setupApiRoute(router, '/', middleware, [...middlewares, middleware.checkRequired.bind(null, ['uids']), middleware.isAdmin, middleware.exposePrivileges], 'delete', controllers.write.users.deleteMany); | 
					
						
							| 
									
										
										
										
											2020-03-31 19:26:03 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-10-08 13:56:50 -04:00
										 |  |  | 	setupApiRoute(router, '/:uid', middleware, [...middlewares, middleware.assert.user], 'put', controllers.write.users.update); | 
					
						
							|  |  |  | 	setupApiRoute(router, '/:uid', middleware, [...middlewares, middleware.assert.user, middleware.exposePrivileges], 'delete', controllers.write.users.delete); | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-10-08 13:56:50 -04:00
										 |  |  | 	setupApiRoute(router, '/:uid/password', middleware, [...middlewares, middleware.checkRequired.bind(null, ['newPassword']), middleware.assert.user], 'put', controllers.write.users.changePassword); | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-10-08 13:56:50 -04:00
										 |  |  | 	setupApiRoute(router, '/:uid/follow', middleware, [...middlewares, middleware.assert.user], 'put', controllers.write.users.follow); | 
					
						
							|  |  |  | 	setupApiRoute(router, '/:uid/follow', middleware, [...middlewares, middleware.assert.user], 'delete', controllers.write.users.unfollow); | 
					
						
							| 
									
										
										
										
											2020-03-31 20:54:10 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-10-08 13:56:50 -04:00
										 |  |  | 	setupApiRoute(router, '/:uid/ban', middleware, [...middlewares, middleware.assert.user, middleware.exposePrivileges], 'put', controllers.write.users.ban); | 
					
						
							|  |  |  | 	setupApiRoute(router, '/:uid/ban', middleware, [...middlewares, middleware.assert.user, middleware.exposePrivileges], 'delete', controllers.write.users.unban); | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-10-08 13:56:50 -04:00
										 |  |  | 	setupApiRoute(router, '/:uid/tokens', middleware, [...middlewares, middleware.assert.user, middleware.exposePrivilegeSet], 'post', controllers.write.users.generateToken); | 
					
						
							|  |  |  | 	setupApiRoute(router, '/:uid/tokens/:token', middleware, [...middlewares, middleware.assert.user, middleware.exposePrivilegeSet], 'delete', controllers.write.users.deleteToken); | 
					
						
							| 
									
										
										
										
											2020-04-01 22:45:43 -04:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	/** | 
					
						
							|  |  |  | 	 * Implement this later... | 
					
						
							|  |  |  | 	 */ | 
					
						
							|  |  |  | 	// 	app.route('/:uid/tokens')
 | 
					
						
							|  |  |  | 	// 		.get(apiMiddleware.requireUser, function(req, res) {
 | 
					
						
							|  |  |  | 	// 			if (parseInt(req.params.uid, 10) !== parseInt(req.user.uid, 10)) {
 | 
					
						
							|  |  |  | 	// 				return errorHandler.respond(401, res);
 | 
					
						
							|  |  |  | 	// 			}
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// 			auth.getTokens(req.params.uid, function(err, tokens) {
 | 
					
						
							|  |  |  | 	// 				return errorHandler.handle(err, res, {
 | 
					
						
							|  |  |  | 	// 					tokens: tokens
 | 
					
						
							|  |  |  | 	// 				});
 | 
					
						
							|  |  |  | 	// 			});
 | 
					
						
							|  |  |  | 	// 		})
 | 
					
						
							|  |  |  | 	// 		.post(apiMiddleware.requireUser, function(req, res) {
 | 
					
						
							|  |  |  | 	// 			if (parseInt(req.params.uid, 10) !== parseInt(req.user.uid)) {
 | 
					
						
							|  |  |  | 	// 				return errorHandler.respond(401, res);
 | 
					
						
							|  |  |  | 	// 			}
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// 			auth.generateToken(req.params.uid, function(err, token) {
 | 
					
						
							|  |  |  | 	// 				return errorHandler.handle(err, res, {
 | 
					
						
							|  |  |  | 	// 					token: token
 | 
					
						
							|  |  |  | 	// 				});
 | 
					
						
							|  |  |  | 	// 			});
 | 
					
						
							|  |  |  | 	// 		});
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// 	app.delete('/:uid/tokens/:token', apiMiddleware.requireUser, function(req, res) {
 | 
					
						
							|  |  |  | 	// 		if (parseInt(req.params.uid, 10) !== req.user.uid) {
 | 
					
						
							|  |  |  | 	// 			return errorHandler.respond(401, res);
 | 
					
						
							|  |  |  | 	// 		}
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// 		auth.revokeToken(req.params.token, 'user', function(err) {
 | 
					
						
							|  |  |  | 	// 			errorHandler.handle(err, res);
 | 
					
						
							|  |  |  | 	// 		});
 | 
					
						
							|  |  |  | 	// 	});
 | 
					
						
							| 
									
										
										
										
											2020-03-31 17:06:13 -04:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | module.exports = function () { | 
					
						
							|  |  |  | 	authenticatedRoutes(); | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-30 13:16:29 -04:00
										 |  |  | 	return router; | 
					
						
							| 
									
										
										
										
											2020-10-01 10:52:05 -04:00
										 |  |  | }; |