mirror of
https://github.com/NodeBB/NodeBB.git
synced 2025-10-26 16:46:12 +01:00
fix(writeapi): authenticate middleware logic to work better with await
This commit is contained in:
@@ -16,17 +16,41 @@ const controllers = {
|
|||||||
authentication: require('../controllers/authentication'),
|
authentication: require('../controllers/authentication'),
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const passportAuthenticateAsync = function (req, res) {
|
||||||
|
return new Promise((resolve, reject) => {
|
||||||
|
passport.authenticate('bearer', { session: false }, (err, user) => {
|
||||||
|
if (err) {
|
||||||
|
reject(err);
|
||||||
|
} else {
|
||||||
|
resolve(user);
|
||||||
|
}
|
||||||
|
})(req, res);
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
module.exports = function (middleware) {
|
module.exports = function (middleware) {
|
||||||
async function authenticate(req, res) {
|
async function authenticate(req, res) {
|
||||||
if (req.loggedIn) {
|
if (req.loggedIn) {
|
||||||
return true;
|
return true;
|
||||||
} else if (req.headers.hasOwnProperty('authorization')) {
|
} else if (req.headers.hasOwnProperty('authorization')) {
|
||||||
passport.authenticate('bearer', { session: false }, function (err, user) {
|
const user = await passportAuthenticateAsync(req, res);
|
||||||
if (err) { throw new Error(err); }
|
if (!user) { return true; }
|
||||||
if (!user) { return false; }
|
|
||||||
|
// If the token received was a master token, a _uid must also be present for all calls
|
||||||
|
if (user.hasOwnProperty('uid')) {
|
||||||
|
req.login(user, async function (err) {
|
||||||
|
if (err) { throw new Error(err); }
|
||||||
|
|
||||||
|
await controllers.authentication.onSuccessfulLogin(req, user.uid);
|
||||||
|
req.uid = user.uid;
|
||||||
|
req.loggedIn = req.uid > 0;
|
||||||
|
return true;
|
||||||
|
});
|
||||||
|
} else if (user.hasOwnProperty('master') && user.master === true) {
|
||||||
|
if (req.body.hasOwnProperty('_uid') || req.query.hasOwnProperty('_uid')) {
|
||||||
|
user.uid = req.body._uid || req.query._uid;
|
||||||
|
delete user.master;
|
||||||
|
|
||||||
// If the token received was a master token, a _uid must also be present for all calls
|
|
||||||
if (user.hasOwnProperty('uid')) {
|
|
||||||
req.login(user, async function (err) {
|
req.login(user, async function (err) {
|
||||||
if (err) { throw new Error(err); }
|
if (err) { throw new Error(err); }
|
||||||
|
|
||||||
@@ -35,27 +59,13 @@ module.exports = function (middleware) {
|
|||||||
req.loggedIn = req.uid > 0;
|
req.loggedIn = req.uid > 0;
|
||||||
return true;
|
return true;
|
||||||
});
|
});
|
||||||
} else if (user.hasOwnProperty('master') && user.master === true) {
|
|
||||||
if (req.body.hasOwnProperty('_uid') || req.query.hasOwnProperty('_uid')) {
|
|
||||||
user.uid = req.body._uid || req.query._uid;
|
|
||||||
delete user.master;
|
|
||||||
|
|
||||||
req.login(user, async function (err) {
|
|
||||||
if (err) { throw new Error(err); }
|
|
||||||
|
|
||||||
await controllers.authentication.onSuccessfulLogin(req, user.uid);
|
|
||||||
req.uid = user.uid;
|
|
||||||
req.loggedIn = req.uid > 0;
|
|
||||||
return true;
|
|
||||||
});
|
|
||||||
} else {
|
|
||||||
throw new Error('A master token was received without a corresponding `_uid` in the request body');
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
winston.warn('[api/authenticate] Unable to find user after verifying token');
|
throw new Error('A master token was received without a corresponding `_uid` in the request body');
|
||||||
return false;
|
|
||||||
}
|
}
|
||||||
})(req, res);
|
} else {
|
||||||
|
winston.warn('[api/authenticate] Unable to find user after verifying token');
|
||||||
|
return true;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
await plugins.fireHook('response:middleware.authenticate', {
|
await plugins.fireHook('response:middleware.authenticate', {
|
||||||
|
|||||||
Reference in New Issue
Block a user