-
Notifications
You must be signed in to change notification settings - Fork 2
/
app.js
129 lines (111 loc) · 3.77 KB
/
app.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
var express = require('express');
var path = require('path');
var fs = require('fs');
var favicon = require('static-favicon');
var logger = require('morgan');
var cookieParser = require('cookie-parser');
var bodyParser = require('body-parser');
var mongoose = require('mongoose');
var session = require('express-session');
var validator = require('express-validator');
var flash = require('connect-flash');
var passport = require('passport');
var configuration = require('./config/config.js');
var md5 = require('MD5');
var RedisStore = require('connect-redis')(session);
var csrf = require('csurf');
var app = express();
mongoose.connect(configuration.mongoUri);
var db = mongoose.connection;
db.on('error', function(err) {
console.log(err);
process.exit(1);
});
db.once('open', function callback() {
console.log('Connected to DB');
});
require('./config/passport')(passport); // pass passport for configuration
// view engine setup
app.set('views', path.join(__dirname, 'views'));
app.set('view engine', 'jade');
app.use(favicon());
app.use(bodyParser.json());
app.use(bodyParser.urlencoded());
app.use(validator());
app.use(cookieParser());
app.use(express.static(path.join(__dirname, 'public')));
app.use(session( {
secret: configuration.COOKIE_KEY,
cookie: { domain:'.statik.io', path: '/' },
store: new RedisStore({url: configuration.redisUri})
}));
app.use(passport.initialize());
app.use(passport.session());
app.use(flash());
app.use(csrf());
app.use(function (err,req,res,next) {
if (err.code !== 'EBADCSRFTOKEN') return next(err)
res.status(403)
res.send('session has expired or form tampered with')
});
app.use(function(req, res, next) {
res.locals.user = req.user;
res.locals.error = req.flash('error');
res.locals.success = req.flash('success');
if (req.user != undefined && req.user.selectedEmail != undefined) {
res.locals.gravatar = 'http://www.gravatar.com/avatar/' +md5(req.user.selectedEmail);
} else {
res.locals.gravatar = 'http://www.gravatar.com/avatar/00000000000000000';
}
next();
});
// Log to file if required
var log = process.env.LOG || false;
if (log) {
var logFile = fs.createWriteStream(log, {flags: 'w'});
app.use(logger('dev', ({stream: logFile})));
console.log("Using " + log + " for logging");
} else {
app.use(logger('dev'));
console.log("Using stdout for logging");
}
//CSP
app.get('/*',function(req, res, next) {
var csp = "default-src 'none'; script-src 'self' data: cdnjs.cloudflare.com cdn.jsdelivr.net; object-src 'self'; style-src 'self' cdnjs.cloudflare.com maxcdn.bootstrapcdn.com fonts.googleapis.com 'unsafe-inline'; img-src 'self'; media-src 'self'; frame-src 'self'; font-src 'self' cdnjs.cloudflare.com maxcdn.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com; connect-src 'self'";
res.header('Content-Security-Policy' , csp);
next();
});
//We load the routes
app.use('/', require('./routes/index'));
app.use('/users', require('./routes/users'));
app.use('/plugins', require('./routes/plugin'));
app.use('/ucp', require('./routes/ucp'));
/// catch 404 and forward to error handler
app.use(function(req, res, next) {
var err = new Error('Not Found');
err.status = 404;
next(err);
});
/// error handlers
// development error handler
// will print stacktrace
if (app.get('env') === 'development') {
app.use(function(err, req, res, next) {
res.status(err.status || 500);
res.render('error', {
message: err.message,
error: err
});
});
app.locals.pretty = true;
}
// production error handler
// no stacktraces leaked to user
app.use(function(err, req, res, next) {
res.status(err.status || 500);
res.render('error', {
message: err.message,
error: {}
});
});
module.exports = app;