/[sudobot]/trunk/src/api/controllers/UserController.ts
ViewVC logotype

Diff of /trunk/src/api/controllers/UserController.ts

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 393 by rakin, Mon Jul 29 17:29:59 2024 UTC revision 396 by rakin, Mon Jul 29 17:30:01 2024 UTC
# Line 17  Line 17 
17  * along with SudoBot. If not, see <https://www.gnu.org/licenses/>.  * along with SudoBot. If not, see <https://www.gnu.org/licenses/>.
18  */  */
19    
20  import { Request } from "express";  import Request from "../Request";
21  import User from "../../models/User";  import User from "../../models/User";
22  import Controller from "../Controller";  import Controller from "../Controller";
23  import { body } from 'express-validator';  import { body } from 'express-validator';
24  import bcrypt from 'bcrypt';  import bcrypt from 'bcrypt';
25  import jwt from 'jsonwebtoken';  import jwt from 'jsonwebtoken';
26  import KeyValuePair from "../../types/KeyValuePair";  import KeyValuePair from "../../types/KeyValuePair";
27  import Response from "../Response";  import { NextFunction, Response as ExpressResponse } from "express";
28  import ValidatorError from "../middleware/ValidatorError";  import ValidatorError from "../middleware/ValidatorError";
29  import RequireAuth from "../middleware/RequireAuth";  import RequireAuth from "../middleware/RequireAuth";
30    
31    function RequireAdmin(request: Request, response: ExpressResponse, next: NextFunction) {
32        if (!request.user?.isAdmin) {
33            response.status(403).send({ error: "Forbidden", code: 403 });
34            return;
35        }
36    
37        next();
38    }
39    
40  export default class UserController extends Controller {  export default class UserController extends Controller {
41      middleware(): KeyValuePair<Function[]> {      middleware(): KeyValuePair<Function[]> {
42          return {          return {
43                index: [RequireAuth, RequireAdmin],
44              create: [              create: [
45                    RequireAuth,
46                    RequireAdmin,
47                  body(["password"]).isLength({ min: 2 }),                  body(["password"]).isLength({ min: 2 }),
48                  body(["username"]).custom(async username => {                  body(["username"]).custom(async username => {
49                      const user = await User.findOne({ username });                      const user = await User.findOne({ username });
# Line 59  export default class UserController exte Line 71  export default class UserController exte
71      }      }
72    
73      public async index() {      public async index() {
         return new Response(403);  
74          return await User.find().select(["_id", "username", "createdAt"]).limit(30);          return await User.find().select(["_id", "username", "createdAt"]).limit(30);
75      }      }
76    
77      public async create(request: Request) {      public async create(request: Request) {
         return new Response(403);  
   
78          const user = new User();          const user = new User();
79    
80          user.username = request.body.username;          user.username = request.body.username;

Legend:
Removed from v.393  
changed lines
  Added in v.396

[email protected]
ViewVC Help
Powered by ViewVC 1.1.26