-
Notifications
You must be signed in to change notification settings - Fork 1
/
auth.js
93 lines (77 loc) · 2.11 KB
/
auth.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
var passport = require('passport')
, TwitterStrategy = require('passport-twitter').Strategy
, User = require('./lib/user')
, confB = require('config')
, conf = confB.Auth
, callbackUrl = confB.Site.callback
, db = require('./lib/db');
User.setBeta(conf.beta);
exports.configure = function (app) {
app.use(passport.initialize());
app.use(passport.session());
};
var twitterConnect = function () {
passport.use(new TwitterStrategy({
consumerKey: conf.twit.consumerKey,
consumerSecret: conf.twit.consumerSecret,
callbackURL: callbackUrl
},
function(token, tokenSecret, profile, done) {
var twitObj = {
twitter_id: profile.id,
twitterObj: profile
};
User.getOrCreate({twitter_id: profile.id}, twitObj, function (err, user) {
done(err, user);
});
}
));
};
exports.connect = function () {
passport.serializeUser(function(user, done) {
done(null, user._id);
});
passport.deserializeUser(function(id, done) {
User.get({_id: db.ObjectId(id)}, function(err, user) {
done(err, user);
});
});
twitterConnect();
};
exports.routes = function (app) {
app.get('/auth/twitter', passport.authenticate('twitter'));
app.get('/auth/twitter/callback',
passport.authenticate('twitter', { successRedirect: '/',
failureRedirect: '/login' }));
app.get('/logout', function(req, res){
req.logout();
res.redirect('/login');
});
};
exports.ensureAuthenticated = function (req, res, next) {
if (req.isAuthenticated()) { return next(); }
res.redirect('/login')
};
exports.ensureAPIAuthenticated = function (req, res, next) {
if (req.isAuthenticated()) { return next(); }
res.json(401, {
error: {
msg: 'Authentification needed.',
code: 401
}
});
};
exports.ensureAdminAuthenticated = function (req, res, next) {
if(!req.isAuthenticated()) {
res.redirect('/login')
return;
}
if (req.user.admin === true) {
return next();
}
res.render('500', {
title: 'Admin Page',
status: 401,
error: 'No access'
});
};