Files
cgm-remote-monitor/lib/api/profile/index.js
T
Sulka HaroandGitHub 914ba78f36 Security improvement batch (#6622)
* Adds a new method for the server to push notifies to the client, which require administration privileges from the user. If there are messages in queue but user is not privileged, she is notified of pending messages

* Fix unit tests

* Increase timeouts on tests

* Add translations

* * Aggregate admin messages
* Send admin message on auth fail
* Sending messages over bus
* XSS filtering of objects sent over the REST API

* Warn users if their instance is world readable

* Fix adminnotifies init()

* Fix couple issues from Codacy
2021-01-07 22:46:55 +02:00

109 lines
3.5 KiB
JavaScript

'use strict';
var consts = require('../../constants');
function configure (app, wares, ctx) {
var express = require('express'),
api = express.Router( );
// invoke common middleware
api.use(wares.sendJSONStatus);
// text body types get handled as raw buffer stream
api.use(wares.bodyParser.raw( ));
// json body types get handled as parsed json
api.use(wares.bodyParser.json( ));
// also support url-encoded content-type
api.use(wares.bodyParser.urlencoded({ extended: true }));
api.use(ctx.authorization.isPermitted('api:profile:read'));
/**
* @function query_models
* Perform the standard query logic, translating API parameters into mongo
* db queries in a fairly regimented manner.
* This middleware executes the query, returning the results as JSON
*/
function query_models (req, res, next) {
var query = req.query;
// If "?count=" is present, use that number to decide how many to return.
if (!query.count) {
query.count = consts.PROFILES_DEFAULT_COUNT;
}
// perform the query
ctx.profile.list_query(query, function payload(err, profiles) {
return res.json(profiles);
});
}
// List profiles available
api.get('/profiles/', query_models);
// List profiles available
api.get('/profile/', function(req, res) {
const limit = req.query && req.query.count ? Number(req.query.count) : consts.PROFILES_DEFAULT_COUNT;
ctx.profile.list(function (err, attribute) {
return res.json(attribute);
}, limit);
});
// List current active record (in current state LAST record is current active)
api.get('/profile/current', function(req, res) {
ctx.profile.last( function(err, records) {
return res.json(records.length > 0 ? records[0] : null);
});
});
function config_authed (app, api, wares, ctx) {
// create new record
api.post('/profile/', ctx.authorization.isPermitted('api:profile:create'), function(req, res) {
var data = req.body;
ctx.purifier.purifyObject(data);
ctx.profile.create(data, function (err, created) {
if (err) {
res.sendJSONStatus(res, consts.HTTP_INTERNAL_ERROR, 'Mongo Error', err);
console.log('Error creating profile');
console.log(err);
} else {
res.json(created.ops);
console.log('Profile created', created);
}
});
});
// update record
api.put('/profile/', ctx.authorization.isPermitted('api:profile:update'), function(req, res) {
var data = req.body;
ctx.profile.save(data, function (err, created) {
if (err) {
res.sendJSONStatus(res, consts.HTTP_INTERNAL_ERROR, 'Mongo Error', err);
console.log('Error saving profile');
console.log(err);
} else {
res.json(created);
console.log('Profile saved', created);
}
});
});
api.delete('/profile/:_id', ctx.authorization.isPermitted('api:profile:delete'), function(req, res) {
ctx.profile.remove(req.params._id, function ( ) {
res.json({ });
});
});
}
if (app.enabled('api')) {
config_authed(app, api, wares, ctx);
}
return api;
}
module.exports = configure;