backend revamp: users

This commit is contained in:
Michael Fatemi 2021-04-10 21:41:24 -04:00
parent 603b7532e4
commit dd837616af
4 changed files with 217 additions and 196 deletions

View File

@ -1,47 +1,13 @@
import { Router } from 'express';
import { createSessionFromCodeAndProvider } from './auth';
import {
getGroupByID,
getPoolByID,
getPoolsWithUser,
getUserByID,
} from './data';
import { GroupModel, PoolModel } from './models';
import { createSessionFromCodeAndProvider } from '../auth';
import { getGroupByID, getPoolByID, getPoolsWithUser } from '../data';
import { GroupModel, PoolModel } from '../models';
import * as user from './user';
export const router = Router();
router.get('/user', async (req, res) => {
if (typeof req.query.userID != 'string') {
return;
}
let userID = req.query.userID;
if (userID === '@me') {
userID = req.session.accountID;
}
let user = await getUserByID(userID);
if (user) {
res.json({ status: 'success', data: user });
} else {
res.json({ status: 'error', error: 'not_found' });
}
});
router.patch('/user', (req, res) => {
// if (!(req.body.userID in users)) {
// res.json({ status: 'error', error: 'user not found' });
// } else {
// let user = users[req.body.userID];
// user.username = req.body.username;
// user.first_name = req.body.first_name;
// user.last_name = req.body.last_name;
// res.json({ status: 'success' });
// }
});
router.delete('/user', (req, res) => {});
router.use('/user', user.router);
router.get('/pool', async (req, res) => {
if (typeof req.query.poolID != 'string') {

43
src/api/user.ts Normal file
View File

@ -0,0 +1,43 @@
import { Router } from 'express';
import { GroupModel, PoolModel, UserModel } from '../models';
import requireApiAuth from '../requireApiAuth';
import { ObjectID } from 'mongodb';
export const router = Router();
router.use(requireApiAuth);
router.get('/@me/groups', async (req, res) => {
let userID = req.session.accountID;
let groups = await GroupModel.find({
member_ids: { $all: [userID] },
});
res.json({ status: 'success', data: groups });
});
router.get('/@me/pools', async (req, res) => {
let userID = req.session.accountID;
let pools = await PoolModel.find({
participant_ids: { $all: [userID] },
}).exec();
res.json({ status: 'success', data: pools });
});
router.get('/@me', async (req, res) => {
let user = await UserModel.findById(
new ObjectID(req.session.accountID)
).exec();
res.json({ status: 'success', data: user });
});
router.get('/:userID', async (req, res) => {
let userID = req.params.userID;
let user = await UserModel.findById(new ObjectID(userID)).exec();
let data = user.toJSON();
delete data['email'];
res.json({ status: 'success', data });
});

View File

@ -16,7 +16,7 @@ else console.log('DB connected successfully');
import bodyParser from 'body-parser';
import cors from 'cors';
import express from 'express';
import * as api from './api';
import * as api from './api/index';
import { sessionMiddleware } from './sessionMiddleware';
const app = express();

12
src/requireApiAuth.ts Normal file
View File

@ -0,0 +1,12 @@
import { RequestHandler } from 'express';
const requireApiAuth: RequestHandler = (req, res, next) => {
if (req.session?.accountID == null) {
res.status(401);
res.json({ error: 'unauthorized' });
} else {
next();
}
};
export default requireApiAuth;