login.js 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217
  1. module.exports = function(app) {
  2. 'use strict';
  3. var googleapis = require('googleapis')
  4. , debug = require('debug')('crowi:routes:login')
  5. , models = app.set('models')
  6. , config = app.set('config')
  7. , Page = models.Page
  8. , User = models.User
  9. , Revision = models.Revision
  10. , actions = {};
  11. var loginSuccess = function(req, res, userData) {
  12. req.user = req.session.user = userData;
  13. if (!userData.password) {
  14. return res.redirect('/me/password');
  15. }
  16. var jumpTo = req.session.jumpTo;
  17. if (jumpTo) {
  18. req.session.jumpTo = null;
  19. return res.redirect(jumpTo);
  20. } else {
  21. return res.redirect('/');
  22. }
  23. };
  24. var loginFailure = function(req, res) {
  25. req.flash('warningMessage', 'ログインに失敗しました');
  26. return res.redirect('/login');
  27. };
  28. actions.googleCallback = function(req, res) {
  29. var nextAction = req.session.googleCallbackAction || '/login';
  30. debug('googleCallback.nextAction', nextAction);
  31. req.session.googleAuthCode = req.query.code || '';
  32. return res.redirect(nextAction);
  33. };
  34. actions.login = function(req, res) {
  35. var loginForm = req.body.loginForm;
  36. if (req.method == 'POST' && req.form.isValid) {
  37. var email = loginForm.email;
  38. var password = loginForm.password;
  39. User.findUserByEmailAndPassword(email, password, function(err, userData) {
  40. debug('on login findUserByEmailAndPassword', err, userData);
  41. if (userData) {
  42. loginSuccess(req, res, userData);
  43. } else {
  44. loginFailure(req, res);
  45. }
  46. });
  47. } else { // method GET
  48. return res.render('login', {
  49. });
  50. }
  51. };
  52. actions.loginGoogle = function(req, res) {
  53. var code = req.session.googleAuthCode || null;
  54. if (!code) {
  55. require('../lib/googleAuth').createAuthUrl(req, function(err, redirectUrl) {
  56. if (err) {
  57. // TODO
  58. }
  59. req.session.googleCallbackAction = '/login/google';
  60. return res.redirect(redirectUrl);
  61. });
  62. } else {
  63. require('../lib/googleAuth').handleCallback(req, function(err, tokenInfo) {
  64. console.log('handleCallback', err, tokenInfo);
  65. if (err) {
  66. return loginFailure(req, res);
  67. }
  68. var googleId = tokenInfo.user_id;
  69. User.findUserByGoogleId(googleId, function(err, userData) {
  70. console.log('findUserByGoogleId', err, userData);
  71. if (!userData) {
  72. return loginFailure(req, res);
  73. }
  74. return loginSuccess(req, res, userData);
  75. });
  76. });
  77. }
  78. };
  79. actions.loginFacebook = function(req, res) {
  80. var facebook = req.facebook;
  81. facebook.getUser(function(err, fbId) {
  82. if (err || !fbId) {
  83. req.user = req.session.user = false;
  84. return res.redirect('/login');
  85. }
  86. User.findUserByFacebookId(fbId, function(err, userData) {
  87. console.log('on login findUserByFacebookId', err, userData);
  88. if (userData) {
  89. return loginSuccess(req, res, userData);
  90. } else {
  91. return loginFailure(req, res);
  92. }
  93. });
  94. });
  95. };
  96. actions.register = function(req, res) {
  97. var registerForm = req.body.registerForm || {};
  98. // ログイン済みならさようなら
  99. if (req.user) {
  100. return res.redirect('/');
  101. }
  102. // config で closed ならさよなら
  103. if (config.crowi['security:registrationMode'] == 'Closed') {
  104. return res.redirect('/');
  105. }
  106. if (req.method == 'POST' && req.form.isValid) {
  107. var name = registerForm.name;
  108. var username = registerForm.username;
  109. var email = registerForm.email;
  110. var password = registerForm.password;
  111. var facebookId = registerForm.fbId || null;
  112. var googleId = registerForm.googleId || null;
  113. // email と username の unique チェックする
  114. User.isRegisterable(email, username, function (isRegisterable, errOn) {
  115. var isError = false;
  116. if (!User.isEmailValid(email)) {
  117. isError = true;
  118. req.flash('registerWarningMessage', 'このメールアドレスは登録できません。(ホワイトリストなどを確認してください)');
  119. }
  120. if (!isRegisterable) {
  121. if (!errOn.username) {
  122. isError = true;
  123. req.flash('registerWarningMessage', 'このユーザーIDは利用できません。');
  124. }
  125. if (!errOn.email) {
  126. isError = true;
  127. req.flash('registerWarningMessage', 'このメールアドレスは登録済みです。');
  128. }
  129. }
  130. if (isError) {
  131. return res.render('login', {
  132. });
  133. }
  134. User.createUserByEmailAndPassword(name, username, email, password, function(err, userData) {
  135. if (err) {
  136. req.flash('registerWarningMessage', 'ユーザー登録に失敗しました。');
  137. return res.redirect('/login?register=1');
  138. } else {
  139. if (facebookId || googleId) {
  140. userData.updateGoogleIdAndFacebookId(googleId, facebookId, function(err, userData) {
  141. if (err) { // TODO
  142. }
  143. return loginSuccess(req, res, userData);
  144. });
  145. } else {
  146. return loginSuccess(req, res, userData);
  147. }
  148. }
  149. });
  150. });
  151. } else { // method GET
  152. // google callback を受ける可能性もある
  153. var code = req.session.googleAuthCode || null;
  154. console.log('register. if code', code);
  155. if (code) {
  156. require('../lib/googleAuth').handleCallback(req, function(err, tokenInfo) {
  157. if (err) {
  158. req.flash('registerWarningMessage', 'Googleコネクト中にエラーが発生しました。');
  159. return res.redirect('/login?register=1'); // TODO Handling
  160. }
  161. var googleId = tokenInfo.user_id;
  162. var googleEmail = tokenInfo.email;
  163. if (!User.isEmailValid(googleEmail)) {
  164. req.flash('registerWarningMessage', 'このメールアドレスのGoogleアカウントはコネクトできません。');
  165. return res.redirect('/login?register=1');
  166. }
  167. return res.render('login', {
  168. googleId: googleId,
  169. googleEmail: googleEmail,
  170. });
  171. });
  172. } else {
  173. return res.render('login', {
  174. });
  175. }
  176. }
  177. };
  178. actions.registerGoogle = function(req, res) {
  179. require('../lib/googleAuth').createAuthUrl(req, function(err, redirectUrl) {
  180. if (err) {
  181. // TODO
  182. }
  183. req.session.googleCallbackAction = '/register';
  184. return res.redirect(redirectUrl);
  185. });
  186. };
  187. return actions;
  188. };