middlewares.js 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177
  1. var debug = require('debug')('crowi:lib:middlewares');
  2. exports.loginChecker = function(crowi, app) {
  3. return function(req, res, next) {
  4. var User = crowi.model('User');
  5. // session に user object が入ってる
  6. if (req.session.user && '_id' in req.session.user) {
  7. User.findById(req.session.user._id, function(err, userData) {
  8. if (err) {
  9. next();
  10. } else {
  11. req.user = req.session.user = userData;
  12. res.locals.user = req.user;
  13. next();
  14. }
  15. });
  16. } else {
  17. req.user = req.session.user = false;
  18. res.locals.user = req.user;
  19. next();
  20. }
  21. };
  22. };
  23. exports.swigFunctions = function(crowi, app) {
  24. return function(req, res, next) {
  25. require('../util/swigFunctions')(crowi, app, res.locals);
  26. next();
  27. };
  28. };
  29. exports.swigFilters = function(app, swig) {
  30. return function(req, res, next) {
  31. swig.setFilter('path2name', function(string) {
  32. var name = string.replace(/(\/)$/, '');
  33. if (name.match(/.+\/([^/]+\/\d{4}\/\d{2}\/\d{2})$/)) { // /.../hoge/YYYY/MM/DD 形式のページ
  34. return name.replace(/.+\/([^/]+\/\d{4}\/\d{2}\/\d{2})$/, '$1');
  35. }
  36. if (name.match(/.+\/([^/]+\/\d{4}\/\d{2})$/)) { // /.../hoge/YYYY/MM 形式のページ
  37. return name.replace(/.+\/([^/]+\/\d{4}\/\d{2})$/, '$1');
  38. }
  39. if (name.match(/.+\/([^/]+\/\d{4})$/)) { // /.../hoge/YYYY 形式のページ
  40. return name.replace(/.+\/([^/]+\/\d{4})$/, '$1');
  41. }
  42. return name.replace(/.+\/(.+)?$/, '$1'); // ページの末尾を拾う
  43. });
  44. swig.setFilter('datetz', function(input, format) {
  45. // timezone
  46. var swigFilters = require('swig/lib/filters');
  47. return swigFilters.date(input, format, app.get('tzoffset'));
  48. });
  49. swig.setFilter('nl2br', function(string) {
  50. return string
  51. .replace(/\n/g, '<br>');
  52. });
  53. swig.setFilter('presentation', function(string) {
  54. // 手抜き
  55. return string
  56. .replace(/[\n]+#/g, '\n\n\n#')
  57. .replace(/\s(https?.+(jpe?g|png|gif))\s/, '\n\n\n![]($1)\n\n\n');
  58. });
  59. swig.setFilter('picture', function(user) {
  60. if (!user) {
  61. return '';
  62. }
  63. user.fbId = user.userId; // migration
  64. if (user.image && user.image != '/images/userpicture.png') {
  65. return user.image;
  66. } else if (user.fbId) {
  67. return '//graph.facebook.com/' + user.fbId + '/picture?size=square';
  68. } else {
  69. return '/images/userpicture.png';
  70. }
  71. });
  72. next();
  73. };
  74. };
  75. exports.adminRequired = function() {
  76. return function(req, res, next) {
  77. if (req.user && '_id' in req.user) {
  78. if (req.user.admin) {
  79. next();
  80. return;
  81. }
  82. return res.redirect('/');
  83. }
  84. return res.redirect('/login');
  85. };
  86. };
  87. exports.loginRequired = function(crowi, app) {
  88. return function(req, res, next) {
  89. var User = crowi.model('User')
  90. if (req.user && '_id' in req.user) {
  91. if (req.user.status === User.STATUS_ACTIVE) {
  92. // Active の人だけ先に進める
  93. return next();
  94. } else if (req.user.status === User.STATUS_REGISTERED) {
  95. return res.redirect('/login/error/registered');
  96. } else if (req.user.status === User.STATUS_SUSPENDED) {
  97. return res.redirect('/login/error/suspended');
  98. } else if (req.user.status === User.STATUS_INVITED) {
  99. return res.redirect('/login/invited');
  100. }
  101. }
  102. req.session.jumpTo = req.originalUrl;
  103. return res.redirect('/login');
  104. };
  105. };
  106. exports.accessTokenParser = function(crowi, app) {
  107. return function(req, res, next) {
  108. var accessToken = req.query.access_token;
  109. if (!accessToken) {
  110. return next();
  111. }
  112. var User = crowi.model('User')
  113. User.findUserByApiToken(accessToken)
  114. .then(function(userData) {
  115. req.user = userData;
  116. next();
  117. }).catch(function(err) {
  118. next();
  119. });
  120. };
  121. };
  122. // this is for Installer
  123. exports.applicationNotInstalled = function() {
  124. return function(req, res, next) {
  125. var config = req.config;
  126. if (Object.keys(config.crowi).length !== 1) {
  127. return res.render('500', { error: 'Application already installed.' });
  128. }
  129. return next();
  130. };
  131. };
  132. exports.applicationInstalled = function() {
  133. return function(req, res, next) {
  134. var config = req.config;
  135. if (Object.keys(config.crowi).length === 1) { // app:url is set by process
  136. return res.redirect('/installer');
  137. }
  138. return next();
  139. };
  140. };
  141. exports.awsEnabled = function() {
  142. return function (req, res, next) {
  143. var config = req.config;
  144. if (config.crowi['aws:region'] !== '' && config.crowi['aws:bucket'] !== '' && config.crowi['aws:accessKeyId'] !== '' && config.crowi['aws:secretAccessKey'] !== '') {
  145. req.flash('globalError', 'AWS settings required to use this function. Please ask the administrator.');
  146. return res.redirect('/');
  147. }
  148. return next();
  149. };
  150. };