express-init.js 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144
  1. 'use strict';
  2. module.exports = function(crowi, app) {
  3. var debug = require('debug')('growi:crowi:express-init')
  4. , path = require('path')
  5. , express = require('express')
  6. , bodyParser = require('body-parser')
  7. , cookieParser = require('cookie-parser')
  8. , methodOverride = require('method-override')
  9. , passport = require('passport')
  10. , session = require('express-session')
  11. , sanitizer = require('express-sanitizer')
  12. , basicAuth = require('basic-auth-connect')
  13. , flash = require('connect-flash')
  14. , swig = require('swig-templates')
  15. , webpackAssets = require('express-webpack-assets')
  16. , i18next = require('i18next')
  17. , i18nFsBackend = require('i18next-node-fs-backend')
  18. , i18nSprintf = require('i18next-sprintf-postprocessor')
  19. , i18nMiddleware = require('i18next-express-middleware')
  20. , i18nUserSettingDetector = require('../util/i18nUserSettingDetector')
  21. , env = crowi.node_env
  22. , config = crowi.getConfig()
  23. , middleware = require('../util/middlewares')
  24. , Config = crowi.model('Config')
  25. , User = crowi.model('User')
  26. ;
  27. var lngDetector = new i18nMiddleware.LanguageDetector();
  28. lngDetector.addDetector(i18nUserSettingDetector);
  29. i18next
  30. .use(lngDetector)
  31. .use(i18nFsBackend)
  32. .use(i18nSprintf)
  33. .init({
  34. // debug: true,
  35. fallbackLng: [User.LANG_EN_US],
  36. whitelist: Object.keys(User.getLanguageLabels()).map((k) => User[k]),
  37. backend: {
  38. loadPath: crowi.localeDir + '{{lng}}/translation.json'
  39. },
  40. detection: {
  41. order: ['userSettingDetector', 'header', 'navigator'],
  42. },
  43. overloadTranslationOptionHandler: i18nSprintf.overloadTranslationOptionHandler
  44. });
  45. // omit unnecessary header
  46. app.disable('x-powered-by');
  47. app.use(function(req, res, next) {
  48. var now = new Date()
  49. , baseUrl
  50. , tzoffset = -(config.crowi['app:timezone'] || 9) * 60 // for datez
  51. , Page = crowi.model('Page')
  52. , User = crowi.model('User')
  53. , Config = crowi.model('Config')
  54. ;
  55. app.set('tzoffset', tzoffset);
  56. req.config = config;
  57. req.csrfToken = null;
  58. config.crowi['app:url'] = baseUrl = (req.headers['x-forwarded-proto'] == 'https' ? 'https' : req.protocol) + '://' + req.get('host');
  59. res.locals.req = req;
  60. res.locals.baseUrl = baseUrl;
  61. res.locals.config = config;
  62. res.locals.env = env;
  63. res.locals.now = now;
  64. res.locals.tzoffset = tzoffset;
  65. res.locals.consts = {
  66. pageGrants: Page.getGrantLabels(),
  67. userStatus: User.getUserStatusLabels(),
  68. language: User.getLanguageLabels(),
  69. restrictGuestMode: Config.getRestrictGuestModeLabels(),
  70. registrationMode: Config.getRegistrationModeLabels(),
  71. };
  72. res.locals.local_config = Config.getLocalconfig(config); // config for browser context
  73. next();
  74. });
  75. app.set('port', crowi.port);
  76. const staticOption = (crowi.node_env === 'production') ? {maxAge: '30d'} : {};
  77. app.use(express.static(crowi.publicDir, staticOption));
  78. app.engine('html', swig.renderFile);
  79. app.use(webpackAssets(
  80. path.join(crowi.publicDir, 'manifest.json'),
  81. { devMode: (crowi.node_env === 'development') })
  82. );
  83. // app.set('view cache', false); // Default: true in production, otherwise undefined. -- 2017.07.04 Yuki Takei
  84. app.set('view engine', 'html');
  85. app.set('views', crowi.viewsDir);
  86. app.use(methodOverride());
  87. app.use(bodyParser.urlencoded({ extended: true, limit: '50mb' }));
  88. app.use(bodyParser.json({limit: '50mb'}));
  89. app.use(sanitizer());
  90. app.use(cookieParser());
  91. app.use(session(crowi.sessionConfig));
  92. // Set basic auth middleware
  93. app.use(function(req, res, next) {
  94. if (req.query.access_token || req.body.access_token) {
  95. return next();
  96. }
  97. if (config.crowi['security:basicName'] && config.crowi['security:basicSecret']) {
  98. return basicAuth(
  99. config.crowi['security:basicName'],
  100. config.crowi['security:basicSecret'])(req, res, next);
  101. }
  102. else {
  103. next();
  104. }
  105. });
  106. // passport
  107. if (Config.isEnabledPassport(config)) {
  108. debug('initialize Passport');
  109. app.use(passport.initialize());
  110. app.use(passport.session());
  111. }
  112. app.use(flash());
  113. app.use(middleware.swigFilters(crowi, app, swig));
  114. app.use(middleware.swigFunctions(crowi, app));
  115. app.use(middleware.csrfKeyGenerator(crowi, app));
  116. // switch loginChecker
  117. if (Config.isEnabledPassport(config)) {
  118. app.use(middleware.loginCheckerForPassport(crowi, app));
  119. }
  120. else {
  121. app.use(middleware.loginChecker(crowi, app));
  122. }
  123. app.use(i18nMiddleware.handle(i18next));
  124. };