login.js 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220
  1. module.exports = function(app) {
  2. 'use strict';
  3. var googleapis = require('googleapis')
  4. , debug = require('debug')('crowi:routes:login')
  5. , models = app.set('models')
  6. , config = app.set('config')
  7. , Page = models.Page
  8. , User = models.User
  9. , Revision = models.Revision
  10. , actions = {};
  11. var loginSuccess = function(req, res, userData) {
  12. req.user = req.session.user = userData;
  13. if (!userData.password) {
  14. return res.redirect('/me/password');
  15. }
  16. var jumpTo = req.session.jumpTo;
  17. if (jumpTo) {
  18. req.session.jumpTo = null;
  19. return res.redirect(jumpTo);
  20. } else {
  21. return res.redirect('/');
  22. }
  23. };
  24. var loginFailure = function(req, res) {
  25. req.flash('warningMessage', 'ログインに失敗しました');
  26. return res.redirect('/login');
  27. };
  28. actions.googleCallback = function(req, res) {
  29. var nextAction = req.session.googleCallbackAction || '/login';
  30. debug('googleCallback.nextAction', nextAction);
  31. req.session.googleAuthCode = req.query.code || '';
  32. return res.redirect(nextAction);
  33. };
  34. actions.login = function(req, res) {
  35. var loginForm = req.body.loginForm;
  36. if (req.method == 'POST' && req.form.isValid) {
  37. var email = loginForm.email;
  38. var password = loginForm.password;
  39. User.findUserByEmailAndPassword(email, password, function(err, userData) {
  40. debug('on login findUserByEmailAndPassword', err, userData);
  41. if (userData) {
  42. loginSuccess(req, res, userData);
  43. } else {
  44. loginFailure(req, res);
  45. }
  46. });
  47. } else { // method GET
  48. return res.render('login', {
  49. });
  50. }
  51. };
  52. actions.loginGoogle = function(req, res) {
  53. var googleAuth = require('../lib/googleAuth')(app);
  54. var code = req.session.googleAuthCode || null;
  55. if (!code) {
  56. googleAuth.createAuthUrl(req, function(err, redirectUrl) {
  57. if (err) {
  58. // TODO
  59. }
  60. req.session.googleCallbackAction = '/login/google';
  61. return res.redirect(redirectUrl);
  62. });
  63. } else {
  64. googleAuth.handleCallback(req, function(err, tokenInfo) {
  65. debug('handleCallback', err, tokenInfo);
  66. if (err) {
  67. return loginFailure(req, res);
  68. }
  69. var googleId = tokenInfo.user_id;
  70. User.findUserByGoogleId(googleId, function(err, userData) {
  71. debug('findUserByGoogleId', err, userData);
  72. if (!userData) {
  73. return loginFailure(req, res);
  74. }
  75. return loginSuccess(req, res, userData);
  76. });
  77. });
  78. }
  79. };
  80. actions.loginFacebook = function(req, res) {
  81. var facebook = req.facebook;
  82. facebook.getUser(function(err, fbId) {
  83. if (err || !fbId) {
  84. req.user = req.session.user = false;
  85. return res.redirect('/login');
  86. }
  87. User.findUserByFacebookId(fbId, function(err, userData) {
  88. debug('on login findUserByFacebookId', err, userData);
  89. if (userData) {
  90. return loginSuccess(req, res, userData);
  91. } else {
  92. return loginFailure(req, res);
  93. }
  94. });
  95. });
  96. };
  97. actions.register = function(req, res) {
  98. var registerForm = req.body.registerForm || {};
  99. var googleAuth = require('../lib/googleAuth')(app);
  100. // ログイン済みならさようなら
  101. if (req.user) {
  102. return res.redirect('/');
  103. }
  104. // config で closed ならさよなら
  105. if (config.crowi['security:registrationMode'] == 'Closed') {
  106. return res.redirect('/');
  107. }
  108. if (req.method == 'POST' && req.form.isValid) {
  109. var name = registerForm.name;
  110. var username = registerForm.username;
  111. var email = registerForm.email;
  112. var password = registerForm.password;
  113. var facebookId = registerForm.fbId || null;
  114. var googleId = registerForm.googleId || null;
  115. // email と username の unique チェックする
  116. User.isRegisterable(email, username, function (isRegisterable, errOn) {
  117. var isError = false;
  118. if (!User.isEmailValid(email)) {
  119. isError = true;
  120. req.flash('registerWarningMessage', 'このメールアドレスは登録できません。(ホワイトリストなどを確認してください)');
  121. }
  122. if (!isRegisterable) {
  123. if (!errOn.username) {
  124. isError = true;
  125. req.flash('registerWarningMessage', 'このユーザーIDは利用できません。');
  126. }
  127. if (!errOn.email) {
  128. isError = true;
  129. req.flash('registerWarningMessage', 'このメールアドレスは登録済みです。');
  130. }
  131. }
  132. if (isError) {
  133. return res.render('login', {
  134. });
  135. }
  136. User.createUserByEmailAndPassword(name, username, email, password, function(err, userData) {
  137. if (err) {
  138. req.flash('registerWarningMessage', 'ユーザー登録に失敗しました。');
  139. return res.redirect('/login?register=1');
  140. } else {
  141. if (facebookId || googleId) {
  142. userData.updateGoogleIdAndFacebookId(googleId, facebookId, function(err, userData) {
  143. if (err) { // TODO
  144. }
  145. return loginSuccess(req, res, userData);
  146. });
  147. } else {
  148. return loginSuccess(req, res, userData);
  149. }
  150. }
  151. });
  152. });
  153. } else { // method GET
  154. // google callback を受ける可能性もある
  155. var code = req.session.googleAuthCode || null;
  156. debug('register. if code', code);
  157. if (code) {
  158. googleAuth.handleCallback(req, function(err, tokenInfo) {
  159. if (err) {
  160. req.flash('registerWarningMessage', 'Googleコネクト中にエラーが発生しました。');
  161. return res.redirect('/login?register=1'); // TODO Handling
  162. }
  163. var googleId = tokenInfo.user_id;
  164. var googleEmail = tokenInfo.email;
  165. if (!User.isEmailValid(googleEmail)) {
  166. req.flash('registerWarningMessage', 'このメールアドレスのGoogleアカウントはコネクトできません。');
  167. return res.redirect('/login?register=1');
  168. }
  169. return res.render('login', {
  170. googleId: googleId,
  171. googleEmail: googleEmail,
  172. });
  173. });
  174. } else {
  175. return res.render('login', {
  176. });
  177. }
  178. }
  179. };
  180. actions.registerGoogle = function(req, res) {
  181. var googleAuth = require('../lib/googleAuth')(app);
  182. googleAuth.createAuthUrl(req, function(err, redirectUrl) {
  183. if (err) {
  184. // TODO
  185. }
  186. req.session.googleCallbackAction = '/register';
  187. return res.redirect(redirectUrl);
  188. });
  189. };
  190. return actions;
  191. };