-
Notifications
You must be signed in to change notification settings - Fork 0
/
utils.js
130 lines (119 loc) · 4.1 KB
/
utils.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
const crypto = require('crypto');
const MongoDB = require('./mongo.js').MongoDB;
const getHash = function (input) {
return crypto.createHash('sha256').update(input).digest('base64');
};
const getUserAsJSON = function (username, password) {
return JSON.stringify({
username: username,
password: this.getHash(password)
});
};
const getServerSecret = function (onSuccess, onFailure) {
MongoDB(
'blog',
'user',
function (collection, closeDBConnection) {
collection.findOne(
{username: "server"},
function (error, result) {
if (error || !result) {
console.log('User not found with username: ' + username);
closeDBConnection();
onFailure();
}
else {
closeDBConnection();
onSuccess(result.password);
}
}
);
},
function () {
console.log('Could not connect to DB.');
onFailure();
}
);
};
const login = function (username, password, onSuccess, onFailure) {
MongoDB(
'blog',
'user',
function (collection, closeDBConnection) {
collection.findOne(
{username: username},
function (error, result) {
if (error || !result) {
console.log('User not found with username: ' + username);
closeDBConnection();
onFailure();
}
else {
if (result.password === password) {
const date = new Date();
date.setHours(date.getHours() + 1);
date.setMinutes(0);
date.setSeconds(0);
date.setMilliseconds(0);
getServerSecret(
//onSuccess
function (serverSecret) {
const hmac = crypto.createHmac('sha256', serverSecret);
hmac.update(JSON.stringify({expiresAt: date.toDateString()}));
const token = hmac.digest('base64');
console.log('Created token:' + token + ', valid until: ' + date.toDateString() + ' ' + date.toTimeString());
onSuccess(token);
},
//onFailure
function () {
onFailure();
}
);
closeDBConnection();
}
else {
console.log('Password was wrong');
closeDBConnection();
onFailure();
}
}
}
);
},
function () {
console.log('Could not connect to DB.');
onFailure();
}
);
};
const validateToken = function(token, onSuccess, onFailure) {
getServerSecret(
//onSuccess
function (serverSecret) {
const date = new Date();
date.setHours(date.getHours() + 1);
date.setMinutes(0);
date.setSeconds(0);
date.setMilliseconds(0);
const hmac = crypto.createHmac('sha256', serverSecret);
hmac.update(JSON.stringify({expiresAt: date.toDateString()}));
const encrypted = hmac.digest('base64');
if (token === encrypted) {
onSuccess();
return;
}
onFailure();
},
//onFailure
function () {
onFailure();
}
);
};
module.exports = {
getHash,
getUserAsJSON,
getServerSecret,
login,
validateToken
};