|
| 1 | +var express = require('express') |
| 2 | +var jwt = require('jsonwebtoken') |
| 3 | +var cors = require('cors') |
| 4 | +var bodyParser = require('body-parser') |
| 5 | +var fs = require('fs') |
| 6 | +var events = require('./db/events.json') |
| 7 | + |
| 8 | +const app = express() |
| 9 | + |
| 10 | +app.use(cors()) |
| 11 | +app.use(bodyParser.json()) |
| 12 | + |
| 13 | +app.get('/', (req, res) => { |
| 14 | + res.json({ |
| 15 | + message: 'Welcome to the API.' |
| 16 | + }) |
| 17 | +}) |
| 18 | + |
| 19 | +app.get('/dashboard', verifyToken, (req, res) => { |
| 20 | + jwt.verify(req.token, 'the_secret_key', err => { |
| 21 | + if (err) { |
| 22 | + res.sendStatus(401) |
| 23 | + } else { |
| 24 | + res.json({ |
| 25 | + events: events |
| 26 | + }) |
| 27 | + } |
| 28 | + }) |
| 29 | +}) |
| 30 | + |
| 31 | +app.post('/register', (req, res) => { |
| 32 | + if (req.body) { |
| 33 | + const user = { |
| 34 | + name: req.body.name, |
| 35 | + email: req.body.email, |
| 36 | + password: req.body.password |
| 37 | + // You'll want to encrypt the password in a live app |
| 38 | + } |
| 39 | + |
| 40 | + var data = JSON.stringify(user, null, 2) |
| 41 | + |
| 42 | + fs.writeFile('db/user.json', data, err => { |
| 43 | + if (err) { |
| 44 | + console.log(err) |
| 45 | + } else { |
| 46 | + console.log('Added user to user.json') |
| 47 | + } |
| 48 | + }) |
| 49 | + // The secret key should be an evironment variable in a live app |
| 50 | + const token = jwt.sign({ user }, 'the_secret_key') |
| 51 | + res.json({ |
| 52 | + token, |
| 53 | + email: user.email, |
| 54 | + name: user.name |
| 55 | + }) |
| 56 | + } else { |
| 57 | + res.sendStatus(401) |
| 58 | + } |
| 59 | +}) |
| 60 | + |
| 61 | +app.post('/login', (req, res) => { |
| 62 | + var userDB = fs.readFileSync('./db/user.json') |
| 63 | + var userInfo = JSON.parse(userDB) |
| 64 | + if ( |
| 65 | + req.body && |
| 66 | + req.body.email === userInfo.email && |
| 67 | + req.body.password === userInfo.password |
| 68 | + ) { |
| 69 | + // The secret key should be an environment variable in a live app |
| 70 | + const token = jwt.sign({ userInfo }, 'the_secret_key') |
| 71 | + res.json({ |
| 72 | + token, |
| 73 | + email: userInfo.email, |
| 74 | + name: userInfo.name |
| 75 | + }) |
| 76 | + } else { |
| 77 | + res.sendStatus(401) |
| 78 | + } |
| 79 | +}) |
| 80 | + |
| 81 | +function verifyToken (req, res, next) { |
| 82 | + const bearerHeader = req.headers['authorization'] |
| 83 | + |
| 84 | + if (typeof bearerHeader !== 'undefined') { |
| 85 | + const bearer = bearerHeader.split(' ') |
| 86 | + const bearerToken = bearer[1] |
| 87 | + req.token = bearerToken |
| 88 | + next() |
| 89 | + } else { |
| 90 | + res.sendStatus(401) |
| 91 | + } |
| 92 | +} |
| 93 | + |
| 94 | +app.listen(3000, () => { |
| 95 | + console.log('Server started on port 3000') |
| 96 | +}) |
0 commit comments