-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathindex.js
More file actions
173 lines (157 loc) · 4.97 KB
/
index.js
File metadata and controls
173 lines (157 loc) · 4.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
var express = require('express');
var request = require("request");
var qs = require('querystring');
var session = require('express-session');
var uuidv4 = require('uuid/v4');
var app = express();
app.use(session({
secret: "OAuthDemo",
}));
// app.use(express.static('public'));
app.set("json spaces", 2)
var client_id = "00257d0ff6c59880804c"; //注册github OAuth App时获得的client id
var client_secret = "ae5b85b761c26e16b43f70f1a7046299f6ee2537"; //注册github OAuth App时获得的client secret
var webRootUrl = "http://oauthtest.zenglong.top:8085"; //注册github OAuth App时填写的callback URL
var getCode_redirect_uri = '/oauthcode.do';
var app_UserAgent = "OAuthDemo"
app.get('/', function (req, res) {
if (isLogin(req)) {
return res.redirect("/user");
}
res.sendFile(__dirname + "/public/" + "index.html");
})
app.get('/user', function (req, res) {
if (!isLogin(req)) {
return res.redirect("/");
}
var loginInfo = getLoginInfo(req);
var jsonStr = JSON.stringify(loginInfo.user, null, 2);
var body = "<div>";
body += ("登录成功,获取到的GitHub用户信息如下:");
body += ("<br />");
body += ("<pre style='word-wrap: break-word; white-space: pre-wrap;'>" + jsonStr + "</pre>");
body += ("<div><a href='/logout'>注销登录</a></div>");
body += "</div>";
res.send(body);
})
app.get('/logout', function (req, res) {
if (!isLogin(req)) {
return res.redirect("/");
}
var loginInfo = getLoginInfo(req);
request.delete({
url: "https://api.github.com/applications/" + client_id + "/grants/" + loginInfo.token.access_token,
headers: {
'User-Agent': app_UserAgent
},
auth: {
'user': client_id,
'pass': client_secret
}
}, function (err, r, body) {
if (err) {
console.error('failed:', err);
}
logout(req);
res.redirect("/");
});
})
app.get('/githubLogin.do', function (req, res) {
if (isLogin(req)) {
return res.redirect("/user");
}
req.session.oauthState = uuidv4();
var authUrl = 'https://github.com/login/oauth/authorize?';
authUrl += "client_id=" + encodeURIComponent(client_id);
authUrl += "&redirect_uri=" + encodeURIComponent(webRootUrl + getCode_redirect_uri);
authUrl += "&state=" + encodeURIComponent(req.session.oauthState);
res.redirect(authUrl);
});
//github重定向回redirect_uri,并回传code和state
app.get(getCode_redirect_uri, function (req, res) {
if (isLogin(req)) {
return res.redirect("/user");
}
if (req.session.oauthState !== req.query.state) {
return res.redirect("/");
};
var tokenReq = {
"client_id": client_id,
"client_secret": client_secret,
"code": req.query.code,
"redirect_uri": webRootUrl + getCode_redirect_uri,
"state": req.query.state
};
console.log(tokenReq);
//获取token
request.post({
url: "https://github.com/login/oauth/access_token",
headers: {
'User-Agent': app_UserAgent
},
form: tokenReq
}, function (err, r, tokenbody) {
if (err) {
console.error('failed:', err);
res.redirect("/");
return;
}
var tokenObj = qs.parse(tokenbody);
if (tokenObj.error) {
console.error('failed:', tokenObj);
var result = {
msg: "登录失败!!!",
response: tokenObj
}
res.json(result);
return;
}
//token获取成功,app内应保存token以在后续免登陆
//获取user信息
request.get({
url: "https://api.github.com/user?access_token=" + tokenObj.access_token,
headers: {
'User-Agent': app_UserAgent
}
}, function (err, r, body) {
if (err) {
console.error('failed:', err);
res.redirect("/");
return;
}
var userObj = JSON.parse(body);
if (userObj.login) {
console.log(userObj);
login(req, tokenObj, userObj);
return res.redirect("/user");
} else {
console.error('failed:', userObj);
var result = {
msg: "登录失败!!!",
response: userObj
}
res.json(result);
}
});
});
});
function isLogin(req) {
return req.session.loginInfo;
}
function login(req, token, user) {
req.session.loginInfo = {
token: token,
user: user
}
}
function getLoginInfo(req) {
return req.session.loginInfo;
}
function logout(req) {
req.session.destroy();
}
var server = app.listen(8085, function () {
var host = server.address().address
var port = server.address().port
console.log("应用实例,访问地址为 http://%s:%s", host, port)
})