Notes/src/routes/login.js

66 lines
1.7 KiB
JavaScript
Raw Normal View History

2017-10-21 21:10:33 -04:00
"use strict";
2017-10-15 19:47:05 -04:00
const utils = require('../services/utils');
const optionService = require('../services/options');
const myScryptService = require('../services/my_scrypt');
2021-04-19 21:41:29 +02:00
const log = require('../services/log');
2017-10-15 16:32:49 -04:00
function loginPage(req, res) {
res.render('login', { failedAuth: false });
}
2017-10-15 16:32:49 -04:00
2021-12-29 23:19:05 +01:00
function setPasswordPage(req, res) {
res.render('set_password', { failed: false });
}
2020-06-20 12:31:38 +02:00
function login(req, res) {
const userName = optionService.getOption('username');
2017-10-15 16:32:49 -04:00
const guessedPassword = req.body.password;
2020-06-20 12:31:38 +02:00
if (req.body.username === userName && verifyPassword(guessedPassword)) {
2017-10-16 19:14:15 -04:00
const rememberMe = req.body.remember_me;
2017-10-15 16:32:49 -04:00
2017-10-15 20:16:30 -04:00
req.session.regenerate(() => {
2017-10-16 19:14:15 -04:00
if (rememberMe) {
req.session.cookie.maxAge = 21 * 24 * 3600000; // 3 weeks
} else {
req.session.cookie.expires = false;
}
2017-10-15 20:16:30 -04:00
req.session.loggedIn = true;
2019-05-22 21:25:13 +02:00
res.redirect('.');
2017-10-15 20:16:30 -04:00
});
2017-10-15 16:32:49 -04:00
}
else {
2021-04-19 21:41:29 +02:00
// note that logged IP address is usually meaningless since the traffic should come from a reverse proxy
log.info(`WARNING: Wrong username / password from ${req.ip}, rejecting.`);
2017-10-15 16:32:49 -04:00
res.render('login', {'failedAuth': true});
}
}
2017-10-15 16:32:49 -04:00
2020-06-20 12:31:38 +02:00
function verifyPassword(guessedPassword) {
const hashed_password = utils.fromBase64(optionService.getOption('passwordVerificationHash'));
2017-10-15 16:32:49 -04:00
2020-06-20 12:31:38 +02:00
const guess_hashed = myScryptService.getVerificationHash(guessedPassword);
2017-10-15 16:32:49 -04:00
return guess_hashed.equals(hashed_password);
}
function logout(req, res) {
req.session.regenerate(() => {
req.session.loggedIn = false;
res.redirect('login');
});
}
module.exports = {
loginPage,
2021-12-29 23:19:05 +01:00
setPasswordPage,
login,
logout
};