2017-10-22 09:10:33 +08:00
|
|
|
"use strict";
|
|
|
|
|
2017-10-16 07:47:05 +08:00
|
|
|
const utils = require('../services/utils');
|
2018-04-02 09:27:46 +08:00
|
|
|
const optionService = require('../services/options');
|
|
|
|
const myScryptService = require('../services/my_scrypt');
|
2017-10-16 04:32:49 +08:00
|
|
|
|
2018-03-31 07:31:22 +08:00
|
|
|
function loginPage(req, res) {
|
|
|
|
res.render('login', { failedAuth: false });
|
|
|
|
}
|
2017-10-16 04:32:49 +08:00
|
|
|
|
2018-03-31 07:31:22 +08:00
|
|
|
async function login(req, res) {
|
2018-04-02 09:27:46 +08:00
|
|
|
const userName = await optionService.getOption('username');
|
2017-10-16 04:32:49 +08:00
|
|
|
|
|
|
|
const guessedPassword = req.body.password;
|
|
|
|
|
|
|
|
if (req.body.username === userName && await verifyPassword(guessedPassword)) {
|
2017-10-17 07:14:15 +08:00
|
|
|
const rememberMe = req.body.remember_me;
|
2017-10-16 04:32:49 +08:00
|
|
|
|
2017-10-16 08:16:30 +08:00
|
|
|
req.session.regenerate(() => {
|
2017-10-17 07:14:15 +08:00
|
|
|
if (rememberMe) {
|
|
|
|
req.session.cookie.maxAge = 21 * 24 * 3600000; // 3 weeks
|
|
|
|
} else {
|
|
|
|
req.session.cookie.expires = false;
|
|
|
|
}
|
|
|
|
|
2017-10-16 08:16:30 +08:00
|
|
|
req.session.loggedIn = true;
|
|
|
|
res.redirect('/');
|
|
|
|
});
|
2017-10-16 04:32:49 +08:00
|
|
|
}
|
|
|
|
else {
|
|
|
|
res.render('login', {'failedAuth': true});
|
|
|
|
}
|
2018-03-31 07:31:22 +08:00
|
|
|
}
|
2017-10-16 04:32:49 +08:00
|
|
|
|
2018-03-31 07:31:22 +08:00
|
|
|
async function verifyPassword(guessedPassword) {
|
2018-04-02 09:27:46 +08:00
|
|
|
const hashed_password = utils.fromBase64(await optionService.getOption('password_verification_hash'));
|
2017-10-16 04:32:49 +08:00
|
|
|
|
2018-04-02 09:27:46 +08:00
|
|
|
const guess_hashed = await myScryptService.getVerificationHash(guessedPassword);
|
2017-10-16 04:32:49 +08:00
|
|
|
|
|
|
|
return guess_hashed.equals(hashed_password);
|
|
|
|
}
|
|
|
|
|
2018-03-31 07:31:22 +08:00
|
|
|
function logout(req, res) {
|
|
|
|
req.session.regenerate(() => {
|
|
|
|
req.session.loggedIn = false;
|
|
|
|
|
|
|
|
res.redirect('/');
|
|
|
|
});
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
module.exports = {
|
|
|
|
loginPage,
|
|
|
|
login,
|
|
|
|
logout
|
|
|
|
};
|