Updated albumsController to use new auth

This commit is contained in:
Pitu 2017-01-29 22:17:49 -03:00
parent 16164115aa
commit 751a876360
1 changed files with 81 additions and 58 deletions

View File

@ -5,93 +5,116 @@ let albumsController = {}
albumsController.list = function(req, res, next){ albumsController.list = function(req, res, next){
if(req.headers.auth !== config.adminToken) let token = req.headers.token
return res.status(401).json({ success: false, description: 'not-authorized'}) if(token === undefined) return res.status(401).json({ success: false, description: 'No token provided' })
let fields = ['id', 'name'] db.table('users').where('token', token).then((user) => {
if(user.length === 0) return res.status(401).json({ success: false, description: 'Invalid token'})
if(req.params.sidebar === undefined) let fields = ['id', 'name']
fields.push('timestamp')
if(req.params.sidebar === undefined)
db.table('albums').select(fields).where('enabled', 1).then((albums) => { fields.push('timestamp')
if(req.params.sidebar !== undefined) db.table('albums').select(fields).where({enabled: 1, userid: user.id}).then((albums) => {
return res.json({ success: true, albums })
let ids = []
for(let album of albums){
album.date = new Date(album.timestamp * 1000)
album.date = album.date.getFullYear() + '-' + (album.date.getMonth() + 1) + '-' + album.date.getDate() + ' ' + (album.date.getHours() < 10 ? '0' : '') + album.date.getHours() + ':' + (album.date.getMinutes() < 10 ? '0' : '') + album.date.getMinutes() + ':' + (album.date.getSeconds() < 10 ? '0' : '') + album.date.getSeconds()
ids.push(album.id)
}
db.table('files').whereIn('albumid', ids).select('albumid').then((files) => {
let albumsCount = {}
for(let id of ids) albumsCount[id] = 0 if(req.params.sidebar !== undefined)
for(let file of files) albumsCount[file.albumid] += 1 return res.json({ success: true, albums })
for(let album of albums) album.files = albumsCount[album.id]
return res.json({ success: true, albums }) let ids = []
for(let album of albums){
album.date = new Date(album.timestamp * 1000)
album.date = album.date.getFullYear() + '-' + (album.date.getMonth() + 1) + '-' + album.date.getDate() + ' ' + (album.date.getHours() < 10 ? '0' : '') + album.date.getHours() + ':' + (album.date.getMinutes() < 10 ? '0' : '') + album.date.getMinutes() + ':' + (album.date.getSeconds() < 10 ? '0' : '') + album.date.getSeconds()
ids.push(album.id)
}
db.table('files').whereIn('albumid', ids).select('albumid').then((files) => {
let albumsCount = {}
for(let id of ids) albumsCount[id] = 0
for(let file of files) albumsCount[file.albumid] += 1
for(let album of albums) album.files = albumsCount[album.id]
return res.json({ success: true, albums })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) }) }).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) }) }).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
} }
albumsController.create = function(req, res, next){ albumsController.create = function(req, res, next){
if(req.headers.auth !== config.adminToken) let token = req.headers.token
return res.status(401).json({ success: false, description: 'not-authorized'}) if(token === undefined) return res.status(401).json({ success: false, description: 'No token provided' })
let name = req.body.name db.table('users').where('token', token).then((user) => {
if(name === undefined || name === '') if(user.length === 0) return res.status(401).json({ success: false, description: 'Invalid token'})
return res.json({ success: false, description: 'No album name specified' })
db.table('albums').where('name', name).where('enabled', 1).then((album) => { let name = req.body.name
if(album.length !== 0) return res.json({ success: false, description: 'There\'s already an album with that name' }) if(name === undefined || name === '')
return res.json({ success: false, description: 'No album name specified' })
db.table('albums').insert({ db.table('albums').where({
name: name, name: name,
enabled: 1, enabled: 1,
timestamp: Math.floor(Date.now() / 1000) userid: user.id
}).then(() => { }).then((album) => {
return res.json({ success: true }) if(album.length !== 0) return res.json({ success: false, description: 'There\'s already an album with that name' })
})
db.table('albums').insert({
name: name,
enabled: 1,
userid: user.id,
timestamp: Math.floor(Date.now() / 1000)
}).then(() => {
return res.json({ success: true })
})
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) }) }).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
} }
albumsController.delete = function(req, res, next){ albumsController.delete = function(req, res, next){
if(req.headers.auth !== config.adminToken) let token = req.headers.token
return res.status(401).json({ success: false, description: 'not-authorized'}) if(token === undefined) return res.status(401).json({ success: false, description: 'No token provided' })
let id = req.body.id db.table('users').where('token', token).then((user) => {
if(id === undefined || id === '') if(user.length === 0) return res.status(401).json({ success: false, description: 'Invalid token'})
return res.json({ success: false, description: 'No album specified' })
db.table('albums').where('id', id).update({ enabled: 0 }).then(() => { let id = req.body.id
return res.json({ success: true }) if(id === undefined || id === '')
return res.json({ success: false, description: 'No album specified' })
db.table('albums').where({id: id, userid: user.id}).update({ enabled: 0 }).then(() => {
return res.json({ success: true })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) }) }).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
} }
albumsController.rename = function(req, res, next){ albumsController.rename = function(req, res, next){
if(req.headers.auth !== config.adminToken) let token = req.headers.token
return res.status(401).json({ success: false, description: 'not-authorized'}) if(token === undefined) return res.status(401).json({ success: false, description: 'No token provided' })
let id = req.body.id db.table('users').where('token', token).then((user) => {
if(id === undefined || id === '') if(user.length === 0) return res.status(401).json({ success: false, description: 'Invalid token'})
return res.json({ success: false, description: 'No album specified' })
let name = req.body.name let id = req.body.id
if(name === undefined || name === '') if(id === undefined || id === '')
return res.json({ success: false, description: 'No name specified' }) return res.json({ success: false, description: 'No album specified' })
db.table('albums').where('name', name).then((results) => { let name = req.body.name
if(results.length !== 0) if(name === undefined || name === '')
return res.json({ success: false, description: 'Name already in use' }) return res.json({ success: false, description: 'No name specified' })
db.table('albums').where('id', id).update({ name: name }).then(() => { db.table('albums').where({name: name, userid: user.id}).then((results) => {
return res.json({ success: true }) if(results.length !== 0) return res.json({ success: false, description: 'Name already in use' })
db.table('albums').where({id: id, userid: user.id}).update({ name: name }).then(() => {
return res.json({ success: true })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) }) }).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) }) }).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })