mailtrain/lib/passport.js

143 lines
4 KiB
JavaScript
Raw Normal View History

2016-04-04 12:36:30 +00:00
'use strict';
2016-04-13 05:36:55 +00:00
let config = require('config');
2016-08-11 11:21:48 +00:00
let log = require('npmlog');
2017-03-07 14:30:56 +00:00
let _ = require('./translate')._;
let util = require('util');
2016-08-11 11:21:48 +00:00
2016-04-04 12:36:30 +00:00
let passport = require('passport');
let LocalStrategy = require('passport-local').Strategy;
2016-08-29 10:57:27 +00:00
2016-04-04 12:36:30 +00:00
let csrf = require('csurf');
let bodyParser = require('body-parser');
const users = require('../models/users');
const { nodeifyFunction, nodeifyPromise } = require('./nodeify');
const interoperableErrors = require('../shared/interoperable-errors');
2016-04-04 12:36:30 +00:00
2016-08-29 10:57:27 +00:00
let LdapStrategy;
try {
LdapStrategy = require('passport-ldapjs').Strategy; // eslint-disable-line global-require
} catch (E) {
2017-03-15 18:44:12 +00:00
if (config.ldap.enabled) {
2017-03-19 15:03:11 +00:00
log.info('LDAP', 'Module "passport-ldapjs" not installed. LDAP auth will fail.');
2017-03-15 18:44:12 +00:00
}
2016-08-29 10:57:27 +00:00
}
2016-04-04 12:36:30 +00:00
module.exports.csrfProtection = csrf({
cookie: true
});
module.exports.parseForm = bodyParser.urlencoded({
2016-04-13 05:36:55 +00:00
extended: false,
limit: config.www.postsize
2016-04-04 12:36:30 +00:00
});
module.exports.loggedIn = (req, res, next) => {
if (!req.user) {
next(new interoperableErrors.NotLoggedInError());
} else {
next();
}
};
2016-04-04 12:36:30 +00:00
module.exports.setup = app => {
app.use(passport.initialize());
app.use(passport.session());
};
module.exports.restLogout = (req, res) => {
req.logout();
res.json();
2016-04-04 12:36:30 +00:00
};
module.exports.restLogin = (req, res, next) => {
2016-08-11 11:21:48 +00:00
passport.authenticate(config.ldap.enabled ? 'ldap' : 'local', (err, user, info) => {
return next(err);
2016-04-04 12:36:30 +00:00
if (!user) {
return next(new interoperableErrors.IncorrectPasswordError());
2016-04-04 12:36:30 +00:00
}
req.logIn(user, err => {
if (err) {
return next(err);
}
if (req.body.remember) {
// Cookie expires after 30 days
req.session.cookie.maxAge = 30 * 24 * 60 * 60 * 1000;
} else {
// Cookie expires at end of session
req.session.cookie.expires = false;
}
return res.json();
2016-04-04 12:36:30 +00:00
});
})(req, res, next);
};
2016-08-29 10:57:27 +00:00
if (config.ldap.enabled && LdapStrategy) {
2016-08-11 11:21:48 +00:00
log.info('Using LDAP auth');
module.exports.authMethod = 'ldap';
module.exports.isAuthMethodLocal = false;
2016-04-04 12:36:30 +00:00
2016-08-29 10:57:27 +00:00
let opts = {
2016-08-11 11:21:48 +00:00
server: {
2016-08-29 10:57:27 +00:00
url: 'ldap://' + config.ldap.host + ':' + config.ldap.port
2016-08-11 11:21:48 +00:00
},
base: config.ldap.baseDN,
search: {
filter: config.ldap.filter,
attributes: [config.ldap.uidTag, config.ldap.nameTag, 'mail'],
2016-08-11 11:21:48 +00:00
scope: 'sub'
},
uidTag: config.ldap.uidTag
2016-08-11 11:21:48 +00:00
};
passport.use(new LdapStrategy(opts, nodeifyFunction(async (profile) => {
try {
const user = await users.getByUsername(profile[config.ldap.uidTag]);
return {
id: user.id,
username: user.username,
name: profile[config.ldap.nameTag],
email: profile.mail
};
} catch (err) {
if (err instanceof interoperableErrors.NotFoundError) {
const userId = await users.createExternal({
username: profile[config.ldap.uidTag],
2016-08-11 11:21:48 +00:00
});
return {
id: userId,
username: profile[config.ldap.uidTag],
name: profile[config.ldap.nameTag],
email: profile.mail
};
2016-08-11 11:21:48 +00:00
} else {
throw err;
2016-08-11 11:21:48 +00:00
}
}
})));
passport.serializeUser((user, done) => { /* FIXME */ console.log(user); done(null, user); });
passport.deserializeUser((user, done) => done(null, user));
2016-08-11 11:21:48 +00:00
} else {
log.info('Using local auth');
module.exports.authMethod = 'local';
module.exports.isAuthMethodLocal = true;
2016-04-04 12:36:30 +00:00
passport.use(new LocalStrategy(nodeifyFunction(async (username, password) => {
return await users.getByUsernameIfPasswordMatch(username, password);
})));
2016-08-11 11:21:48 +00:00
passport.serializeUser((user, done) => done(null, user.id));
passport.deserializeUser((id, done) => nodeifyPromise(users.getById(id), done));
2016-08-11 11:21:48 +00:00
}
2016-04-04 12:36:30 +00:00