user_control.js 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395
  1. var _ = require('lodash');
  2. var async = require('async');
  3. var crypto = require('crypto');
  4. var nodemailer = require('nodemailer');
  5. var passport = require('passport');
  6. var User = require('../models/user');
  7. var secure = require('../config/secure');
  8. /********** GET / Login **************/
  9. exports.getLogin = function (req, res) {
  10. if (req.user) {
  11. return res.redirect('/');
  12. }
  13. res.render('account/login', {
  14. title: 'Login'
  15. });
  16. };
  17. /********** User GET / User URL **************/
  18. exports.getUserURL = function (req, res) {
  19. User.find({ username: 'windhamdavid' }, function (err, username) {
  20. console.log('%s', User.username);
  21. console.log(req.originalUrl);
  22. console.log(req.baseUrl);
  23. console.log(req.path);
  24. if (err) {
  25. res.render('404', { url: req.url, error: '404 Not found' });
  26. return;
  27. }
  28. var username = req.params.username;
  29. res.render('account/user', {
  30. title: username.User,
  31. url: username.User
  32. });
  33. });
  34. };
  35. /********** POST / Login **************/
  36. exports.postLogin = function(req, res, next) {
  37. req.assert('email', 'Email is not valid').isEmail();
  38. req.assert('password', 'Password cannot be blank').notEmpty();
  39. var errors = req.validationErrors();
  40. if (errors) {
  41. req.flash('errors', errors);
  42. return res.redirect('/login');
  43. }
  44. passport.authenticate('local', function(err, user, info) {
  45. if (err) {
  46. return next(err);
  47. }
  48. if (!user) {
  49. req.flash('errors', { msg: info.message });
  50. return res.redirect('/login');
  51. }
  52. req.logIn(user, function(err) {
  53. if (err) {
  54. return next(err);
  55. }
  56. req.flash('success', { msg: 'Success! You are logged in.' });
  57. res.redirect(req.session.returnTo || '/');
  58. });
  59. })(req, res, next);
  60. };
  61. /********** GET / Logout **************/
  62. exports.logout = function(req, res) {
  63. req.logout();
  64. res.redirect('/');
  65. };
  66. /********** GET / Register **************/
  67. exports.getSignup = function(req, res) {
  68. if (req.user) {
  69. return res.redirect('/');
  70. }
  71. res.render('account/register', {
  72. title: 'Register'
  73. });
  74. };
  75. /********** POST / Register **************/
  76. exports.postSignup = function(req, res, next) {
  77. req.assert('email', 'Email is not valid').isEmail();
  78. req.assert('password', 'Password must be at least 6 characters long').len(6);
  79. req.assert('confirmPassword', 'Passwords do not match').equals(req.body.password);
  80. var errors = req.validationErrors();
  81. if (errors) {
  82. req.flash('errors', errors);
  83. return res.redirect('/register');
  84. }
  85. var user = new User({
  86. email: req.body.email,
  87. password: req.body.password
  88. });
  89. User.findOne({ email: req.body.email }, function(err, existingUser) {
  90. if (existingUser) {
  91. req.flash('errors', { msg: 'Account with that email address already exists.' });
  92. return res.redirect('/register');
  93. }
  94. user.save(function(err) {
  95. if (err) {
  96. return next(err);
  97. }
  98. req.logIn(user, function(err) {
  99. if (err) {
  100. return next(err);
  101. }
  102. res.redirect('/');
  103. });
  104. });
  105. });
  106. };
  107. /********** GET / Account **************/
  108. exports.getAccount = function(req, res) {
  109. res.render('account/profile', {
  110. title: 'Account Management'
  111. });
  112. };
  113. /********** POST / Account **************/
  114. exports.postUpdateProfile = function(req, res, next) {
  115. User.findById(req.user.id, function(err, user) {
  116. if (err) {
  117. return next(err);
  118. }
  119. user.email = req.body.email || '';
  120. user.profile.name = req.body.name || '';
  121. user.profile.username = req.body.username || '';
  122. user.profile.gender = req.body.gender || '';
  123. user.profile.location = req.body.location || '';
  124. user.profile.website = req.body.website || '';
  125. user.profile.bio = req.body.bio || '';
  126. user.save(function(err) {
  127. if (err) {
  128. return next(err);
  129. }
  130. req.flash('success', { msg: 'Profile information updated.' });
  131. res.redirect('/account');
  132. });
  133. });
  134. };
  135. /********** POST / Account / Password **************/
  136. exports.postUpdatePassword = function(req, res, next) {
  137. req.assert('password', 'Password must be at least 4 characters long').len(4);
  138. req.assert('confirmPassword', 'Passwords do not match').equals(req.body.password);
  139. var errors = req.validationErrors();
  140. if (errors) {
  141. req.flash('errors', errors);
  142. return res.redirect('/account');
  143. }
  144. User.findById(req.user.id, function(err, user) {
  145. if (err) {
  146. return next(err);
  147. }
  148. user.password = req.body.password;
  149. user.save(function(err) {
  150. if (err) {
  151. return next(err);
  152. }
  153. req.flash('success', { msg: 'Password has been changed.' });
  154. res.redirect('/account');
  155. });
  156. });
  157. };
  158. /********** POST / Account / Delete **************/
  159. exports.postDeleteAccount = function(req, res, next) {
  160. User.remove({ _id: req.user.id }, function(err) {
  161. if (err) {
  162. return next(err);
  163. }
  164. req.logout();
  165. req.flash('info', { msg: 'Your account has been deleted.' });
  166. res.redirect('/');
  167. });
  168. };
  169. /********** POST / Account / Oauth **************/
  170. exports.getOauthUnlink = function(req, res, next) {
  171. var provider = req.params.provider;
  172. User.findById(req.user.id, function(err, user) {
  173. if (err) {
  174. return next(err);
  175. }
  176. user[provider] = undefined;
  177. user.tokens = _.reject(user.tokens, function(token) { return token.kind === provider; });
  178. user.save(function(err) {
  179. if (err) return next(err);
  180. req.flash('info', { msg: provider + ' account has been unlinked.' });
  181. res.redirect('/account');
  182. });
  183. });
  184. };
  185. /********** GET / Password / :Token **************/
  186. exports.getReset = function(req, res) {
  187. if (req.isAuthenticated()) {
  188. return res.redirect('/');
  189. }
  190. User
  191. .findOne({ resetPasswordToken: req.params.token })
  192. .where('resetPasswordExpires').gt(Date.now())
  193. .exec(function(err, user) {
  194. if (err) {
  195. return next(err);
  196. }
  197. if (!user) {
  198. req.flash('errors', { msg: 'Password reset token is invalid or has expired.' });
  199. return res.redirect('/forgot');
  200. }
  201. res.render('account/reset', {
  202. title: 'Password Reset'
  203. });
  204. });
  205. };
  206. /********** POST / Password / :Token **************/
  207. exports.postReset = function(req, res, next) {
  208. req.assert('password', 'Password must be at least 4 characters long.').len(4);
  209. req.assert('confirm', 'Passwords must match.').equals(req.body.password);
  210. var errors = req.validationErrors();
  211. if (errors) {
  212. req.flash('errors', errors);
  213. return res.redirect('back');
  214. }
  215. async.waterfall([
  216. function(done) {
  217. User
  218. .findOne({ resetPasswordToken: req.params.token })
  219. .where('resetPasswordExpires').gt(Date.now())
  220. .exec(function(err, user) {
  221. if (err) {
  222. return next(err);
  223. }
  224. if (!user) {
  225. req.flash('errors', { msg: 'Password reset token is invalid or has expired.' });
  226. return res.redirect('back');
  227. }
  228. user.password = req.body.password;
  229. user.resetPasswordToken = undefined;
  230. user.resetPasswordExpires = undefined;
  231. user.save(function(err) {
  232. if (err) {
  233. return next(err);
  234. }
  235. req.logIn(user, function(err) {
  236. done(err, user);
  237. });
  238. });
  239. });
  240. },
  241. function(user, done) {
  242. var transporter = nodemailer.createTransport({
  243. service: 'Mandrill',
  244. auth: {
  245. user: secrets.mandrill.user,
  246. pass: secrets.mandrill.password
  247. }
  248. });
  249. var mailOptions = {
  250. to: user.email,
  251. from: 'admin@juryd.com',
  252. subject: 'Your Juryd password has been changed',
  253. text: 'Hello,\n\n' +
  254. 'This is a confirmation that the password for your account ' + user.email + ' has just been changed.\n'
  255. };
  256. transporter.sendMail(mailOptions, function(err) {
  257. req.flash('success', { msg: 'Success! Your password has been changed.' });
  258. done(err);
  259. });
  260. }
  261. ], function(err) {
  262. if (err) {
  263. return next(err);
  264. }
  265. res.redirect('/');
  266. });
  267. };
  268. /********** GET / Password / Forgot **************/
  269. exports.getForgot = function(req, res) {
  270. if (req.isAuthenticated()) {
  271. return res.redirect('/');
  272. }
  273. res.render('account/forgot', {
  274. title: 'Forgot Password'
  275. });
  276. };
  277. /********** Post / Password / Forgot / Email **************/
  278. exports.postForgot = function(req, res, next) {
  279. req.assert('email', 'Please enter a valid email address.').isEmail();
  280. var errors = req.validationErrors();
  281. if (errors) {
  282. req.flash('errors', errors);
  283. return res.redirect('/forgot');
  284. }
  285. async.waterfall([
  286. function(done) {
  287. crypto.randomBytes(16, function(err, buf) {
  288. var token = buf.toString('hex');
  289. done(err, token);
  290. });
  291. },
  292. function(token, done) {
  293. User.findOne({ email: req.body.email.toLowerCase() }, function(err, user) {
  294. if (!user) {
  295. req.flash('errors', { msg: 'No account with that email address exists.' });
  296. return res.redirect('/forgot');
  297. }
  298. user.resetPasswordToken = token;
  299. user.resetPasswordExpires = Date.now() + 3600000; // 1 hour
  300. user.save(function(err) {
  301. done(err, token, user);
  302. });
  303. });
  304. },
  305. function(token, user, done) {
  306. var transporter = nodemailer.createTransport({
  307. service: 'Mandrill',
  308. auth: {
  309. user: secrets.mandrill.user,
  310. pass: secrets.mandrill.password
  311. }
  312. });
  313. var mailOptions = {
  314. to: user.email,
  315. from: 'admin@juryd.com',
  316. subject: 'Juryd - Reset your password',
  317. text: 'You are receiving this email because you (or someone else) have requested the reset of the password for your account.\n\n' +
  318. 'Please click on the following link, or paste this into your browser to complete the process:\n\n' +
  319. 'http://' + req.headers.host + '/reset/' + token + '\n\n' +
  320. 'If you did not request this, please ignore this email and your password will remain unchanged.\n'
  321. };
  322. transporter.sendMail(mailOptions, function(err) {
  323. req.flash('info', { msg: 'An e-mail has been sent to ' + user.email + ' with further instructions.' });
  324. done(err, 'done');
  325. });
  326. }
  327. ], function(err) {
  328. if (err) {
  329. return next(err);
  330. }
  331. res.redirect('/forgot');
  332. });
  333. };