user.js 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381
  1. var _ = require('lodash');
  2. var async = require('async');
  3. var crypto = require('crypto');
  4. var nodemailer = require('nodemailer');
  5. var passport = require('passport');
  6. var User = require('../models/user');
  7. var secure = require('../config/secure');
  8. /********** GET / Login **************/
  9. exports.getLogin = function (req, res) {
  10. if (req.user) {
  11. return res.redirect('/');
  12. }
  13. res.render('account/login', {
  14. title: 'Login'
  15. });
  16. };
  17. /********** POST / Login **************/
  18. exports.postLogin = function(req, res, next) {
  19. req.assert('email', 'Email is not valid').isEmail();
  20. req.assert('password', 'Password cannot be blank').notEmpty();
  21. var errors = req.validationErrors();
  22. if (errors) {
  23. req.flash('errors', errors);
  24. return res.redirect('/login');
  25. }
  26. passport.authenticate('local', function(err, user, info) {
  27. if (err) {
  28. return next(err);
  29. }
  30. if (!user) {
  31. req.flash('errors', { msg: info.message });
  32. return res.redirect('/login');
  33. }
  34. req.logIn(user, function(err) {
  35. if (err) {
  36. return next(err);
  37. }
  38. req.flash('success', { msg: 'Success! You are logged in.' });
  39. res.redirect(req.session.returnTo || '/');
  40. });
  41. })(req, res, next);
  42. };
  43. /********** GET / Logout **************/
  44. exports.logout = function(req, res) {
  45. req.logout();
  46. res.redirect('/');
  47. };
  48. /********** GET / Register **************/
  49. exports.getSignup = function(req, res) {
  50. if (req.user) {
  51. return res.redirect('/');
  52. }
  53. res.render('account/register', {
  54. title: 'Register'
  55. });
  56. };
  57. /********** POST / Register **************/
  58. exports.postSignup = function(req, res, next) {
  59. req.assert('email', 'Email is not valid').isEmail();
  60. req.assert('password', 'Password must be at least 4 characters long').len(4);
  61. req.assert('confirmPassword', 'Passwords do not match').equals(req.body.password);
  62. var errors = req.validationErrors();
  63. if (errors) {
  64. req.flash('errors', errors);
  65. return res.redirect('/register');
  66. }
  67. var user = new User({
  68. email: req.body.email,
  69. password: req.body.password
  70. });
  71. User.findOne({ email: req.body.email }, function(err, existingUser) {
  72. if (existingUser) {
  73. req.flash('errors', { msg: 'Account with that email address already exists.' });
  74. return res.redirect('/register');
  75. }
  76. user.save(function(err) {
  77. if (err) {
  78. return next(err);
  79. }
  80. req.logIn(user, function(err) {
  81. if (err) {
  82. return next(err);
  83. }
  84. res.redirect('/');
  85. });
  86. });
  87. });
  88. };
  89. /**
  90. * GET /account
  91. * Profile page.
  92. */
  93. exports.getAccount = function(req, res) {
  94. res.render('account/profile', {
  95. title: 'Account Management'
  96. });
  97. };
  98. /**
  99. * POST /account/profile
  100. * Update profile information.
  101. */
  102. exports.postUpdateProfile = function(req, res, next) {
  103. User.findById(req.user.id, function(err, user) {
  104. if (err) {
  105. return next(err);
  106. }
  107. user.email = req.body.email || '';
  108. user.profile.name = req.body.name || '';
  109. user.profile.gender = req.body.gender || '';
  110. user.profile.location = req.body.location || '';
  111. user.profile.website = req.body.website || '';
  112. user.save(function(err) {
  113. if (err) {
  114. return next(err);
  115. }
  116. req.flash('success', { msg: 'Profile information updated.' });
  117. res.redirect('/account');
  118. });
  119. });
  120. };
  121. /**
  122. * POST /account/password
  123. * Update current password.
  124. */
  125. exports.postUpdatePassword = function(req, res, next) {
  126. req.assert('password', 'Password must be at least 4 characters long').len(4);
  127. req.assert('confirmPassword', 'Passwords do not match').equals(req.body.password);
  128. var errors = req.validationErrors();
  129. if (errors) {
  130. req.flash('errors', errors);
  131. return res.redirect('/account');
  132. }
  133. User.findById(req.user.id, function(err, user) {
  134. if (err) {
  135. return next(err);
  136. }
  137. user.password = req.body.password;
  138. user.save(function(err) {
  139. if (err) {
  140. return next(err);
  141. }
  142. req.flash('success', { msg: 'Password has been changed.' });
  143. res.redirect('/account');
  144. });
  145. });
  146. };
  147. /**
  148. * POST /account/delete
  149. * Delete user account.
  150. */
  151. exports.postDeleteAccount = function(req, res, next) {
  152. User.remove({ _id: req.user.id }, function(err) {
  153. if (err) {
  154. return next(err);
  155. }
  156. req.logout();
  157. req.flash('info', { msg: 'Your account has been deleted.' });
  158. res.redirect('/');
  159. });
  160. };
  161. /**
  162. * GET /account/unlink/:provider
  163. * Unlink OAuth provider.
  164. */
  165. exports.getOauthUnlink = function(req, res, next) {
  166. var provider = req.params.provider;
  167. User.findById(req.user.id, function(err, user) {
  168. if (err) {
  169. return next(err);
  170. }
  171. user[provider] = undefined;
  172. user.tokens = _.reject(user.tokens, function(token) { return token.kind === provider; });
  173. user.save(function(err) {
  174. if (err) return next(err);
  175. req.flash('info', { msg: provider + ' account has been unlinked.' });
  176. res.redirect('/account');
  177. });
  178. });
  179. };
  180. /**
  181. * GET /reset/:token
  182. * Reset Password page.
  183. */
  184. exports.getReset = function(req, res) {
  185. if (req.isAuthenticated()) {
  186. return res.redirect('/');
  187. }
  188. User
  189. .findOne({ resetPasswordToken: req.params.token })
  190. .where('resetPasswordExpires').gt(Date.now())
  191. .exec(function(err, user) {
  192. if (err) {
  193. return next(err);
  194. }
  195. if (!user) {
  196. req.flash('errors', { msg: 'Password reset token is invalid or has expired.' });
  197. return res.redirect('/forgot');
  198. }
  199. res.render('account/reset', {
  200. title: 'Password Reset'
  201. });
  202. });
  203. };
  204. /**
  205. * POST /reset/:token
  206. * Process the reset password request.
  207. */
  208. exports.postReset = function(req, res, next) {
  209. req.assert('password', 'Password must be at least 4 characters long.').len(4);
  210. req.assert('confirm', 'Passwords must match.').equals(req.body.password);
  211. var errors = req.validationErrors();
  212. if (errors) {
  213. req.flash('errors', errors);
  214. return res.redirect('back');
  215. }
  216. async.waterfall([
  217. function(done) {
  218. User
  219. .findOne({ resetPasswordToken: req.params.token })
  220. .where('resetPasswordExpires').gt(Date.now())
  221. .exec(function(err, user) {
  222. if (err) {
  223. return next(err);
  224. }
  225. if (!user) {
  226. req.flash('errors', { msg: 'Password reset token is invalid or has expired.' });
  227. return res.redirect('back');
  228. }
  229. user.password = req.body.password;
  230. user.resetPasswordToken = undefined;
  231. user.resetPasswordExpires = undefined;
  232. user.save(function(err) {
  233. if (err) {
  234. return next(err);
  235. }
  236. req.logIn(user, function(err) {
  237. done(err, user);
  238. });
  239. });
  240. });
  241. },
  242. function(user, done) {
  243. var transporter = nodemailer.createTransport({
  244. service: 'Mandrill',
  245. auth: {
  246. user: secrets.mandrill.user,
  247. pass: secrets.mandrill.password
  248. }
  249. });
  250. var mailOptions = {
  251. to: user.email,
  252. from: 'hackathon@starter.com',
  253. subject: 'Your Hackathon Starter password has been changed',
  254. text: 'Hello,\n\n' +
  255. 'This is a confirmation that the password for your account ' + user.email + ' has just been changed.\n'
  256. };
  257. transporter.sendMail(mailOptions, function(err) {
  258. req.flash('success', { msg: 'Success! Your password has been changed.' });
  259. done(err);
  260. });
  261. }
  262. ], function(err) {
  263. if (err) {
  264. return next(err);
  265. }
  266. res.redirect('/');
  267. });
  268. };
  269. /**
  270. * GET /forgot
  271. * Forgot Password page.
  272. */
  273. exports.getForgot = function(req, res) {
  274. if (req.isAuthenticated()) {
  275. return res.redirect('/');
  276. }
  277. res.render('account/forgot', {
  278. title: 'Forgot Password'
  279. });
  280. };
  281. /**
  282. * POST /forgot
  283. * Create a random token, then the send user an email with a reset link.
  284. */
  285. exports.postForgot = function(req, res, next) {
  286. req.assert('email', 'Please enter a valid email address.').isEmail();
  287. var errors = req.validationErrors();
  288. if (errors) {
  289. req.flash('errors', errors);
  290. return res.redirect('/forgot');
  291. }
  292. async.waterfall([
  293. function(done) {
  294. crypto.randomBytes(16, function(err, buf) {
  295. var token = buf.toString('hex');
  296. done(err, token);
  297. });
  298. },
  299. function(token, done) {
  300. User.findOne({ email: req.body.email.toLowerCase() }, function(err, user) {
  301. if (!user) {
  302. req.flash('errors', { msg: 'No account with that email address exists.' });
  303. return res.redirect('/forgot');
  304. }
  305. user.resetPasswordToken = token;
  306. user.resetPasswordExpires = Date.now() + 3600000; // 1 hour
  307. user.save(function(err) {
  308. done(err, token, user);
  309. });
  310. });
  311. },
  312. function(token, user, done) {
  313. var transporter = nodemailer.createTransport({
  314. service: 'Mandrill',
  315. auth: {
  316. user: secrets.mandrill.user,
  317. pass: secrets.mandrill.password
  318. }
  319. });
  320. var mailOptions = {
  321. to: user.email,
  322. from: 'hackathon@starter.com',
  323. subject: 'Reset your password on Hackathon Starter',
  324. text: 'You are receiving this email because you (or someone else) have requested the reset of the password for your account.\n\n' +
  325. 'Please click on the following link, or paste this into your browser to complete the process:\n\n' +
  326. 'http://' + req.headers.host + '/reset/' + token + '\n\n' +
  327. 'If you did not request this, please ignore this email and your password will remain unchanged.\n'
  328. };
  329. transporter.sendMail(mailOptions, function(err) {
  330. req.flash('info', { msg: 'An e-mail has been sent to ' + user.email + ' with further instructions.' });
  331. done(err, 'done');
  332. });
  333. }
  334. ], function(err) {
  335. if (err) {
  336. return next(err);
  337. }
  338. res.redirect('/forgot');
  339. });
  340. };