2015-10-01 20:55:55 -07:00
|
|
|
import dedent from 'dedent';
|
2015-08-20 09:40:03 -07:00
|
|
|
import debugFactory from 'debug';
|
2018-02-19 20:32:14 +00:00
|
|
|
import { curry } from 'lodash';
|
2015-08-07 13:31:48 -07:00
|
|
|
|
2016-06-23 20:05:30 -07:00
|
|
|
import {
|
|
|
|
ifNoUser401,
|
2016-12-15 02:54:59 +05:30
|
|
|
ifNoUserRedirectTo,
|
2018-05-25 23:14:09 +05:30
|
|
|
ifNotVerifiedRedirectToUpdateEmail
|
2016-06-23 20:05:30 -07:00
|
|
|
} from '../utils/middleware';
|
2015-08-07 13:31:48 -07:00
|
|
|
|
2016-01-27 11:34:44 -08:00
|
|
|
const debug = debugFactory('fcc:boot:user');
|
2018-05-25 23:14:09 +05:30
|
|
|
const sendNonUserToHome = ifNoUserRedirectTo('/');
|
|
|
|
const sendNonUserToHomeWithMessage = curry(ifNoUserRedirectTo, 2)('/');
|
2015-08-19 13:05:53 -07:00
|
|
|
|
2015-06-03 16:19:23 -07:00
|
|
|
module.exports = function(app) {
|
2016-06-17 12:35:10 -07:00
|
|
|
const router = app.loopback.Router();
|
|
|
|
const api = app.loopback.Router();
|
2017-12-26 13:20:03 -08:00
|
|
|
const { Email, User } = app.models;
|
2016-12-17 01:44:06 +05:30
|
|
|
|
2016-06-17 12:35:10 -07:00
|
|
|
api.post(
|
2015-08-20 09:40:03 -07:00
|
|
|
'/account/delete',
|
|
|
|
ifNoUser401,
|
|
|
|
postDeleteAccount
|
|
|
|
);
|
2016-06-17 12:35:10 -07:00
|
|
|
api.get(
|
2015-10-01 20:55:55 -07:00
|
|
|
'/account',
|
2018-05-25 23:14:09 +05:30
|
|
|
sendNonUserToHome,
|
2015-10-01 20:55:55 -07:00
|
|
|
getAccount
|
|
|
|
);
|
2016-09-20 12:43:34 -05:00
|
|
|
api.post(
|
2018-02-16 23:18:53 +00:00
|
|
|
'/account/reset-progress',
|
2016-09-20 12:43:34 -05:00
|
|
|
ifNoUser401,
|
|
|
|
postResetProgress
|
|
|
|
);
|
2016-09-28 21:26:17 +07:00
|
|
|
api.get(
|
|
|
|
'/account/unlink/:social',
|
2018-05-25 23:14:09 +05:30
|
|
|
sendNonUserToHome,
|
2016-09-28 21:26:17 +07:00
|
|
|
getUnlinkSocial
|
|
|
|
);
|
|
|
|
|
2015-10-02 11:47:36 -07:00
|
|
|
// Ensure these are the last routes!
|
2016-12-15 02:54:59 +05:30
|
|
|
router.get(
|
2018-02-19 20:32:14 +00:00
|
|
|
'/user/:username/report-user/',
|
2018-05-25 23:14:09 +05:30
|
|
|
sendNonUserToHomeWithMessage('You must be signed in to report a user'),
|
|
|
|
ifNotVerifiedRedirectToUpdateEmail,
|
2016-12-15 02:54:59 +05:30
|
|
|
getReportUserProfile
|
|
|
|
);
|
|
|
|
|
|
|
|
api.post(
|
2018-02-19 20:32:14 +00:00
|
|
|
'/user/:username/report-user/',
|
2016-12-15 02:54:59 +05:30
|
|
|
ifNoUser401,
|
|
|
|
postReportUserProfile
|
|
|
|
);
|
2015-06-03 16:19:23 -07:00
|
|
|
|
2018-05-15 06:12:05 +01:00
|
|
|
app.use(router);
|
2016-07-15 14:32:42 -07:00
|
|
|
app.use(api);
|
2015-06-03 16:31:42 -07:00
|
|
|
|
2015-07-22 23:27:18 -07:00
|
|
|
function getAccount(req, res) {
|
2015-10-01 20:55:55 -07:00
|
|
|
const { username } = req.user;
|
|
|
|
return res.redirect('/' + username);
|
2015-06-03 16:19:23 -07:00
|
|
|
}
|
2015-01-24 04:14:41 -05:00
|
|
|
|
2016-09-28 21:26:17 +07:00
|
|
|
function getUnlinkSocial(req, res, next) {
|
|
|
|
const { user } = req;
|
|
|
|
const { username } = user;
|
|
|
|
|
|
|
|
let social = req.params.social;
|
|
|
|
if (!social) {
|
2018-01-12 14:16:33 -08:00
|
|
|
req.flash('danger', 'No social account found');
|
2016-09-28 21:26:17 +07:00
|
|
|
return res.redirect('/' + username);
|
|
|
|
}
|
|
|
|
|
|
|
|
social = social.toLowerCase();
|
|
|
|
const validSocialAccounts = ['twitter', 'linkedin'];
|
|
|
|
if (validSocialAccounts.indexOf(social) === -1) {
|
2018-01-12 14:16:33 -08:00
|
|
|
req.flash('danger', 'Invalid social account');
|
2016-09-28 21:26:17 +07:00
|
|
|
return res.redirect('/' + username);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!user[social]) {
|
2018-01-12 14:16:33 -08:00
|
|
|
req.flash('danger', `No ${social} account associated`);
|
2016-09-28 21:26:17 +07:00
|
|
|
return res.redirect('/' + username);
|
|
|
|
}
|
|
|
|
|
|
|
|
const query = {
|
|
|
|
where: {
|
|
|
|
provider: social
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
return user.identities(query, function(err, identities) {
|
|
|
|
if (err) { return next(err); }
|
|
|
|
|
|
|
|
// assumed user identity is unique by provider
|
|
|
|
let identity = identities.shift();
|
|
|
|
if (!identity) {
|
2018-01-12 14:16:33 -08:00
|
|
|
req.flash('danger', 'No social account found');
|
2016-09-28 21:26:17 +07:00
|
|
|
return res.redirect('/' + username);
|
|
|
|
}
|
|
|
|
|
|
|
|
return identity.destroy(function(err) {
|
|
|
|
if (err) { return next(err); }
|
|
|
|
|
|
|
|
const updateData = { [social]: null };
|
|
|
|
|
|
|
|
return user.update$(updateData)
|
|
|
|
.subscribe(() => {
|
|
|
|
debug(`${social} has been unlinked successfully`);
|
|
|
|
|
2018-01-12 14:16:33 -08:00
|
|
|
req.flash('info', `You've successfully unlinked your ${social}.`);
|
2016-09-28 21:26:17 +07:00
|
|
|
return res.redirect('/' + username);
|
|
|
|
}, next);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2015-07-22 23:27:18 -07:00
|
|
|
function postDeleteAccount(req, res, next) {
|
2015-06-03 16:19:23 -07:00
|
|
|
User.destroyById(req.user.id, function(err) {
|
2015-03-21 13:42:02 +09:00
|
|
|
if (err) { return next(err); }
|
2015-06-03 16:19:23 -07:00
|
|
|
req.logout();
|
2018-02-16 23:18:53 +00:00
|
|
|
req.flash('success', 'You have successfully deleted your account.');
|
2018-05-26 18:28:20 +05:30
|
|
|
const config = {
|
|
|
|
signed: !!req.signedCookies,
|
|
|
|
domain: process.env.COOKIE_DOMAIN || 'localhost'
|
|
|
|
};
|
|
|
|
res.clearCookie('jwt_access_token', config);
|
|
|
|
res.clearCookie('access_token', config);
|
|
|
|
res.clearCookie('userId', config);
|
|
|
|
res.clearCookie('_csrf', config);
|
2018-02-16 23:18:53 +00:00
|
|
|
return res.status(200).end();
|
2016-09-20 12:43:34 -05:00
|
|
|
});
|
|
|
|
}
|
|
|
|
|
|
|
|
function postResetProgress(req, res, next) {
|
|
|
|
User.findById(req.user.id, function(err, user) {
|
|
|
|
if (err) { return next(err); }
|
2018-02-16 23:18:53 +00:00
|
|
|
return user.update$({
|
2016-09-20 12:43:34 -05:00
|
|
|
progressTimestamps: [{
|
|
|
|
timestamp: Date.now()
|
|
|
|
}],
|
|
|
|
currentChallengeId: '',
|
2018-02-16 23:18:53 +00:00
|
|
|
isRespWebDesignCert: false,
|
|
|
|
is2018DataVisCert: false,
|
|
|
|
isFrontEndLibsCert: false,
|
|
|
|
isJsAlgoDataStructCert: false,
|
|
|
|
isApisMicroservicesCert: false,
|
|
|
|
isInfosecQaCert: false,
|
|
|
|
is2018FullStackCert: false,
|
|
|
|
isFrontEndCert: false,
|
2016-09-20 12:43:34 -05:00
|
|
|
isBackEndCert: false,
|
|
|
|
isDataVisCert: false,
|
2018-02-16 23:18:53 +00:00
|
|
|
isFullStackCert: false,
|
2018-05-15 14:56:26 +01:00
|
|
|
completedChallenges: []
|
2018-02-16 23:18:53 +00:00
|
|
|
})
|
|
|
|
.subscribe(
|
|
|
|
() => {
|
|
|
|
req.flash('success', 'You have successfully reset your progress.');
|
|
|
|
return res.status(200).end();
|
|
|
|
},
|
|
|
|
next
|
|
|
|
);
|
2016-09-20 12:43:34 -05:00
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2016-12-15 02:54:59 +05:30
|
|
|
function getReportUserProfile(req, res) {
|
|
|
|
const username = req.params.username.toLowerCase();
|
|
|
|
return res.render('account/report-profile', {
|
|
|
|
title: 'Report User',
|
|
|
|
username
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
|
|
|
function postReportUserProfile(req, res, next) {
|
|
|
|
const { user } = req;
|
|
|
|
const { username } = req.params;
|
|
|
|
const report = req.sanitize('reportDescription').trimTags();
|
|
|
|
|
|
|
|
if (!username || !report || report === '') {
|
2018-01-12 14:16:33 -08:00
|
|
|
req.flash(
|
|
|
|
'danger',
|
|
|
|
'Oops, something is not right please re-check your submission.'
|
|
|
|
);
|
2016-12-15 02:54:59 +05:30
|
|
|
return next();
|
|
|
|
}
|
|
|
|
|
|
|
|
return Email.send$({
|
|
|
|
type: 'email',
|
2017-08-26 00:07:44 +02:00
|
|
|
to: 'team@freecodecamp.org',
|
2016-12-15 02:54:59 +05:30
|
|
|
cc: user.email,
|
2017-08-26 00:07:44 +02:00
|
|
|
from: 'team@freecodecamp.org',
|
2016-12-15 02:54:59 +05:30
|
|
|
subject: 'Abuse Report : Reporting ' + username + '\'s profile.',
|
|
|
|
text: dedent(`
|
|
|
|
Hello Team,\n
|
|
|
|
This is to report the profile of ${username}.\n
|
|
|
|
Report Details:\n
|
|
|
|
${report}\n\n
|
|
|
|
Reported by:
|
|
|
|
Username: ${user.username}
|
|
|
|
Name: ${user.name}
|
|
|
|
Email: ${user.email}\n
|
|
|
|
Thanks and regards,
|
|
|
|
${user.name}
|
|
|
|
`)
|
|
|
|
}, err => {
|
|
|
|
if (err) {
|
|
|
|
err.redirectTo = '/' + username;
|
|
|
|
return next(err);
|
|
|
|
}
|
|
|
|
|
2018-01-12 14:16:33 -08:00
|
|
|
req.flash(
|
|
|
|
'info',
|
|
|
|
`A report was sent to the team with ${user.email} in copy.`
|
|
|
|
);
|
2016-12-15 02:54:59 +05:30
|
|
|
return res.redirect('/');
|
|
|
|
});
|
|
|
|
}
|
2016-12-16 10:35:38 +05:30
|
|
|
|
2015-06-03 16:19:23 -07:00
|
|
|
};
|