var express = require("express"); var bodyParser = require("body-parser"); var cookieParser = require('cookie-parser'); var multer = require("multer"); var PropertiesReader = require('properties-reader'); var properties = PropertiesReader('./properties.file'); var app = express(); var http = null; // Properties if (properties.get('ssl')) { http = require("https"); } else { http = require("http"); } var auth = properties.get('userInfoUrl'); /** @deprecated*/ var authDeprecated = auth.includes("accessToken"); var localPath = properties.get('localPath'); var maxSize = properties.get('max.size') * 1024; var bigMaxSize = properties.get('big-max.size') * 1024; var storage = multer.diskStorage({ destination: function (req, file, cb) { cb(null, 'uploads') }, filename: function (req, file, cb) { if (req.params.id) { cb(null, req.params.id + (req.params.label?('-' + req.params.label):'') + '-' + new Date().getTime() + '.' + file.originalname.split('.').pop()); } else { cb(null, file.originalname); } } }); var upload = multer({storage: storage}) app.use(bodyParser.json()); app.use(bodyParser.urlencoded({extended: true})); app.use(cookieParser()); app.use(function (req, res, next) { res.header('Access-Control-Allow-Origin', req.headers.origin); res.header('Access-Control-Allow-Headers', 'Origin, X-Requested-With, Content-Type, Accept, x-xsrf-token'); res.header('Access-Control-Allow-Credentials', "true"); res.header('Access-Control-Allow-Methods', 'GET, OPTIONS, POST, DELETE'); res.header('Access-Control-Max-Age', "1800"); next(); }); app.get('/download/:filename', function (req, res) { res.download('./uploads/' + req.params.filename); }); app.post("/upload", upload.array("uploads[]", 12), function (req, res) { var filepath = (localPath ? "." : __dirname) + "/" + req.files[0].path; let type = req.query.type; if (type === 'json' && req.files[0].mimetype !== 'application/json') { console.error("No proper file type"); res.status(500).send(getResponse(500, "No proper file type")); } else if ((!type || type === 'csv') && req.files[0].mimetype !== 'text/csv' && req.files[0].mimetype !== 'application/vnd.ms-excel') { console.error("No proper file type"); res.status(500).send(getResponse(500, "No proper file type")); } else { res.download(filepath); setTimeout(function () { deleteFile(filepath); }, 3000); // deleteFile(filepath); } }); app.post(['/upload/:id', '/upload/stakeholder/:id', '/upload/:type/:id', '/upload/:type/:id/:label'], upload.single('photo'), (req, res) => { let fileMaxSize = (req.query.big)?bigMaxSize:maxSize sendFile(req, res, fileMaxSize, (result) => { let type = req.params['type']; let id = req.params['id']; let roles = result.roles; if(type) { return isPortalAdmin(roles) || isCurator(type, roles) || isManager(type, id, roles); } else { return result.sub.indexOf(id) !== -1 || isPortalAdmin(roles) || isAnyCurator(roles); } }); }); app.delete(['/delete/:filename', '/delete/stakeholder/:filename', '/delete/:type/:id/:filename'], function (req, res) { deleteFileSend(req, res, (result) => { let roles = result.roles; let type = req.params['type']; let id = req.params['id']; if(type && id) { return isPortalAdmin(roles) || isCurator(type, roles) || isManager(type, id, roles); } else { return result.sub.indexOf(req.params.filename.split('-')[0]) !== -1 || isPortalAdmin(roles) || isAnyCurator(roles); } }); }); const server = app.listen(properties.get('port'), function () { console.log("Listening on port %s...", server.address().port); }); function sendFile(req, res, size, authorized) { const cookie = (authDeprecated)?req.cookies['AccessToken']:req.cookies['openAIRESession']; const file = req.file; var filepath = (localPath ? "." : __dirname) + "/" + file.path; if (!cookie) { res.status(401).send(getResponse(401, "Unauthorized")); deleteFile(filepath); } else if (!file || (file.mimetype !== 'image/jpeg' && file.mimetype !== 'image/png')) { res.status(500).send(getResponse(500, "No image file type")); deleteFile(filepath); } else if (file.size > size) { res.status(500).send(getResponse(500, "Exceeds file size limit")); deleteFile(filepath); } else { getUserInfo(authorized, req, res, () => { res.send(file); }); } } function deleteFileSend(req, res, authorized) { const cookie = (authDeprecated)?req.cookies['AccessToken']:req.cookies['openAIRESession']; if (!cookie) { res.status(401).send(getResponse(401, "Unauthorized")); } else { getUserInfo(authorized, req, res, () => { deleteFile('./uploads/' + req.params.filename, res); }); } } function getUserInfo(authorized, req, res, success) { let url = (authDeprecated)?(auth + cookie):auth; http.get(url, {headers: {Cookie: req.header('Cookie')}}, function (resp) { var responseString = ""; resp.on("data", function (data) { responseString += data; }); resp.on("end", function () { var result = JSON.parse(responseString); if (result.error) { res.status(401).send(getResponse(401, "Unauthorized")); } else { if (authorized(result)) { success(); } else { res.status(401).send(getResponse(401, "Unauthorized")); } } }); }); } function getResponse(code, message) { var response = {}; response["code"] = code; response["message"] = message; return response; } function deleteFile(filepath, res = null) { const fs = require('fs'); fs.stat(filepath, function (err, stats) { if (err) { return console.error(err); } try{ fs.unlinkSync(filepath); console.log('file deleted successfully'); if(res) { res.send("File Deleted Successfully"); } } catch (err) { console.error(err); } }); } function mapType(type, communityMap = true) { if(type === 'organization') { return 'institution'; } else if(type === 'ri' && communityMap) { return 'community'; } else { return type; } } function isPortalAdmin(roles) { return roles.includes("PORTAL_ADMINISTRATOR"); } function isAnyCurator(roles) { return roles.filter(role => role.includes("CURATOR_")).length > 0; } function isCurator(type, roles) { return roles.includes("CURATOR_" + mapType(type).toUpperCase()); } function isManager(type, id, roles) { return roles.includes(mapType(type).toUpperCase() + "_" + id.toUpperCase() + "_MANAGER"); }