3 Commits

Author SHA1 Message Date
34696a1fc8 Added user management 2025-10-04 13:40:30 +02:00
a197d9bd3b Bump version to 1.0.2 2025-10-03 11:41:58 +02:00
91cdc9e08a Updated login 2025-10-03 11:41:30 +02:00
10 changed files with 340 additions and 48 deletions

5
.gitignore vendored
View File

@@ -138,3 +138,8 @@ dist
# Vite logs files # Vite logs files
vite.config.js.timestamp-* vite.config.js.timestamp-*
vite.config.ts.timestamp-* vite.config.ts.timestamp-*
# user files
/responses

View File

@@ -4,9 +4,11 @@ import express from "express";
import expressWs from "express-ws"; import expressWs from "express-ws";
import morgan from "morgan"; import morgan from "morgan";
import cookieParser from "cookie-parser"; import cookieParser from "cookie-parser";
import cors from "cors";
import { initWebsocket } from "./src/websocket.js"; import { initWebsocket } from "./src/websocket.js";
import { initAuth } from "./src/auth.js"; import { initAuth } from "./src/auth.js";
import { close as closeDbConnection, initDbConnection, db } from "./src/db.js"; import { close as closeDbConnection, initDbConnection, db } from "./src/db.js";
import { initUsers } from "./src/user.js";
const app = express(); const app = express();
const appWs = expressWs(app); const appWs = expressWs(app);
const port = 12345; const port = 12345;
@@ -17,6 +19,7 @@ process.on('exit', function() {
closeDbConnection(); closeDbConnection();
}); });
app.use(cors({credentials: true, origin: process.env.JEOPARDY_URL}));
app.use(morgan(process.env.production ? 'common' : 'dev')); app.use(morgan(process.env.production ? 'common' : 'dev'));
app.use(express.json()); app.use(express.json());
app.use(cookieParser()); app.use(cookieParser());
@@ -24,6 +27,7 @@ app.use(cookieParser());
await initDbConnection(); await initDbConnection();
initAuth(app, db); initAuth(app, db);
initUsers(app, db);
initWebsocket(app); initWebsocket(app);
app.listen(port, () => { app.listen(port, () => {

27
package-lock.json generated
View File

@@ -1,16 +1,17 @@
{ {
"name": "jeopardyserver", "name": "jeopardyserver",
"version": "1.0.1", "version": "1.0.3",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "jeopardyserver", "name": "jeopardyserver",
"version": "1.0.1", "version": "1.0.3",
"license": "ISC", "license": "ISC",
"dependencies": { "dependencies": {
"@types/express": "^5.0.3", "@types/express": "^5.0.3",
"cookie-parser": "^1.4.7", "cookie-parser": "^1.4.7",
"cors": "^2.8.5",
"dotenv": "^17.2.3", "dotenv": "^17.2.3",
"express": "^5.1.0", "express": "^5.1.0",
"express-ws": "^5.0.2", "express-ws": "^5.0.2",
@@ -298,6 +299,19 @@
"node": ">=6.6.0" "node": ">=6.6.0"
} }
}, },
"node_modules/cors": {
"version": "2.8.5",
"resolved": "https://registry.npmjs.org/cors/-/cors-2.8.5.tgz",
"integrity": "sha512-KIHbLJqu73RGr/hnbrO9uBeixNGuvSQjul/jdFvS/KFSIH1hWVd1ng7zOHx+YrEfInLG7q4n6GHQ9cDtxv/P6g==",
"license": "MIT",
"dependencies": {
"object-assign": "^4",
"vary": "^1"
},
"engines": {
"node": ">= 0.10"
}
},
"node_modules/debug": { "node_modules/debug": {
"version": "4.4.3", "version": "4.4.3",
"resolved": "https://registry.npmjs.org/debug/-/debug-4.4.3.tgz", "resolved": "https://registry.npmjs.org/debug/-/debug-4.4.3.tgz",
@@ -834,6 +848,15 @@
"node": ">= 0.6" "node": ">= 0.6"
} }
}, },
"node_modules/object-assign": {
"version": "4.1.1",
"resolved": "https://registry.npmjs.org/object-assign/-/object-assign-4.1.1.tgz",
"integrity": "sha512-rJgTQnkUnH1sFw8yT6VSU3zD3sWmu6sZhIseY8VX+GRu3P6F7Fu+JNDoXfklElbLJSnc3FUQHVe4cU5hj+BcUg==",
"license": "MIT",
"engines": {
"node": ">=0.10.0"
}
},
"node_modules/object-inspect": { "node_modules/object-inspect": {
"version": "1.13.4", "version": "1.13.4",
"resolved": "https://registry.npmjs.org/object-inspect/-/object-inspect-1.13.4.tgz", "resolved": "https://registry.npmjs.org/object-inspect/-/object-inspect-1.13.4.tgz",

View File

@@ -1,6 +1,6 @@
{ {
"name": "jeopardyserver", "name": "jeopardyserver",
"version": "1.0.1", "version": "1.0.3",
"description": "", "description": "",
"license": "ISC", "license": "ISC",
"author": "", "author": "",
@@ -13,6 +13,7 @@
"dependencies": { "dependencies": {
"@types/express": "^5.0.3", "@types/express": "^5.0.3",
"cookie-parser": "^1.4.7", "cookie-parser": "^1.4.7",
"cors": "^2.8.5",
"dotenv": "^17.2.3", "dotenv": "^17.2.3",
"express": "^5.1.0", "express": "^5.1.0",
"express-ws": "^5.0.2", "express-ws": "^5.0.2",

View File

@@ -6,5 +6,9 @@ content-type: application/json
{ {
"username": "jonas", "username": "jonas",
"password": "kappa" "password": "paula"
} }
###
GET {{url}}/auth HTTP/1.1

45
requests/user.http Normal file
View File

@@ -0,0 +1,45 @@
@url = http://{{host}}:{{port}}
PUT {{url}}/admin/user HTTP/1.1
Content-Type: application/json
{
"username": "Paula"
}
###
GET {{url}}/admin/user/list HTTP/1.1
###
POST {{url}}/admin/user/resetpw HTTP/1.1
Content-Type: application/json
{
"userid": "68e1058faf78b3aabbdfe8dc"
}
###
GET {{url}}/admin/roles HTTP/1.1
###
POST {{url}}/admin/user/changerole HTTP/1.1
Content-Type: application/json
{
"userid": "68e0efc6e4ac740114d8fc9d",
"role": "default"
}
###
POST {{url}}/user/changepw HTTP/1.1
Content-Type: application/json
{
"old": "DkgnWspm4To2ww==",
"new": "Kolata"
}

View File

@@ -1,16 +1,29 @@
import { createHash, pbkdf2Sync, randomBytes } from "node:crypto"; import { createUser, generateHash, updateSessionToken } from "./userHelper.js";
let db; let db;
let users; let users;
export function initAuth(app, db) { export function initAuth(app, db) {
app.use(checkSessionToken); app.use(checkSessionToken);
app.use('/admin', checkAuthorization('admin'));
users = db.collection('users'); users = db.collection('users');
app.get('/auth', getUserInfo);
app.post('/auth/login', loginUser); app.post('/auth/login', loginUser);
} }
async function getUserInfo(req, res) {
const sessiontoken = await updateSessionToken(users, req.user._id);
setTokenCookie(res, sessiontoken);
res.status(200).send({
username: req.user.username,
role: req.user.role,
_id: req.user._id
});
}
async function checkSessionToken(req, res, next) { async function checkSessionToken(req, res, next) {
if (req.path.startsWith("/auth/")) { if (req.path.startsWith("/auth/")) {
next(); next();
return; return;
@@ -27,80 +40,75 @@ async function checkSessionToken(req, res, next) {
req.user = { req.user = {
role: user.role, role: user.role,
username: user.username username: user.username,
_id: user._id
} }
next(); next();
} }
function checkAuthorization(role) {
return (req, res, next) => {
if (req.user === undefined) {
res.status(403).send();
return;
}
if (req.user.role === role) {
next();
} else {
res.status(403).send();
}
}
}
async function loginUser(req, res) { async function loginUser(req, res) {
const username = req.body.username; const username = req.body.username;
const password = req.body.password; const password = req.body.password;
let userCount = await users.estimatedDocumentCount(); let userCount = await users.estimatedDocumentCount();
let sessiontoken = null; let userobj = null;
if (userCount <= 0) { if (userCount <= 0) {
// create first user // create first user
sessiontoken = await createUser(username, password, 'admin'); userobj = await createUser(users, username, password, 'admin', true);
} else { } else {
// authenticate user // authenticate user
sessiontoken = await authenticateUser(username, password); userobj = await authenticateUser(username, password);
} }
if (sessiontoken !== null) { if (userobj !== null) {
const expires = new Date(); setTokenCookie(res, userobj.sessiontoken);
expires.setDate(expires.getDate() + 1);
res.cookie('jeopardytoken', sessiontoken, { res.status(200).send({username: userobj.username, role: userobj.role, _id: userobj._id});
maxAge: 1e3 * 60 * 60 * 24
})
res.status(200).send(username);
} else { } else {
res.sendStatus(403); res.sendStatus(403);
} }
} }
async function createUser(username, password, role) { export async function authenticateUser(username, password, updateSession = true) {
const salt = randomBytes(128).toString('base64');
const iterations = Math.floor(Math.random() * 5000) + 5000;
const hash = generateHash(password, salt, iterations);
const sessiontoken = generateSessionToken();
await users.insertOne({
username,
role,
salt,
iterations,
hash,
sessiontoken
});
return sessiontoken;
}
async function authenticateUser(username, password) {
let foundUser = await users.findOne({username}); let foundUser = await users.findOne({username});
if (foundUser === null) return null; if (foundUser === null) return null;
const hash = generateHash(password, foundUser.salt, foundUser.iterations); const hash = generateHash(password, foundUser.salt, foundUser.iterations);
if (hash === foundUser.hash) { if (hash === foundUser.hash) {
const sessiontoken = generateSessionToken(); if (updateSession) {
await users.updateOne({_id: foundUser._id}, {$set: { let sessiontoken = await updateSessionToken(users, foundUser._id);
sessiontoken return {sessiontoken, username, role: foundUser.role, _id: foundUser._id};
}}); } else {
return sessiontoken; return {sessiontoken: foundUser.sessiontoken, username, role: foundUser.role, _id: foundUser._id};
}
} }
return null; return null;
} }
function generateSessionToken() { function setTokenCookie(res, sessiontoken) {
return randomBytes(128).toString('base64'); const expires = new Date();
} expires.setDate(expires.getDate() + 1);
function generateHash(password, salt, iterations) { res.cookie('jeopardytoken', sessiontoken, {
return pbkdf2Sync(password, salt, iterations, 128, 'sha512').toString('hex'); maxAge: 1e3 * 60 * 60 * 24,
path: "/"
})
} }

12
src/roles.js Normal file
View File

@@ -0,0 +1,12 @@
export const roles = [
"admin",
"default"
]
/**
*
* @param {string} newrole
*/
export function isValidRole(newrole) {
return roles.includes(newrole);
}

114
src/user.js Normal file
View File

@@ -0,0 +1,114 @@
import { ObjectId } from "mongodb";
import { createUser as userHelperCreateUser, generateSessionToken, updatePassword, userExists } from "./userHelper.js";
import { isValidRole, roles } from "./roles.js";
import { authenticateUser } from "./auth.js";
let db;
let users;
export function initUsers(app, db) {
users = db.collection('users');
app.put('/admin/user', createUser);
app.get('/admin/user/list', userlist);
app.post('/admin/user/resetpw', resetpassword);
app.post('/admin/user/changerole', changerole);
app.get('/admin/roles', getRoles);
app.post('/user/changepw', changePassword);
}
async function createUser(req, res) {
const username = req.body.username;
// check if user exists
let foundUser = await users.findOne({username});
if (foundUser !== null) {
res.status(400).send();
return;
}
const password = generateSessionToken(10);
const userobj = await userHelperCreateUser(users, username, password, 'default', false);
res.status(200).send({
username: userobj.username,
role: userobj.role,
_id: userobj._id,
password
});
}
async function userlist(req, res) {
const result = await users.find().project({
username: 1,
role: 1
}).toArray();
res.status(200).send(result);
}
async function resetpassword(req, res) {
/** @type {string} */
const userid = req.body.userid;
const _id = new ObjectId(userid);
const foundUser = userExists(res, users, _id);
if (foundUser === null) return;
const password = generateSessionToken(10);
await updatePassword(users, _id, password, false);
res.status(200).send({
_id: userid,
username: foundUser.username,
role: foundUser.role,
password
});
}
async function changerole(req, res) {
/** @type {string} */
const userid = req.body.userid;
const _id = new ObjectId(userid);
const newrole = req.body.role;
if (!isValidRole(newrole)) {
res.status(400).send();
return;
}
const foundUser = await userExists(res, users, _id);
if (foundUser === null) return;
await users.updateOne({_id}, {
$set: {
role: newrole
}
});
res.status(200).send({
_id,
username: foundUser.username,
role: newrole
});
}
function getRoles(req, res) {
res.status(200).send(roles);
}
async function changePassword(req, res) {
const oldpassword = req.body.old;
const newpassword = req.body.new;
const userobj = await authenticateUser(req.user.username, oldpassword, false);
if (userobj === null) {
res.status(400).send();
return;
}
await updatePassword(users, req.user._id, newpassword, false);
res.status(200).send();
}

76
src/userHelper.js Normal file
View File

@@ -0,0 +1,76 @@
import { pbkdf2Sync, randomBytes } from "node:crypto";
export async function createUser(collection, username, password, role, withSession = true) {
const {salt, iterations, hash} = createHash(password);
let sessiontoken = "";
if (withSession) {
sessiontoken = generateSessionToken();
}
const result = await collection.insertOne({
username,
role,
salt,
iterations,
hash,
sessiontoken
});
return {sessiontoken, username, role, _id: result.insertedId};
}
export async function updatePassword(collection, _id, password, keepSession = true) {
const {salt, iterations, hash} = createHash(password);
if (keepSession) {
await collection.updateOne({_id}, {$set: {
salt,
iterations,
hash
}});
} else {
await collection.updateOne({_id}, {$set: {
salt,
iterations,
hash,
sessiontoken: ""
}});
}
}
export function generateSessionToken(length = 128, encoding = 'base64') {
return randomBytes(length).toString(encoding);
}
export function generateHash(password, salt, iterations) {
return pbkdf2Sync(password, salt, iterations, 128, 'sha512').toString('hex');
}
export async function updateSessionToken(collection, _id) {
const sessiontoken = generateSessionToken();
await collection.updateOne({_id: _id}, {$set: {
sessiontoken
}});
return sessiontoken;
}
export async function userExists(res, collection, _id) {
const foundUser = await collection.findOne({_id});
if (foundUser === null) {
res.status(400).send();
}
return foundUser;
}
function createHash(password) {
const salt = randomBytes(128).toString('base64');
const iterations = Math.floor(Math.random() * 5000) + 5000;
const hash = generateHash(password, salt, iterations);
return {
salt, hash, iterations
}
}