mirror of
https://github.com/parse-community/parse-server
synced 2026-08-09 13:03:18 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4a787654d9 | ||
|
|
ef33575811 | ||
|
|
8c8fceec05 | ||
|
|
f04656e828 | ||
|
|
c290070b7d | ||
|
|
373f4f06a6 | ||
|
|
a54828d9f5 | ||
|
|
7ab05372ea | ||
|
|
3d3a97d151 | ||
|
|
c430ee94da | ||
|
|
3c3f1e5365 | ||
|
|
3e46efc2e3 | ||
|
|
89bd2f737f | ||
|
|
adccb2869c | ||
|
|
54e8285577 | ||
|
|
f82122f4a1 | ||
|
|
96609e35d5 | ||
|
|
a78adfe533 | ||
|
|
35b6b16918 | ||
|
|
15edb0cf95 | ||
|
|
8fda77c986 | ||
|
|
044fb52a2f | ||
|
|
fa66ac551f | ||
|
|
52769cce29 | ||
|
|
5d05c742c9 | ||
|
|
ffa7d1b1f1 | ||
|
|
95cea9230b | ||
|
|
97cf00b4d0 | ||
|
|
6b91b98854 | ||
|
|
477a091f88 | ||
|
|
6546610567 | ||
|
|
3978e41f02 | ||
|
|
e3c5ea959f | ||
|
|
e9f82632b7 | ||
|
|
8e1f632e31 | ||
|
|
15ab25940e | ||
|
|
c2373cfe7f | ||
|
|
f9a5255e32 | ||
|
|
4bda6e49e4 | ||
|
|
319179387b | ||
|
|
2008c4dce9 | ||
|
|
05c2246f7b | ||
|
|
a814655b15 | ||
|
|
3f2124410a | ||
|
|
86e42976f9 | ||
|
|
5dc66fd8fa | ||
|
|
5216c93071 | ||
|
|
cb1079a6d3 | ||
|
|
40bfc4ae95 | ||
|
|
7f01a67c0f | ||
|
|
1cddbb0a37 | ||
|
|
6051e3a35c | ||
|
|
18b5a30f1e | ||
|
|
9eb4e4c0e7 | ||
|
|
952ccd4ef3 | ||
|
|
72a956a3cf | ||
|
|
251ec4d701 | ||
|
|
07b0235349 | ||
|
|
956fd0840f | ||
|
|
e8e7f4ba6b | ||
|
|
234c405530 | ||
|
|
1328270014 | ||
|
|
bce6244e31 | ||
|
|
25a0fbeaee | ||
|
|
03302459e2 | ||
|
|
c13b61f07e |
@@ -28,3 +28,6 @@ node_modules
|
||||
|
||||
# Emacs
|
||||
*~
|
||||
|
||||
# WebStorm/IntelliJ
|
||||
.idea
|
||||
@@ -64,6 +64,7 @@ var getAuthForSessionToken = function(config, sessionToken) {
|
||||
var obj = results[0]['user'];
|
||||
delete obj.password;
|
||||
obj['className'] = '_User';
|
||||
obj['sessionToken'] = sessionToken;
|
||||
var userObject = Parse.Object.fromJSON(obj);
|
||||
cache.setUser(sessionToken, userObject);
|
||||
return new Auth(config, false, userObject);
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
### Contributing to Parse Server
|
||||
|
||||
#### Pull Requests Welcome!
|
||||
|
||||
We really want Parse to be yours, to see it grow and thrive in the open source community.
|
||||
|
||||
##### Please Do's
|
||||
|
||||
* Please write tests to cover new methods.
|
||||
* Please run the tests and make sure you didn't break anything.
|
||||
|
||||
##### Code of Conduct
|
||||
|
||||
This project adheres to the [Open Code of Conduct][code-of-conduct]. By participating, you are expected to honor this code.
|
||||
[code-of-conduct]: http://todogroup.org/opencodeofconduct/#Parse Server/fjm@fb.com
|
||||
|
||||
|
||||
+10
-2
@@ -20,6 +20,7 @@ var adapter = ExportAdapter;
|
||||
var cache = require('./cache');
|
||||
var dbConnections = {};
|
||||
var databaseURI = 'mongodb://localhost:27017/parse';
|
||||
var appDatabaseURIs = {};
|
||||
|
||||
function setAdapter(databaseAdapter) {
|
||||
adapter = databaseAdapter;
|
||||
@@ -29,11 +30,17 @@ function setDatabaseURI(uri) {
|
||||
databaseURI = uri;
|
||||
}
|
||||
|
||||
function setAppDatabaseURI(appId, uri) {
|
||||
appDatabaseURIs[appId] = uri;
|
||||
}
|
||||
|
||||
function getDatabaseConnection(appId) {
|
||||
if (dbConnections[appId]) {
|
||||
return dbConnections[appId];
|
||||
}
|
||||
dbConnections[appId] = new adapter(databaseURI, {
|
||||
|
||||
var dbURI = (appDatabaseURIs[appId] ? appDatabaseURIs[appId] : databaseURI);
|
||||
dbConnections[appId] = new adapter(dbURI, {
|
||||
collectionPrefix: cache.apps[appId]['collectionPrefix']
|
||||
});
|
||||
dbConnections[appId].connect();
|
||||
@@ -44,5 +51,6 @@ module.exports = {
|
||||
dbConnections: dbConnections,
|
||||
getDatabaseConnection: getDatabaseConnection,
|
||||
setAdapter: setAdapter,
|
||||
setDatabaseURI: setDatabaseURI
|
||||
setDatabaseURI: setDatabaseURI,
|
||||
setAppDatabaseURI: setAppDatabaseURI
|
||||
};
|
||||
|
||||
+15
-2
@@ -34,8 +34,21 @@ ExportAdapter.prototype.connect = function() {
|
||||
return this.connectionPromise;
|
||||
}
|
||||
|
||||
//http://regexr.com/3cn6m
|
||||
if (!this.mongoURI.match(/^mongodb:\/\/((.+):(.+)@)?([^:@]+):([^:]+)\/(.+?)$/gm)) {
|
||||
throw new Error("Invalid mongoURI: " + this.mongoURI)
|
||||
}
|
||||
var usernameStart = this.mongoURI.indexOf('://') + 3;
|
||||
var lastAtIndex = this.mongoURI.lastIndexOf('@');
|
||||
var encodedMongoURI = this.mongoURI;
|
||||
var split = null;
|
||||
if (lastAtIndex > 0) {
|
||||
split = this.mongoURI.slice(usernameStart, lastAtIndex).split(':');
|
||||
encodedMongoURI = this.mongoURI.slice(0, usernameStart) + encodeURIComponent(split[0]) + ':' + encodeURIComponent(split[1]) + this.mongoURI.slice(lastAtIndex);
|
||||
}
|
||||
|
||||
this.connectionPromise = Promise.resolve().then(() => {
|
||||
return MongoClient.connect(this.mongoURI);
|
||||
return MongoClient.connect(encodedMongoURI, {uri_decode_auth:true});
|
||||
}).then((db) => {
|
||||
this.db = db;
|
||||
});
|
||||
@@ -232,7 +245,7 @@ ExportAdapter.prototype.handleRelationUpdates = function(className,
|
||||
}
|
||||
|
||||
if (op.__op == 'Batch') {
|
||||
for (x of op.ops) {
|
||||
for (var x of op.ops) {
|
||||
process(x, key);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -5,6 +5,7 @@
|
||||
// Adapter classes must implement the following functions:
|
||||
// * create(config, filename, data)
|
||||
// * get(config, filename)
|
||||
// * location(config, req, filename)
|
||||
//
|
||||
// Default is GridStoreAdapter, which requires mongo
|
||||
// and for the API server to be using the ExportAdapter
|
||||
|
||||
+11
-1
@@ -4,6 +4,7 @@
|
||||
// Requires the database adapter to be based on mongoclient
|
||||
|
||||
var GridStore = require('mongodb').GridStore;
|
||||
var path = require('path');
|
||||
|
||||
// For a given config object, filename, and data, store a file
|
||||
// Returns a promise
|
||||
@@ -32,7 +33,16 @@ function get(config, filename) {
|
||||
});
|
||||
}
|
||||
|
||||
// Generates and returns the location of a file stored in GridStore for the
|
||||
// given request and filename
|
||||
function location(config, req, filename) {
|
||||
return (req.protocol + '://' + req.get('host') +
|
||||
path.dirname(req.originalUrl) + '/' + req.config.applicationId +
|
||||
'/' + encodeURIComponent(filename));
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
create: create,
|
||||
get: get
|
||||
get: get,
|
||||
location: location
|
||||
};
|
||||
|
||||
+1
-1
@@ -434,7 +434,7 @@ function includePath(config, auth, response, path) {
|
||||
function findPointers(object, path) {
|
||||
if (object instanceof Array) {
|
||||
var answer = [];
|
||||
for (x of object) {
|
||||
for (var x of object) {
|
||||
answer = answer.concat(findPointers(x, path));
|
||||
}
|
||||
return answer;
|
||||
|
||||
+28
-12
@@ -2,13 +2,14 @@
|
||||
// that writes to the database.
|
||||
// This could be either a "create" or an "update".
|
||||
|
||||
var crypto = require('crypto');
|
||||
var deepcopy = require('deepcopy');
|
||||
var rack = require('hat').rack();
|
||||
|
||||
var Auth = require('./Auth');
|
||||
var cache = require('./cache');
|
||||
var Config = require('./Config');
|
||||
var crypto = require('./crypto');
|
||||
var passwordCrypto = require('./password');
|
||||
var facebook = require('./facebook');
|
||||
var Parse = require('parse/node');
|
||||
var triggers = require('./triggers');
|
||||
@@ -228,6 +229,7 @@ RestWrite.prototype.handleFacebookAuthData = function() {
|
||||
this.className,
|
||||
{'authData.facebook.id': facebookData.id}, {});
|
||||
}).then((results) => {
|
||||
this.storage['authProvider'] = "facebook";
|
||||
if (results.length > 0) {
|
||||
if (!this.query) {
|
||||
// We're signing up, but this user already exists. Short-circuit
|
||||
@@ -236,6 +238,7 @@ RestWrite.prototype.handleFacebookAuthData = function() {
|
||||
response: results[0],
|
||||
location: this.location()
|
||||
};
|
||||
this.data.objectId = results[0].objectId;
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -248,6 +251,8 @@ RestWrite.prototype.handleFacebookAuthData = function() {
|
||||
// We're trying to create a duplicate FB auth. Forbid it
|
||||
throw new Parse.Error(Parse.Error.ACCOUNT_ALREADY_LINKED,
|
||||
'this auth is already used');
|
||||
} else {
|
||||
this.data.username = rack();
|
||||
}
|
||||
|
||||
// This FB auth does not already exist, so transform it to a
|
||||
@@ -261,7 +266,7 @@ RestWrite.prototype.handleFacebookAuthData = function() {
|
||||
|
||||
// The non-third-party parts of User transformation
|
||||
RestWrite.prototype.transformUser = function() {
|
||||
if (this.response || this.className !== '_User') {
|
||||
if (this.className !== '_User') {
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -271,7 +276,8 @@ RestWrite.prototype.transformUser = function() {
|
||||
var token = 'r:' + rack();
|
||||
this.storage['token'] = token;
|
||||
promise = promise.then(() => {
|
||||
// TODO: Proper createdWith options, pass installationId
|
||||
var expiresAt = new Date();
|
||||
expiresAt.setFullYear(expiresAt.getFullYear() + 1);
|
||||
var sessionData = {
|
||||
sessionToken: token,
|
||||
user: {
|
||||
@@ -281,10 +287,15 @@ RestWrite.prototype.transformUser = function() {
|
||||
},
|
||||
createdWith: {
|
||||
'action': 'login',
|
||||
'authProvider': 'password'
|
||||
'authProvider': this.storage['authProvider'] || 'password'
|
||||
},
|
||||
restricted: false
|
||||
restricted: false,
|
||||
installationId: this.data.installationId,
|
||||
expiresAt: Parse._encode(expiresAt)
|
||||
};
|
||||
if (this.response && this.response.response) {
|
||||
this.response.response.sessionToken = token;
|
||||
}
|
||||
var create = new RestWrite(this.config, Auth.master(this.config),
|
||||
'_Session', null, sessionData);
|
||||
return create.execute();
|
||||
@@ -299,7 +310,7 @@ RestWrite.prototype.transformUser = function() {
|
||||
if (this.query) {
|
||||
this.storage['clearSessions'] = true;
|
||||
}
|
||||
return crypto.hash(this.data.password).then((hashedPassword) => {
|
||||
return passwordCrypto.hash(this.data.password).then((hashedPassword) => {
|
||||
this.data._hashed_password = hashedPassword;
|
||||
delete this.data.password;
|
||||
});
|
||||
@@ -361,7 +372,7 @@ RestWrite.prototype.handleFollowup = function() {
|
||||
};
|
||||
delete this.storage['clearSessions'];
|
||||
return this.config.database.destroy('_Session', sessionQuery)
|
||||
.then(this.handleFollowup);
|
||||
.then(this.handleFollowup.bind(this));
|
||||
}
|
||||
};
|
||||
|
||||
@@ -403,6 +414,8 @@ RestWrite.prototype.handleSession = function() {
|
||||
|
||||
if (!this.query && !this.auth.isMaster) {
|
||||
var token = 'r:' + rack();
|
||||
var expiresAt = new Date();
|
||||
expiresAt.setFullYear(expiresAt.getFullYear() + 1);
|
||||
var sessionData = {
|
||||
sessionToken: token,
|
||||
user: {
|
||||
@@ -414,7 +427,7 @@ RestWrite.prototype.handleSession = function() {
|
||||
'action': 'create'
|
||||
},
|
||||
restricted: true,
|
||||
expiresAt: 0
|
||||
expiresAt: Parse._encode(expiresAt)
|
||||
};
|
||||
for (var key in this.data) {
|
||||
if (key == 'objectId') {
|
||||
@@ -701,15 +714,18 @@ RestWrite.prototype.objectId = function() {
|
||||
return this.data.objectId || this.query.objectId;
|
||||
};
|
||||
|
||||
// Returns a string that's usable as an object id.
|
||||
// Probably unique. Good enough? Probably!
|
||||
// Returns a unique string that's usable as an object id.
|
||||
function newObjectId() {
|
||||
var chars = ('ABCDEFGHIJKLMNOPQRSTUVWXYZ' +
|
||||
'abcdefghijklmnopqrstuvwxyz' +
|
||||
'0123456789');
|
||||
var objectId = '';
|
||||
for (var i = 0; i < 10; ++i) {
|
||||
objectId += chars[Math.floor(Math.random() * chars.length)];
|
||||
var bytes = crypto.randomBytes(10);
|
||||
for (var i = 0; i < bytes.length; ++i) {
|
||||
// Note: there is a slight modulo bias, because chars length
|
||||
// of 62 doesn't divide the number of all bytes (256) evenly.
|
||||
// It is acceptable for our purposes.
|
||||
objectId += chars[bytes.readUInt8(i) % chars.length];
|
||||
}
|
||||
return objectId;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,77 @@
|
||||
// S3Adapter
|
||||
//
|
||||
// Stores Parse files in AWS S3.
|
||||
|
||||
var AWS = require('aws-sdk');
|
||||
var path = require('path');
|
||||
|
||||
var DEFAULT_REGION = "us-east-1";
|
||||
var DEFAULT_BUCKET = "parse-files";
|
||||
|
||||
// Creates an S3 session.
|
||||
// Providing AWS access and secret keys is mandatory
|
||||
// Region and bucket will use sane defaults if omitted
|
||||
function S3Adapter(accessKey, secretKey, options) {
|
||||
options = options || {};
|
||||
|
||||
this.region = options.region || DEFAULT_REGION;
|
||||
this.bucket = options.bucket || DEFAULT_BUCKET;
|
||||
this.bucketPrefix = options.bucketPrefix || "";
|
||||
this.directAccess = options.directAccess || false;
|
||||
|
||||
s3Options = {
|
||||
accessKeyId: accessKey,
|
||||
secretAccessKey: secretKey,
|
||||
params: {Bucket: this.bucket}
|
||||
};
|
||||
AWS.config.region = this.region;
|
||||
this.s3 = new AWS.S3(s3Options);
|
||||
}
|
||||
|
||||
// For a given config object, filename, and data, store a file in S3
|
||||
// Returns a promise containing the S3 object creation response
|
||||
S3Adapter.prototype.create = function(config, filename, data) {
|
||||
var params = {
|
||||
Key: this.bucketPrefix + filename,
|
||||
Body: data,
|
||||
};
|
||||
if (this.directAccess) {
|
||||
params.ACL = "public-read"
|
||||
}
|
||||
|
||||
return new Promise((resolve, reject) => {
|
||||
this.s3.upload(params, (err, data) => {
|
||||
if (err !== null) return reject(err);
|
||||
resolve(data);
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
// Search for and return a file if found by filename
|
||||
// Returns a promise that succeeds with the buffer result from S3
|
||||
S3Adapter.prototype.get = function(config, filename) {
|
||||
var params = {Key: this.bucketPrefix + filename};
|
||||
|
||||
return new Promise((resolve, reject) => {
|
||||
this.s3.getObject(params, (err, data) => {
|
||||
if (err !== null) return reject(err);
|
||||
resolve(data.Body);
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
// Generates and returns the location of a file stored in S3 for the given request and
|
||||
// filename
|
||||
// The location is the direct S3 link if the option is set, otherwise we serve
|
||||
// the file through parse-server
|
||||
S3Adapter.prototype.location = function(config, req, filename) {
|
||||
if (this.directAccess) {
|
||||
return ('https://' + this.bucket + '.s3.amazonaws.com' + '/' +
|
||||
this.bucketPrefix + filename);
|
||||
}
|
||||
return (req.protocol + '://' + req.get('host') +
|
||||
path.dirname(req.originalUrl) + '/' + req.config.applicationId +
|
||||
'/' + encodeURIComponent(filename));
|
||||
}
|
||||
|
||||
module.exports = S3Adapter;
|
||||
+27
-14
@@ -10,32 +10,45 @@ var router = new PromiseRouter();
|
||||
|
||||
// Returns a promise that resolves to a {response} object.
|
||||
function handleFind(req) {
|
||||
var body = Object.assign(req.body, req.query);
|
||||
var options = {};
|
||||
if (req.body.skip) {
|
||||
options.skip = Number(req.body.skip);
|
||||
if (body.skip) {
|
||||
options.skip = Number(body.skip);
|
||||
}
|
||||
if (req.body.limit) {
|
||||
options.limit = Number(req.body.limit);
|
||||
if (body.limit) {
|
||||
options.limit = Number(body.limit);
|
||||
}
|
||||
if (req.body.order) {
|
||||
options.order = String(req.body.order);
|
||||
if (body.order) {
|
||||
options.order = String(body.order);
|
||||
}
|
||||
if (req.body.count) {
|
||||
if (body.count) {
|
||||
options.count = true;
|
||||
}
|
||||
if (typeof req.body.keys == 'string') {
|
||||
options.keys = req.body.keys;
|
||||
if (typeof body.keys == 'string') {
|
||||
options.keys = body.keys;
|
||||
}
|
||||
if (req.body.include) {
|
||||
options.include = String(req.body.include);
|
||||
if (body.include) {
|
||||
options.include = String(body.include);
|
||||
}
|
||||
if (req.body.redirectClassNameForKey) {
|
||||
options.redirectClassNameForKey = String(req.body.redirectClassNameForKey);
|
||||
if (body.redirectClassNameForKey) {
|
||||
options.redirectClassNameForKey = String(body.redirectClassNameForKey);
|
||||
}
|
||||
|
||||
if(typeof body.where === 'string') {
|
||||
body.where = JSON.parse(body.where);
|
||||
}
|
||||
|
||||
return rest.find(req.config, req.auth,
|
||||
req.params.className, req.body.where, options)
|
||||
req.params.className, body.where, options)
|
||||
.then((response) => {
|
||||
if (response && response.results) {
|
||||
for (result of response.results) {
|
||||
if (result.sessionToken) {
|
||||
result.sessionToken = req.info.sessionToken || result.sessionToken;
|
||||
}
|
||||
}
|
||||
response.results.sessionToken
|
||||
}
|
||||
return {response: response};
|
||||
});
|
||||
}
|
||||
|
||||
@@ -7,7 +7,6 @@ var bodyParser = require('body-parser'),
|
||||
middlewares = require('./middlewares.js'),
|
||||
mime = require('mime'),
|
||||
Parse = require('parse/node').Parse,
|
||||
path = require('path'),
|
||||
rack = require('hat').rack();
|
||||
|
||||
var router = express.Router();
|
||||
@@ -44,10 +43,7 @@ var processCreate = function(req, res, next) {
|
||||
FilesAdapter.getAdapter().create(req.config, filename, req.body)
|
||||
.then(() => {
|
||||
res.status(201);
|
||||
var location = (req.protocol + '://' + req.get('host') +
|
||||
path.dirname(req.originalUrl) + '/' +
|
||||
req.config.applicationId + '/' +
|
||||
encodeURIComponent(filename));
|
||||
var location = FilesAdapter.getAdapter().location(req.config, req, filename);
|
||||
res.set('Location', location);
|
||||
res.json({ url: location, name: filename });
|
||||
}).catch((error) => {
|
||||
@@ -78,8 +74,8 @@ router.post('/files', function(req, res, next) {
|
||||
'Filename not provided.'));
|
||||
});
|
||||
|
||||
// TODO: do we need to allow crossdomain and method override?
|
||||
router.post('/files/:filename',
|
||||
middlewares.allowCrossDomain,
|
||||
bodyParser.raw({type: '*/*', limit: '20mb'}),
|
||||
middlewares.handleParseHeaders,
|
||||
processCreate);
|
||||
|
||||
+2
-2
@@ -8,12 +8,12 @@ var express = require('express'),
|
||||
var router = new PromiseRouter();
|
||||
|
||||
function handleCloudFunction(req) {
|
||||
// TODO: set user from req.auth
|
||||
if (Parse.Cloud.Functions[req.params.functionName]) {
|
||||
return new Promise(function (resolve, reject) {
|
||||
var response = createResponseObject(resolve, reject);
|
||||
var request = {
|
||||
params: req.body || {}
|
||||
params: req.body || {},
|
||||
user: req.auth && req.auth.user || {}
|
||||
};
|
||||
Parse.Cloud.Functions[req.params.functionName](request, response);
|
||||
});
|
||||
|
||||
@@ -6,6 +6,7 @@ var batch = require('./batch'),
|
||||
DatabaseAdapter = require('./DatabaseAdapter'),
|
||||
express = require('express'),
|
||||
FilesAdapter = require('./FilesAdapter'),
|
||||
S3Adapter = require('./S3Adapter'),
|
||||
middlewares = require('./middlewares'),
|
||||
multer = require('multer'),
|
||||
Parse = require('parse/node').Parse,
|
||||
@@ -23,7 +24,9 @@ addParseCloud();
|
||||
// and delete
|
||||
// "databaseURI": a uri like mongodb://localhost:27017/dbname to tell us
|
||||
// what database this Parse API connects to.
|
||||
// "cloud": relative location to cloud code to require
|
||||
// "cloud": relative location to cloud code to require, or a function
|
||||
// that is given an instance of Parse as a parameter. Use this instance of Parse
|
||||
// to register your cloud code hooks and functions.
|
||||
// "appId": the application id to host
|
||||
// "masterKey": the master key for requests to this app
|
||||
// "facebookAppIds": an array of valid Facebook Application IDs, required
|
||||
@@ -47,11 +50,18 @@ function ParseServer(args) {
|
||||
FilesAdapter.setAdapter(args.filesAdapter);
|
||||
}
|
||||
if (args.databaseURI) {
|
||||
DatabaseAdapter.setDatabaseURI(args.databaseURI);
|
||||
DatabaseAdapter.setAppDatabaseURI(args.appId, args.databaseURI);
|
||||
}
|
||||
if (args.cloud) {
|
||||
addParseCloud();
|
||||
require(args.cloud);
|
||||
if (typeof args.cloud === 'function') {
|
||||
args.cloud(Parse)
|
||||
} else if (typeof args.cloud === 'string') {
|
||||
require(args.cloud);
|
||||
} else {
|
||||
throw "argument 'cloud' must either be a string or a function";
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
cache.apps[args.appId] = {
|
||||
@@ -150,6 +160,9 @@ function addParseCloud() {
|
||||
options.uri = options.url;
|
||||
delete options.url;
|
||||
}
|
||||
if (typeof options.body === 'object') {
|
||||
options.body = JSON.stringify(options.body);
|
||||
}
|
||||
request(options, (error, response, body) => {
|
||||
if (error) {
|
||||
if (callbacks.error) {
|
||||
@@ -176,6 +189,6 @@ function getClassName(parseClass) {
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
ParseServer: ParseServer
|
||||
ParseServer: ParseServer,
|
||||
S3Adapter: S3Adapter
|
||||
};
|
||||
|
||||
|
||||
+5
-3
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "parse-server",
|
||||
"version": "2.0.3",
|
||||
"version": "2.0.5",
|
||||
"description": "An express module providing a Parse-compatible API server",
|
||||
"main": "index.js",
|
||||
"repository": {
|
||||
@@ -9,7 +9,8 @@
|
||||
},
|
||||
"license": "BSD-3-Clause",
|
||||
"dependencies": {
|
||||
"bcrypt": "~0.8",
|
||||
"aws-sdk": "~2.2.33",
|
||||
"bcrypt-nodejs": "0.0.3",
|
||||
"body-parser": "~1.12.4",
|
||||
"deepcopy": "^0.5.0",
|
||||
"express": "~4.2.x",
|
||||
@@ -21,10 +22,11 @@
|
||||
"request": "^2.65.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"istanbul": "^0.4.2",
|
||||
"jasmine": "^2.3.2"
|
||||
},
|
||||
"scripts": {
|
||||
"test": "TESTING=1 jasmine"
|
||||
"test": "TESTING=1 ./node_modules/.bin/istanbul cover --include-all-sources ./node_modules/.bin/jasmine"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=4.1"
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
// Tools for encrypting and decrypting passwords.
|
||||
// Basically promise-friendly wrappers for bcrypt.
|
||||
var bcrypt = require('bcrypt');
|
||||
var bcrypt = require('bcrypt-nodejs');
|
||||
|
||||
// Returns a promise for a hashed password string.
|
||||
function hash(password) {
|
||||
return new Promise(function(fulfill, reject) {
|
||||
bcrypt.hash(password, 8, function(err, hashedPassword) {
|
||||
bcrypt.hash(password, null, null, function(err, hashedPassword) {
|
||||
if (err) {
|
||||
reject(err);
|
||||
} else {
|
||||
+75
-90
@@ -6,7 +6,7 @@
|
||||
// Tests that involve sending password reset emails.
|
||||
|
||||
var request = require('request');
|
||||
var crypto = require('../crypto');
|
||||
var passwordCrypto = require('../password');
|
||||
|
||||
describe('Parse.User testing', () => {
|
||||
it("user sign up class method", (done) => {
|
||||
@@ -78,7 +78,8 @@ describe('Parse.User testing', () => {
|
||||
sessionToken = newUser.getSessionToken();
|
||||
ok(sessionToken);
|
||||
|
||||
Parse.User.logOut();
|
||||
return Parse.User.logOut();
|
||||
}).then(() => {
|
||||
ok(!Parse.User.current());
|
||||
|
||||
return Parse.User.become(sessionToken);
|
||||
@@ -91,7 +92,8 @@ describe('Parse.User testing', () => {
|
||||
equal(newUser.get("username"), "Jason");
|
||||
equal(newUser.get("code"), "red");
|
||||
|
||||
Parse.User.logOut();
|
||||
return Parse.User.logOut();
|
||||
}).then(() => {
|
||||
ok(!Parse.User.current());
|
||||
|
||||
return Parse.User.become("somegarbage");
|
||||
@@ -236,22 +238,20 @@ describe('Parse.User testing', () => {
|
||||
user.set("password", "asdf");
|
||||
user.set("email", "asdf@example.com");
|
||||
user.set("username", "zxcv");
|
||||
user.signUp(null, {
|
||||
success: function() {
|
||||
var currentUser = Parse.User.current();
|
||||
equal(user.id, currentUser.id);
|
||||
ok(user.getSessionToken());
|
||||
user.signUp().then(() => {
|
||||
var currentUser = Parse.User.current();
|
||||
equal(user.id, currentUser.id);
|
||||
ok(user.getSessionToken());
|
||||
|
||||
var currentUserAgain = Parse.User.current();
|
||||
// should be the same object
|
||||
equal(currentUser, currentUserAgain);
|
||||
var currentUserAgain = Parse.User.current();
|
||||
// should be the same object
|
||||
equal(currentUser, currentUserAgain);
|
||||
|
||||
// test logging out the current user
|
||||
Parse.User.logOut();
|
||||
|
||||
equal(Parse.User.current(), null);
|
||||
done();
|
||||
}
|
||||
// test logging out the current user
|
||||
return Parse.User.logOut();
|
||||
}).then(() => {
|
||||
equal(Parse.User.current(), null);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
@@ -268,50 +268,39 @@ describe('Parse.User testing', () => {
|
||||
user2.set("password", "password");
|
||||
user3.set("password", "password");
|
||||
|
||||
user1.signUp(null, {
|
||||
success: function () {
|
||||
equal(user1.isCurrent(), true);
|
||||
equal(user2.isCurrent(), false);
|
||||
equal(user3.isCurrent(), false);
|
||||
user2.signUp(null, {
|
||||
success: function() {
|
||||
equal(user1.isCurrent(), false);
|
||||
equal(user2.isCurrent(), true);
|
||||
equal(user3.isCurrent(), false);
|
||||
user3.signUp(null, {
|
||||
success: function() {
|
||||
equal(user1.isCurrent(), false);
|
||||
equal(user2.isCurrent(), false);
|
||||
equal(user3.isCurrent(), true);
|
||||
Parse.User.logIn("a", "password", {
|
||||
success: function(user1) {
|
||||
equal(user1.isCurrent(), true);
|
||||
equal(user2.isCurrent(), false);
|
||||
equal(user3.isCurrent(), false);
|
||||
Parse.User.logIn("b", "password", {
|
||||
success: function(user2) {
|
||||
equal(user1.isCurrent(), false);
|
||||
equal(user2.isCurrent(), true);
|
||||
equal(user3.isCurrent(), false);
|
||||
Parse.User.logIn("b", "password", {
|
||||
success: function(user3) {
|
||||
equal(user1.isCurrent(), false);
|
||||
equal(user2.isCurrent(), true);
|
||||
equal(user3.isCurrent(), true);
|
||||
Parse.User.logOut();
|
||||
equal(user3.isCurrent(), false);
|
||||
done();
|
||||
}
|
||||
});
|
||||
}
|
||||
});
|
||||
}
|
||||
});
|
||||
}
|
||||
});
|
||||
}
|
||||
});
|
||||
}
|
||||
user1.signUp().then(() => {
|
||||
equal(user1.isCurrent(), true);
|
||||
equal(user2.isCurrent(), false);
|
||||
equal(user3.isCurrent(), false);
|
||||
return user2.signUp();
|
||||
}).then(() => {
|
||||
equal(user1.isCurrent(), false);
|
||||
equal(user2.isCurrent(), true);
|
||||
equal(user3.isCurrent(), false);
|
||||
return user3.signUp();
|
||||
}).then(() => {
|
||||
equal(user1.isCurrent(), false);
|
||||
equal(user2.isCurrent(), false);
|
||||
equal(user3.isCurrent(), true);
|
||||
return Parse.User.logIn("a", "password");
|
||||
}).then(() => {
|
||||
equal(user1.isCurrent(), true);
|
||||
equal(user2.isCurrent(), false);
|
||||
equal(user3.isCurrent(), false);
|
||||
return Parse.User.logIn("b", "password");
|
||||
}).then(() => {
|
||||
equal(user1.isCurrent(), false);
|
||||
equal(user2.isCurrent(), true);
|
||||
equal(user3.isCurrent(), false);
|
||||
return Parse.User.logIn("b", "password");
|
||||
}).then(() => {
|
||||
equal(user1.isCurrent(), false);
|
||||
equal(user2.isCurrent(), true);
|
||||
equal(user3.isCurrent(), false);
|
||||
return Parse.User.logOut();
|
||||
}).then(() => {
|
||||
equal(user2.isCurrent(), false);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
@@ -589,28 +578,24 @@ describe('Parse.User testing', () => {
|
||||
|
||||
|
||||
it("user loaded from localStorage from login", (done) => {
|
||||
var id;
|
||||
Parse.User.signUp("alice", "password").then((alice) => {
|
||||
id = alice.id;
|
||||
return Parse.User.logOut();
|
||||
}).then(() => {
|
||||
return Parse.User.logIn("alice", "password");
|
||||
}).then((user) => {
|
||||
// Force the current user to read from disk
|
||||
delete Parse.User._currentUser;
|
||||
delete Parse.User._currentUserMatchesDisk;
|
||||
|
||||
Parse.User.signUp("alice", "password", null, {
|
||||
success: function(alice) {
|
||||
var id = alice.id;
|
||||
Parse.User.logOut();
|
||||
|
||||
Parse.User.logIn("alice", "password", {
|
||||
success: function(user) {
|
||||
// Force the current user to read from disk
|
||||
delete Parse.User._currentUser;
|
||||
delete Parse.User._currentUserMatchesDisk;
|
||||
|
||||
var userFromDisk = Parse.User.current();
|
||||
equal(userFromDisk.get("password"), undefined,
|
||||
"password should not be in attributes");
|
||||
equal(userFromDisk.id, id, "id should be set");
|
||||
ok(userFromDisk.getSessionToken(),
|
||||
"currentUser should have a sessionToken");
|
||||
done();
|
||||
}
|
||||
});
|
||||
}
|
||||
var userFromDisk = Parse.User.current();
|
||||
equal(userFromDisk.get("password"), undefined,
|
||||
"password should not be in attributes");
|
||||
equal(userFromDisk.id, id, "id should be set");
|
||||
ok(userFromDisk.getSessionToken(),
|
||||
"currentUser should have a sessionToken");
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
@@ -620,8 +605,8 @@ describe('Parse.User testing', () => {
|
||||
|
||||
Parse.User.signUp("alice", "password", null).then(function(alice) {
|
||||
id = alice.id;
|
||||
Parse.User.logOut();
|
||||
|
||||
return Parse.User.logOut();
|
||||
}).then(() => {
|
||||
return Parse.User.logIn("alice", "password");
|
||||
}).then(function() {
|
||||
// Simulate browser refresh by force-reloading user from localStorage
|
||||
@@ -1311,8 +1296,8 @@ describe('Parse.User testing', () => {
|
||||
return Parse.User.signUp("finn", "human", { foo: "bar" });
|
||||
|
||||
}).then(function() {
|
||||
Parse.User.logOut();
|
||||
|
||||
return Parse.User.logOut();
|
||||
}).then(() => {
|
||||
var user = new Parse.User();
|
||||
user.set("username", "jake");
|
||||
user.set("password", "dog");
|
||||
@@ -1320,8 +1305,8 @@ describe('Parse.User testing', () => {
|
||||
return user.signUp();
|
||||
|
||||
}).then(function() {
|
||||
Parse.User.logOut();
|
||||
|
||||
return Parse.User.logOut();
|
||||
}).then(() => {
|
||||
var query = new Parse.Query(Parse.User);
|
||||
return query.find();
|
||||
|
||||
@@ -1560,7 +1545,7 @@ describe('Parse.User testing', () => {
|
||||
|
||||
it('password format matches hosted parse', (done) => {
|
||||
var hashed = '$2a$10$8/wZJyEuiEaobBBqzTG.jeY.XSFJd0rzaN//ososvEI4yLqI.4aie';
|
||||
crypto.compare('test', hashed)
|
||||
passwordCrypto.compare('test', hashed)
|
||||
.then((pass) => {
|
||||
expect(pass).toBe(true);
|
||||
done();
|
||||
@@ -1574,7 +1559,7 @@ describe('Parse.User testing', () => {
|
||||
var sessionToken = null;
|
||||
|
||||
Parse.Promise.as().then(function() {
|
||||
return Parse.User.signUp("fosco", "parse");
|
||||
return Parse.User.signUp("fosco", "parse");
|
||||
}).then(function(newUser) {
|
||||
equal(Parse.User.current(), newUser);
|
||||
sessionToken = newUser.getSessionToken();
|
||||
|
||||
+4
-5
@@ -1,6 +1,6 @@
|
||||
// Sets up a Parse API server for testing.
|
||||
|
||||
jasmine.DEFAULT_TIMEOUT_INTERVAL = 1000;
|
||||
jasmine.DEFAULT_TIMEOUT_INTERVAL = 2000;
|
||||
|
||||
var cache = require('../cache');
|
||||
var DatabaseAdapter = require('../DatabaseAdapter');
|
||||
@@ -46,8 +46,7 @@ beforeEach(function(done) {
|
||||
});
|
||||
|
||||
afterEach(function(done) {
|
||||
Parse.User.logOut();
|
||||
Parse.Promise.as().then(() => {
|
||||
Parse.User.logOut().then(() => {
|
||||
return clearData();
|
||||
}).then(() => {
|
||||
done();
|
||||
@@ -153,7 +152,7 @@ function normalize(obj) {
|
||||
return '[' + obj.map(normalize).join(', ') + ']';
|
||||
}
|
||||
var answer = '{';
|
||||
for (key of Object.keys(obj).sort()) {
|
||||
for (var key of Object.keys(obj).sort()) {
|
||||
answer += key + ': ';
|
||||
answer += normalize(obj[key]);
|
||||
answer += ', ';
|
||||
@@ -192,7 +191,7 @@ function mockFacebook() {
|
||||
|
||||
function clearData() {
|
||||
var promises = [];
|
||||
for (conn in DatabaseAdapter.dbConnections) {
|
||||
for (var conn in DatabaseAdapter.dbConnections) {
|
||||
promises.push(DatabaseAdapter.dbConnections[conn].deleteEverything());
|
||||
}
|
||||
return Promise.all(promises);
|
||||
|
||||
+54
-16
@@ -2,16 +2,18 @@
|
||||
|
||||
var transform = require('../transform');
|
||||
|
||||
var dummyConfig = {
|
||||
schema: {
|
||||
var dummySchema = {
|
||||
data: {},
|
||||
getExpectedType: function(className, key) {
|
||||
if (key == 'userPointer') {
|
||||
return '*_User';
|
||||
} else if (key == 'picture') {
|
||||
return 'file';
|
||||
} else if (key == 'location') {
|
||||
return 'geopoint';
|
||||
}
|
||||
return;
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
|
||||
@@ -19,7 +21,7 @@ describe('transformCreate', () => {
|
||||
|
||||
it('a basic number', (done) => {
|
||||
var input = {five: 5};
|
||||
var output = transform.transformCreate(dummyConfig, null, input);
|
||||
var output = transform.transformCreate(dummySchema, null, input);
|
||||
jequal(input, output);
|
||||
done();
|
||||
});
|
||||
@@ -29,7 +31,7 @@ describe('transformCreate', () => {
|
||||
createdAt: "2015-10-06T21:24:50.332Z",
|
||||
updatedAt: "2015-10-06T21:24:50.332Z"
|
||||
};
|
||||
var output = transform.transformCreate(dummyConfig, null, input);
|
||||
var output = transform.transformCreate(dummySchema, null, input);
|
||||
expect(output._created_at instanceof Date).toBe(true);
|
||||
expect(output._updated_at instanceof Date).toBe(true);
|
||||
done();
|
||||
@@ -41,21 +43,21 @@ describe('transformCreate', () => {
|
||||
objectId: 'myId',
|
||||
className: 'Blah',
|
||||
};
|
||||
var out = transform.transformCreate(dummyConfig, null, {pointers: [pointer]});
|
||||
var out = transform.transformCreate(dummySchema, null, {pointers: [pointer]});
|
||||
jequal([pointer], out.pointers);
|
||||
done();
|
||||
});
|
||||
|
||||
it('a delete op', (done) => {
|
||||
var input = {deleteMe: {__op: 'Delete'}};
|
||||
var output = transform.transformCreate(dummyConfig, null, input);
|
||||
var output = transform.transformCreate(dummySchema, null, input);
|
||||
jequal(output, {});
|
||||
done();
|
||||
});
|
||||
|
||||
it('basic ACL', (done) => {
|
||||
var input = {ACL: {'0123': {'read': true, 'write': true}}};
|
||||
var output = transform.transformCreate(dummyConfig, null, input);
|
||||
var output = transform.transformCreate(dummySchema, null, input);
|
||||
// This just checks that it doesn't crash, but it should check format.
|
||||
done();
|
||||
});
|
||||
@@ -63,7 +65,7 @@ describe('transformCreate', () => {
|
||||
|
||||
describe('transformWhere', () => {
|
||||
it('objectId', (done) => {
|
||||
var out = transform.transformWhere(dummyConfig, null, {objectId: 'foo'});
|
||||
var out = transform.transformWhere(dummySchema, null, {objectId: 'foo'});
|
||||
expect(out._id).toEqual('foo');
|
||||
done();
|
||||
});
|
||||
@@ -72,7 +74,7 @@ describe('transformWhere', () => {
|
||||
var input = {
|
||||
objectId: {'$in': ['one', 'two', 'three']},
|
||||
};
|
||||
var output = transform.transformWhere(dummyConfig, null, input);
|
||||
var output = transform.transformWhere(dummySchema, null, input);
|
||||
jequal(input.objectId, output._id);
|
||||
done();
|
||||
});
|
||||
@@ -81,17 +83,53 @@ describe('transformWhere', () => {
|
||||
describe('untransformObject', () => {
|
||||
it('built-in timestamps', (done) => {
|
||||
var input = {createdAt: new Date(), updatedAt: new Date()};
|
||||
var output = transform.untransformObject(dummyConfig, null, input);
|
||||
var output = transform.untransformObject(dummySchema, null, input);
|
||||
expect(typeof output.createdAt).toEqual('string');
|
||||
expect(typeof output.updatedAt).toEqual('string');
|
||||
done();
|
||||
});
|
||||
|
||||
it('pointer', (done) => {
|
||||
var input = {_p_userPointer: '_User$123'};
|
||||
var output = transform.untransformObject(dummySchema, null, input);
|
||||
expect(typeof output.userPointer).toEqual('object');
|
||||
expect(output.userPointer).toEqual(
|
||||
{__type: 'Pointer', className: '_User', objectId: '123'}
|
||||
);
|
||||
done();
|
||||
});
|
||||
|
||||
it('null pointer', (done) => {
|
||||
var input = {_p_userPointer: null};
|
||||
var output = transform.untransformObject(dummySchema, null, input);
|
||||
expect(output.userPointer).toBeUndefined();
|
||||
done();
|
||||
});
|
||||
|
||||
it('file', (done) => {
|
||||
var input = {picture: 'pic.jpg'};
|
||||
var output = transform.untransformObject(dummySchema, null, input);
|
||||
expect(typeof output.picture).toEqual('object');
|
||||
expect(output.picture).toEqual({__type: 'File', name: 'pic.jpg'});
|
||||
done();
|
||||
});
|
||||
|
||||
it('geopoint', (done) => {
|
||||
var input = {location: [180, -180]};
|
||||
var output = transform.untransformObject(dummySchema, null, input);
|
||||
expect(typeof output.location).toEqual('object');
|
||||
expect(output.location).toEqual(
|
||||
{__type: 'GeoPoint', longitude: 180, latitude: -180}
|
||||
);
|
||||
done();
|
||||
});
|
||||
|
||||
});
|
||||
|
||||
describe('transformKey', () => {
|
||||
it('throws out _password', (done) => {
|
||||
try {
|
||||
transform.transformKey(dummyConfig, '_User', '_password');
|
||||
transform.transformKey(dummySchema, '_User', '_password');
|
||||
fail('should have thrown');
|
||||
} catch (e) {
|
||||
done();
|
||||
@@ -105,7 +143,7 @@ describe('transform schema key changes', () => {
|
||||
var input = {
|
||||
somePointer: {__type: 'Pointer', className: 'Micro', objectId: 'oft'}
|
||||
};
|
||||
var output = transform.transformCreate(dummyConfig, null, input);
|
||||
var output = transform.transformCreate(dummySchema, null, input);
|
||||
expect(typeof output._p_somePointer).toEqual('string');
|
||||
expect(output._p_somePointer).toEqual('Micro$oft');
|
||||
done();
|
||||
@@ -115,7 +153,7 @@ describe('transform schema key changes', () => {
|
||||
var input = {
|
||||
userPointer: {__type: 'Pointer', className: '_User', objectId: 'qwerty'}
|
||||
};
|
||||
var output = transform.transformCreate(dummyConfig, null, input);
|
||||
var output = transform.transformCreate(dummySchema, null, input);
|
||||
expect(typeof output._p_userPointer).toEqual('string');
|
||||
expect(output._p_userPointer).toEqual('_User$qwerty');
|
||||
done();
|
||||
@@ -128,7 +166,7 @@ describe('transform schema key changes', () => {
|
||||
"Kevin": { "write": true }
|
||||
}
|
||||
};
|
||||
var output = transform.transformCreate(dummyConfig, null, input);
|
||||
var output = transform.transformCreate(dummySchema, null, input);
|
||||
expect(typeof output._rperm).toEqual('object');
|
||||
expect(typeof output._wperm).toEqual('object');
|
||||
expect(output.ACL).toBeUndefined();
|
||||
@@ -142,7 +180,7 @@ describe('transform schema key changes', () => {
|
||||
_rperm: ["*"],
|
||||
_wperm: ["Kevin"]
|
||||
};
|
||||
var output = transform.untransformObject(dummyConfig, null, input);
|
||||
var output = transform.untransformObject(dummySchema, null, input);
|
||||
expect(typeof output.ACL).toEqual('object');
|
||||
expect(output._rperm).toBeUndefined();
|
||||
expect(output._wperm).toBeUndefined();
|
||||
|
||||
+7
-2
@@ -48,7 +48,7 @@ function transformKeyValue(schema, className, restKey, restValue, options) {
|
||||
break;
|
||||
case 'expiresAt':
|
||||
case '_expiresAt':
|
||||
key = '_expiresAt';
|
||||
key = 'expiresAt';
|
||||
timeField = true;
|
||||
break;
|
||||
case '_rperm':
|
||||
@@ -676,6 +676,9 @@ function untransformObject(schema, className, mongoObject) {
|
||||
console.log('Found a pointer in a non-pointer column, dropping it.', className, key);
|
||||
break;
|
||||
}
|
||||
if (mongoObject[key] === null) {
|
||||
break;
|
||||
}
|
||||
var objData = mongoObject[key].split('$');
|
||||
var newClass = (expected ? expected.substring(1) : objData[0]);
|
||||
if (objData[0] !== newClass) {
|
||||
@@ -689,9 +692,11 @@ function untransformObject(schema, className, mongoObject) {
|
||||
break;
|
||||
} else if (key[0] == '_' && key != '__type') {
|
||||
throw ('bad key in untransform: ' + key);
|
||||
//} else if (mongoObject[key] === null) {
|
||||
//break;
|
||||
} else {
|
||||
var expected = schema.getExpectedType(className, key);
|
||||
if (expected == 'file') {
|
||||
if (expected == 'file' && mongoObject[key]) {
|
||||
restObject[key] = {
|
||||
__type: 'File',
|
||||
name: mongoObject[key]
|
||||
|
||||
@@ -5,18 +5,21 @@ var Parse = require('parse/node').Parse;
|
||||
var rack = require('hat').rack();
|
||||
|
||||
var Auth = require('./Auth');
|
||||
var crypto = require('./crypto');
|
||||
var passwordCrypto = require('./password');
|
||||
var facebook = require('./facebook');
|
||||
var PromiseRouter = require('./PromiseRouter');
|
||||
var rest = require('./rest');
|
||||
var RestWrite = require('./RestWrite');
|
||||
var deepcopy = require('deepcopy');
|
||||
|
||||
var router = new PromiseRouter();
|
||||
|
||||
// Returns a promise for a {status, response, location} object.
|
||||
function handleCreate(req) {
|
||||
var data = deepcopy(req.body);
|
||||
data.installationId = req.info.installationId;
|
||||
return rest.create(req.config, req.auth,
|
||||
'_User', req.body);
|
||||
'_User', data);
|
||||
}
|
||||
|
||||
// Returns a promise for a {response} object.
|
||||
@@ -45,7 +48,7 @@ function handleLogIn(req) {
|
||||
'Invalid username/password.');
|
||||
}
|
||||
user = results[0];
|
||||
return crypto.compare(req.body.password, user.password);
|
||||
return passwordCrypto.compare(req.body.password, user.password);
|
||||
}).then((correct) => {
|
||||
if (!correct) {
|
||||
throw new Parse.Error(Parse.Error.OBJECT_NOT_FOUND,
|
||||
@@ -70,9 +73,13 @@ function handleLogIn(req) {
|
||||
'authProvider': 'password'
|
||||
},
|
||||
restricted: false,
|
||||
expiresAt: Parse._encode(expiresAt).iso,
|
||||
installationId: req.info.installationId
|
||||
expiresAt: Parse._encode(expiresAt)
|
||||
};
|
||||
|
||||
if (req.info.installationId) {
|
||||
sessionData.installationId = req.info.installationId
|
||||
}
|
||||
|
||||
var create = new RestWrite(req.config, Auth.master(req.config),
|
||||
'_Session', null, sessionData);
|
||||
return create.execute();
|
||||
@@ -157,6 +164,22 @@ function handleDelete(req) {
|
||||
});
|
||||
}
|
||||
|
||||
function handleLogOut(req) {
|
||||
var success = {response: {}};
|
||||
if (req.info && req.info.sessionToken) {
|
||||
rest.find(req.config, Auth.master(req.config), '_Session',
|
||||
{_session_token: req.info.sessionToken}
|
||||
).then((records) => {
|
||||
if (records.results && records.results.length) {
|
||||
rest.del(req.config, Auth.master(req.config), '_Session',
|
||||
records.results[0].id
|
||||
);
|
||||
}
|
||||
});
|
||||
}
|
||||
return Promise.resolve(success);
|
||||
}
|
||||
|
||||
function handleUpdate(req) {
|
||||
return rest.update(req.config, req.auth, '_User',
|
||||
req.params.objectId, req.body)
|
||||
@@ -172,6 +195,7 @@ function notImplementedYet(req) {
|
||||
|
||||
router.route('POST', '/users', handleCreate);
|
||||
router.route('GET', '/login', handleLogIn);
|
||||
router.route('POST', '/logout', handleLogOut);
|
||||
router.route('GET', '/users/me', handleMe);
|
||||
router.route('GET', '/users/:objectId', handleGet);
|
||||
router.route('PUT', '/users/:objectId', handleUpdate);
|
||||
|
||||
Reference in New Issue
Block a user