Ensure bouncer intercepts '/:code' requests
This commit is contained in:
@@ -94,16 +94,18 @@ app.use('/graphql', expressGraphQL(req => ({
|
|||||||
//
|
//
|
||||||
// Register RSVP routes
|
// Register RSVP routes
|
||||||
// -----------------------------------------------------------------------------
|
// -----------------------------------------------------------------------------
|
||||||
//
|
// TODO: This could do with cleaning up, to prevent duplicate bouncer tests and Person queries
|
||||||
|
|
||||||
app.get('/:code', (req, res, next) => {
|
app.get('/:code', bouncer.block, (req, res, next) => {
|
||||||
if (req.params.code.length !== 4) {
|
try {
|
||||||
// Not a password
|
// Hijack router to test if url is a RSVP code
|
||||||
next();
|
if (req.params.code.length === 4) {
|
||||||
} else {
|
// Possibly a password
|
||||||
Person.findAll({ where: { password: req.params.code } })
|
Person.findAll({ where: { password: req.params.code } })
|
||||||
.then(data => {
|
.then(data => {
|
||||||
if (data.length > 0) {
|
if (data.length > 0) {
|
||||||
|
// It is a password
|
||||||
|
bouncer.reset(req);
|
||||||
res.redirect(`/rsvp/${req.params.code}`);
|
res.redirect(`/rsvp/${req.params.code}`);
|
||||||
} else {
|
} else {
|
||||||
next();
|
next();
|
||||||
@@ -112,6 +114,13 @@ app.get('/:code', (req, res, next) => {
|
|||||||
Rollbar.handleError(err);
|
Rollbar.handleError(err);
|
||||||
next(err);
|
next(err);
|
||||||
});
|
});
|
||||||
|
} else {
|
||||||
|
bouncer.reset(req);
|
||||||
|
next();
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
Rollbar.handleError(err);
|
||||||
|
next(err);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user