Ensure bouncer intercepts '/:code' requests

This commit is contained in:
2017-02-13 20:43:54 +00:00
parent a6c6e61b0b
commit 9cae851e3a

View File

@@ -94,16 +94,18 @@ app.use('/graphql', expressGraphQL(req => ({
// //
// Register RSVP routes // Register RSVP routes
// ----------------------------------------------------------------------------- // -----------------------------------------------------------------------------
// // TODO: This could do with cleaning up, to prevent duplicate bouncer tests and Person queries
app.get('/:code', (req, res, next) => { app.get('/:code', bouncer.block, (req, res, next) => {
if (req.params.code.length !== 4) { try {
// Not a password // Hijack router to test if url is a RSVP code
next(); if (req.params.code.length === 4) {
} else { // Possibly a password
Person.findAll({ where: { password: req.params.code } }) Person.findAll({ where: { password: req.params.code } })
.then(data => { .then(data => {
if (data.length > 0) { if (data.length > 0) {
// It is a password
bouncer.reset(req);
res.redirect(`/rsvp/${req.params.code}`); res.redirect(`/rsvp/${req.params.code}`);
} else { } else {
next(); next();
@@ -112,6 +114,13 @@ app.get('/:code', (req, res, next) => {
Rollbar.handleError(err); Rollbar.handleError(err);
next(err); next(err);
}); });
} else {
bouncer.reset(req);
next();
}
} catch (err) {
Rollbar.handleError(err);
next(err);
} }
}); });