-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathapp.js
More file actions
78 lines (67 loc) · 1.97 KB
/
app.js
File metadata and controls
78 lines (67 loc) · 1.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
const express = require('express');
const partials = require('express-partials');
const path = require('path');
const sqlite3 = require("sqlite3");
const db = new sqlite3.Database("./db.sqlite");
const app = express();
const csurf = require('csurf');
const cookieParser = require('cookie-parser');
// Require validator:
const validator = require('validator');
const PORT = 4001;
app.set("views", path.join(__dirname, "/views"));
app.set("view engine", "ejs");
app.use(partials());
app.use(cookieParser());
app.set('trust proxy', 1)
app.use(express.json());
app.use(express.urlencoded({extended: true}));
app.use(express.static(path.join(__dirname, "/public")));
const csrfMiddleware = csurf({
cookie: {
maxAge: 300000000,
secure: true,
sameSite: 'none'
}
});
app.use(csrfMiddleware);
const errorMessage = (err, req, res, next) => {
if (err.code === 'EBADCSRFTOKEN'){
res.render('csrfError');
} else {
next();
}
}
app.use(errorMessage)
app.get('/', (req, res) => {
res.render('order', {csrfToken: req.csrfToken()})
})
app.get('/contact', (req, res) => {
res.render('contact', {csrfToken: req.csrfToken()})
})
app.get('/customer', (req, res) => {
res.render('customer', {csrfToken: req.csrfToken()})
})
app.post('/submit', (req, res) => {
res.send(`<p>Post successful!</p> <p>CSRF token used: ${req.body._csrf}</p>`);
});
app.post('/track', (req, res) => {
// Validate form submission is an integer:
if(validator.isInt(req.body.customerId)) {
// Change the query to a prepared statement
db.all(
`SELECT * FROM Employee WHERE EmployeeId = $customerId`, {$customerId: req.body.customerId}, (err, rows) => {
if (rows) {
res.status(200);
res.json(rows);
} else {
res.status(200);
res.json({ message: "No employees" });
}
}
);
} else {
res.json({"message": "Invalid customer ID" });
}
})
app.listen(PORT, () => console.log(`Listening on http://localhost:${PORT}`) );