token validation changes

This commit is contained in:
mrfry 2023-04-02 14:29:14 +02:00
parent 9194593fa3
commit f13636ce1a

View file

@ -318,15 +318,16 @@ function setup(data: SubmoduleData): Submodule {
logger.LogReq(req)
const user: User = req.session.user
const { token, userid } = req.query
const isQueryValid = validateuuid(token) && !Number.isNaN(+userid)
if (validateuuid(token) && !Number.isNaN(+userid)) {
if (isQueryValid) {
const specifiedUser = dbtools.Select(userDB, 'users', {
id: +userid,
})
if (specifiedUser.length === 0) {
res.json({
result: 'error',
result: 'nouser',
msg: 'couldnt find user',
})
}
@ -340,14 +341,17 @@ function setup(data: SubmoduleData): Submodule {
} else {
if (!user) {
res.json({
result: 'error',
msg: 'you are not logged in',
result: 'invalid',
msg: isQueryValid
? 'you are not logged in'
: 'token or user id is not valid',
})
return
}
const key = v5(validationTokenName, user.pw)
res.json({
result: 'success',
result: 'newtoken',
key: key,
...((token || userid) && {
msg: 'userid or token was provided, but was invalid',