-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathapp.js
More file actions
157 lines (130 loc) · 3.81 KB
/
app.js
File metadata and controls
157 lines (130 loc) · 3.81 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
const path = require('path');
const express = require('express');
const morgan = require('morgan');
const rateLimit = require('express-rate-limit');
const helmet = require('helmet');
//const mongoSanitize = require('express-mongo-sanitize');
const xss = require('xss-clean');
const hpp = require('hpp');
const session = require('express-session');
const cookieParser = require('cookie-parser');
const bodyParser = require('body-parser');
const compression = require('compression');
const cors = require('cors');
const AppError = require('./utils/appError');
const globalErrorHandler = require('./controllers/errorController');
const tourRouter = require('./routes/tourRoutes');
const userRouter = require('./routes/userRoutes');
const reviewRouter = require('./routes/reviewRoutes');
const viewRouter = require('./routes/viewRoutes');
const bookingRouter = require('./routes/bookingRoutes');
const bookingController = require('./controllers/bookingController');
const app = express();
app.enable('trust proxy');
app.use(
cors({
origin: '*',
method: ['GET', 'POST'],
credentials: true,
})
);
app.options('*', cors());
app.set('view engine', 'pug');
app.set('views', path.join(__dirname, 'views'));
// 1) GLOBAL MIDDLEWARE
// Serving static files
app.use(express.static(path.join(__dirname, 'public')));
// Set security HTTP headers
app.use(helmet());
// Development logging0
if (process.env.NODE_ENV === 'development') {
//console.log(process.env.NODE_ENV)
app.use(morgan('dev'));
}
// Limit request from same API
const limiter = rateLimit({
max: 100,
windowMs: 60 * 60 * 1000,
message: 'Too many request from this IP, please try again in an hour!',
});
app.use('/api', limiter);
app.post(
'/webhook-checkout',
bodyParser.raw({ type: 'application/json' }),
bookingController.webhookCheckout
);
// app.post(
// '/webhook-checkout',
// express.raw({ type: 'application/json' }),
// bookingController.webhookCheckout
// );
// Body parer, reading data from body info req.body
app.use(express.json({ limit: '10kb' }));
app.use(express.urlencoded({ extended: true, limit: '10kb' }));
app.use(cookieParser());
const sessionConfig = {
secret: process.env.JWT_SECRET,
name: 'natours',
saveUninitialized: false,
resave: false,
cookie: {
sameSite: 'none',
secure: true,
},
};
if (process.env.NODE_ENV === 'production') {
app.set('trust proxy', 1);
sessionConfig.cookie.secure = true;
}
app.use(session(sessionConfig));
// Data sanitization against NoSQL query injection
//app.use(mongoSanitize());
// Data sanitization against XSS
app.use(
xss({
whitelist: [
'duration',
'ratingsAverage',
'ratingsQuantity',
'maxGroupSize',
'difficulty',
'price',
],
})
);
app.use(compression());
// Prevent paramter pollution
app.use(hpp());
// Test middleware
app.use((req, res, next) => {
req.requestTime = new Date().toISOString();
//console.log(req.headers);
//console.log(req.cookies);
next();
});
// 3) ROUTES
app.use('/', viewRouter);
app.use('/api/v1/tours', tourRouter);
app.use('/api/v1/users', userRouter);
app.use('/api/v1/reviews', reviewRouter);
app.use('/api/v1/bookings', bookingRouter);
app.all('*', (req, res, next) => {
next(new AppError(`Can't find ${req.originalUrl} on this server!`, 404));
// res.status(404).json({
// status: 'fail',
// message: `Can't find ${req.originalUrl} on this server!`,
// });
// next();
// const err = new Error(`Can't find ${req.originalUrl} on this server!`);
// err.status = 'fail';
// err.statusCode = 404;
// next(err);
});
app.use(globalErrorHandler);
// 4) SERVER
module.exports = app;
// app.get('/api/v1/tours', getAllTours);
// app.get('/api/v1/tours/:id', getTour);
// app.get('/api/v1/tours', createTour);
// app.patch('/api/v1/tours/:id', updateTour)
// app.delete('/api/v1/tours/:id', deleteTour)