|
2 | 2 | // jshint node: true |
3 | 3 | "use strict"; |
4 | 4 |
|
| 5 | +const jwt = require("jsonwebtoken"); |
| 6 | +const mongoose = require("mongoose"); |
| 7 | +const User = require("../models/user"); // Passe Pfad |
5 | 8 |
|
6 | | -const request = require('request'); |
| 9 | +const userAuthorization = async (req, res, next) => { |
| 10 | + const authHeader = req.headers.authorization; |
7 | 11 |
|
| 12 | + if (!authHeader || !authHeader.startsWith("Bearer ")) { |
| 13 | + return res.status(401).json({ message: "No token provided." }); |
| 14 | + } |
8 | 15 |
|
9 | | -const userAuthorization = function(req, res, next){ |
10 | | - var options = { |
11 | | - headers: { |
12 | | - 'Content-type': 'application/json', |
13 | | - 'Authorization': req.header('authorization') |
| 16 | + const token = authHeader.split(" ")[1]; |
| 17 | + |
| 18 | + try { |
| 19 | + // 🔍 Versuche zuerst, das Token als **native JWT** zu verifizieren |
| 20 | + const decoded = jwt.verify(token, process.env.JWT_SECRET); |
| 21 | + |
| 22 | + // Hole Nutzer aus deiner DB |
| 23 | + const user = await User.findOne({ |
| 24 | + _id: decoded.id, |
| 25 | + authProvider: "native", |
| 26 | + }); |
| 27 | + if (user) { |
| 28 | + req.user = user; |
| 29 | + return next(); |
14 | 30 | } |
| 31 | + // Wenn kein nativer Nutzer gefunden → falle zu openSenseMap zurück |
| 32 | + } catch (jwtError) { |
| 33 | + // Token ist kein gültiges natives JWT → weiter mit openSenseMap |
| 34 | + } |
| 35 | + |
| 36 | + // 🔁 Fallback: openSenseMap-Auth (wie bisher) |
| 37 | + const options = { |
| 38 | + headers: { |
| 39 | + "Content-Type": "application/json", |
| 40 | + Authorization: authHeader, |
| 41 | + }, |
15 | 42 | }; |
16 | | - request.get('https://api.opensensemap.org/users/me', options) |
17 | | - .on('response', function(response) { |
18 | | - // concatenate updates from datastream |
19 | | - var body = ''; |
20 | | - response.on('data', function(chunk){ |
21 | | - body += chunk; |
22 | | - }); |
23 | | - response.on('end', async function(){ |
24 | | - if(response.statusCode !== 200){ |
25 | | - return res.status(401).send({ |
26 | | - message: 'Unauthorized', |
27 | | - }); |
| 43 | + |
| 44 | + const { get } = require("request"); |
| 45 | + get("https://api.opensensemap.org/users/me", options) |
| 46 | + .on("response", function (response) { |
| 47 | + let body = ""; |
| 48 | + response.on("data", (chunk) => (body += chunk)); |
| 49 | + response.on("end", () => { |
| 50 | + if (response.statusCode !== 200) { |
| 51 | + return res.status(401).json({ message: "Unauthorized" }); |
| 52 | + } |
| 53 | + try { |
| 54 | + const osemUser = JSON.parse(body).data.me; |
| 55 | + // Optional: Nutzer in deiner DB anlegen/aktualisieren |
| 56 | + req.user = osemUser; |
| 57 | + next(); |
| 58 | + } catch (e) { |
| 59 | + return res |
| 60 | + .status(401) |
| 61 | + .json({ message: "Invalid openSenseMap response" }); |
28 | 62 | } |
29 | | - req.user = JSON.parse(body).data.me; |
30 | | - next(); |
31 | 63 | }); |
32 | 64 | }) |
33 | | - .on('error', function(err) { |
34 | | - return res.status(401).send({ |
35 | | - message: 'Unauthorized', |
36 | | - }); |
| 65 | + .on("error", () => { |
| 66 | + return res.status(401).json({ message: "openSenseMap unreachable" }); |
37 | 67 | }); |
38 | 68 | }; |
39 | 69 |
|
40 | | - |
41 | 70 | module.exports = { |
42 | | - userAuthorization |
| 71 | + userAuthorization, |
43 | 72 | }; |
0 commit comments