limit logout function to logged in users

This commit is contained in:
2020-05-15 23:21:47 +02:00
parent ab7b2d907d
commit babc2c8ea8

View File

@@ -165,12 +165,7 @@ app.post("/API/user/login", passport.authenticate('local-login'), function (req,
return res.status(status.OK).send("login success"); return res.status(status.OK).send("login success");
}); });
app.delete("/API/user/logout", function (req, res) { app.put("/API/user/create", function (req, res) {
req.logout();
return res.status(status.OK).send("logout success");
}); !!
app.put("/API/user/create", function (req, res) {
let { email, password } = req.body; let { email, password } = req.body;
if (email && password) { if (email && password) {
email = mysql.escape(email); email = mysql.escape(email);
@@ -184,7 +179,7 @@ app.delete("/API/user/logout", function (req, res) {
} else { } else {
return res.status(status.BAD_REQUEST).send("invalid data supplied"); return res.status(status.BAD_REQUEST).send("invalid data supplied");
} }
}); });
app.all("*", function (req, res, next) { app.all("*", function (req, res, next) {
if (req.isAuthenticated()) { if (req.isAuthenticated()) {
@@ -199,6 +194,11 @@ app.get("/API/testlogin", function (req, res) {
return res.status(status.OK).send(req.user["email"]); return res.status(status.OK).send(req.user["email"]);
}); });
app.delete("/API/user/logout", function (req, res) {
req.logout();
return res.status(status.OK).send("logout success");
});
app.get('/API/day', function (req, res) { app.get('/API/day', function (req, res) {
const kind = parseInt(req.query.kind); const kind = parseInt(req.query.kind);
if (Number.isInteger(kind)) { if (Number.isInteger(kind)) {