Archived
2
This repository has been archived on 2023-03-02. You can view files and clone it, but cannot push or open issues or pull requests.
definma-api/src/index.ts

139 lines
3.7 KiB
TypeScript
Raw Normal View History

2020-01-14 13:25:13 +01:00
import express from 'express';
import bodyParser from 'body-parser';
2020-06-05 10:51:03 +02:00
import compression from 'compression';
2020-04-23 13:59:45 +02:00
import contentFilter from 'content-filter';
2020-06-05 10:51:03 +02:00
import helmet from 'helmet';
2020-07-09 13:48:27 +02:00
import cors from 'cors';
2020-05-12 14:05:47 +02:00
import api from './api';
import db from './db';
2020-08-07 08:37:25 +02:00
import Mail from './helpers/mail';
2020-01-14 13:25:13 +01:00
// tell if server is running in debug or production environment
2020-08-04 13:54:14 +02:00
console.info(process.env.NODE_ENV === 'production' ?
'===== PRODUCTION =====' : process.env.NODE_ENV === 'test' ? '' :'===== DEVELOPMENT =====');
2020-01-14 13:25:13 +01:00
// mongodb connection
db.connect();
2020-04-20 16:17:43 +02:00
2020-08-07 08:37:25 +02:00
// mail service
Mail.init();
2020-01-14 13:25:13 +01:00
// create Express app
const app = express();
// get port from environment, defaults to 3000
const port = process.env.PORT || 3000;
// security headers
2020-07-28 13:59:13 +02:00
const defaultHeaderConfig = {
contentSecurityPolicy: {
directives: {
defaultSrc: [`'none'`],
baseUri: [`'self'`],
formAction: [`'none'`],
frameAncestors: [`'none'`]
}
2020-07-28 13:59:13 +02:00
},
frameguard: {
action: 'deny'
},
permittedCrossDomainPolicies: true,
refererPolicy: true
};
app.use(helmet(defaultHeaderConfig));
// special CSP header for api-doc
app.use('/api-doc', helmet.contentSecurityPolicy({
2020-07-28 13:59:13 +02:00
...defaultHeaderConfig,
directives: {
2020-07-30 11:36:03 +02:00
defaultSrc: [`'none'`],
scriptSrc: [`'self'`],
connectSrc: [`'self'`],
styleSrc: [`'self'`, `'unsafe-inline'`],
2020-07-28 13:59:13 +02:00
imgSrc: [`'self'`, 'data:']
}
}));
2020-08-07 15:21:16 +02:00
// special CSP header for the intro-presentation
2020-08-09 17:25:32 +02:00
app.use(/\/static\/intro-presentation\/(index.html)?/, helmet.contentSecurityPolicy({
2020-08-07 15:21:16 +02:00
...defaultHeaderConfig,
directives: {
defaultSrc: [`'none'`],
scriptSrc: [`'self'`, `'unsafe-inline'`],
styleSrc: [`'self'`, `'unsafe-inline'`],
imgSrc: [`'self'`]
}
}));
// special CSP header for the bosch-logo.svg
2020-08-07 15:21:16 +02:00
app.use('/static/*.svg', helmet.contentSecurityPolicy({
2020-07-28 13:59:13 +02:00
...defaultHeaderConfig,
directives: {
styleSrc: [`'unsafe-inline'`]
}
}));
// middleware
2020-08-04 13:54:14 +02:00
app.use(compression()); // compress responses
app.use(express.json({ limit: '5mb'}));
app.use(express.urlencoded({ extended: false, limit: '5mb' }));
app.use(bodyParser.json());
2020-08-04 13:54:14 +02:00
app.use(contentFilter({
urlBlackList: ['$', '&&', '||'],
bodyBlackList: ['$', '{', '&&', '||'],
appendFound: true
2020-08-04 13:54:14 +02:00
})); // filter URL query attacks
app.use((err, req, res, ignore) => { // bodyParser error handling
res.status(400).send({status: 'Invalid JSON body'});
});
2020-04-23 13:59:45 +02:00
app.use((req, res, next) => { // no database connection error
if (db.getState().db) {
next();
}
else {
2020-07-09 13:48:27 +02:00
console.error('No database connection');
2020-04-23 13:59:45 +02:00
res.status(500).send({status: 'Internal server error'});
}
});
2020-07-09 13:48:27 +02:00
app.use(cors()); // CORS headers
2020-04-23 13:59:45 +02:00
app.use(require('./helpers/authorize')); // handle authentication
// redirect /api routes for Angular proxy in development
if (process.env.NODE_ENV !== 'production') {
2020-06-29 15:50:24 +02:00
app.use('/api/:url([^]+)', (req, res) => {
req.url = '/' + req.params.url;
2020-06-29 15:50:24 +02:00
app.handle(req, res);
});
}
2020-01-14 13:25:13 +01:00
// require routes
app.use('/', require('./routes/root'));
app.use('/', require('./routes/sample'));
app.use('/', require('./routes/material'));
2020-08-13 12:07:40 +02:00
app.use('/', require('./routes/measurement'));
app.use('/', require('./routes/template'));
2020-08-13 12:07:40 +02:00
app.use('/', require('./routes/model'));
app.use('/', require('./routes/user'));
2020-01-14 13:25:13 +01:00
2020-04-29 15:07:07 +02:00
// static files
app.use('/static', express.static('static'));
2020-01-14 13:25:13 +01:00
// Swagger UI
app.use('/api-doc', api());
2020-01-14 13:25:13 +01:00
app.use((req, res) => { // 404 error handling
res.status(404).json({status: 'Not found'});
});
app.use((err, req, res, ignore) => { // internal server error handling
console.error(err);
res.status(500).json({status: 'Internal server error'});
});
2020-01-14 13:25:13 +01:00
// hook up server to port
const server = app.listen(port, () => {
2020-05-07 21:55:29 +02:00
console.info(process.env.NODE_ENV === 'test' ? '' : `Listening on http://localhost:${port}`);
2020-01-14 13:25:13 +01:00
});
module.exports = server;