panel/app.moon

99 lines
2.6 KiB
Plaintext
Raw Normal View History

2015-01-05 21:41:19 +00:00
lapis = require "lapis"
db = require "lapis.db"
csrf = require "lapis.csrf"
2015-01-05 22:22:26 +00:00
encoding = require "lapis.util.encoding"
2015-01-05 21:41:19 +00:00
2015-01-05 22:22:26 +00:00
import capture_errors from require "lapis.application"
import assert_valid from require "lapis.validate"
2015-01-05 21:41:19 +00:00
import respond_to from require "lapis.application"
2015-01-05 22:51:12 +00:00
require "models.user"
2015-01-05 21:41:19 +00:00
class App extends lapis.Application
2015-01-06 03:09:03 +00:00
[index: "/"]: =>
@user = @session.user
render: true
2015-01-05 21:41:19 +00:00
2015-01-05 23:08:29 +00:00
[list: "/list"]: =>
user = Users\find id: @session.user
@list = Users\select!
render: true
2015-01-05 22:22:26 +00:00
[register: "/register"]: capture_errors respond_to {
2015-01-05 21:41:19 +00:00
GET: =>
2015-01-05 22:22:26 +00:00
@csrf_token = csrf.generate_token @
render: true
2015-01-05 21:41:19 +00:00
POST: =>
csrf.assert_token @
2015-01-05 22:22:26 +00:00
assert_valid @params, {
{ "email", exists: true, min_length: 3 }
{ "password", exists: true, min_length: 3 }
{ "password_again", equals: @params.password }
{ "name", exists: true, min_length: 3}
}
@params.password = encoding.encode_base64 encoding.hmac_sha1("ninjas", @params.password)
@params.password_again = nil
@params.csrf_token = nil
@params.extension = "9001"
2015-01-07 16:42:49 +00:00
@params.registrar_password = encoding.encode_base64 encoding.hmac_sha1(@params.email, os.time!)
2015-01-05 22:22:26 +00:00
if Users\find email: @params.email
2015-01-07 17:10:16 +00:00
@title = "Failure"
2015-01-06 03:09:03 +00:00
return status: 500, "User with that email already exists"
2015-01-05 22:22:26 +00:00
user = Users\create @params
2015-01-05 22:51:12 +00:00
user\write_session @
2015-01-05 22:22:26 +00:00
2015-01-07 17:10:16 +00:00
@title = "Success"
@html ->
h1 "Success"
p ->
text "Your email is " .. user.email
p ->
text "Your extension is " .. user.id
p ->
text "Your sip password is "
code user.registrar_password
p "This will not be shown again so please be sure to write this down."
2015-01-05 22:22:26 +00:00
}
[login: "/login"]: capture_errors respond_to {
GET: =>
@csrf_token = csrf.generate_token @
render: true
POST: =>
csrf.assert_token @
assert_valid @params, {
{ "email", exists: true, min_length: 3 }
{ "password", exists: true, min_length: 3 }
}
user = Users\find email: @params.email
2015-01-05 22:51:12 +00:00
cmppass = encoding.encode_base64 encoding.hmac_sha1("ninjas", @params.password)
if user.password == cmppass
user\write_session @
2015-01-07 17:10:16 +00:00
@title = "Login successful"
2015-01-05 22:51:12 +00:00
return "Hi " .. user.name
else
2015-01-07 17:10:16 +00:00
@title = "Login failure"
2015-01-05 22:51:12 +00:00
return status: 500, "bad password"
2015-01-05 21:41:19 +00:00
}
2015-01-07 16:42:49 +00:00
[freeswitch: "/freeswitch"]: respond_to {
POST: =>
uid = @params["user"] or @params["sip_auth_username"]
@user = Users\find id: uid
render: true, layout: false
}