-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathindex.js
68 lines (58 loc) · 1.82 KB
/
index.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
/* eslint-disable no-undef */
// Environment variables
const dotenv = require("dotenv");
dotenv.config();
const PORT = process.env.PORT || 5000;
// Modules
const bodyParser = require("body-parser");
const session = require("express-session");
// Express
const express = require("express");
const app = express();
app.use(bodyParser.json());
/*
Object.defineProperty(session.Cookie.prototype, 'sameSite', {
// sameSite cannot be set to `None` if cookie is not marked secure
get() {
return this._sameSite === 'none' && !this.secure ? 'lax' : this._sameSite;
},
set(value) {
this._sameSite = value;
}
});
*/
// Session
app.use(session({
secret: process.env.APP_SECRET,
resave: true,
saveUninitialized: true,
cookie: {
httpOnly: true, // empêche l'accès au cookie depuis du javascript côté front
secure: false, // HTTPS est nécessaire si l'on veut passer l'option à true
maxAge: 1000 * 60 * 60 * 24, // durée de vie du cookie en milliseconds, ici ça donne 1 jour
}
})),
// CORS
app.use((req, res, next) => {
// on autorise explicitement le domaine du front
res.header("Access-Control-Allow-Origin", "http://174.129.9.82");
// on autorise le partage du cookie
res.header("Access-Control-Allow-Credentials", true);
// on autorise le partage de ressources entre origines
res.header("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept");
res.header("Access-Control-Allow-Methods", "GET, POST, OPTIONS, PUT, DELETE, PATCH");
next();
});
app.use(express.static('uploads'));
// POST management
app.use(express.urlencoded({extended: true}));
// Sanitizer
const sanitizeData = require("./app/middlewares/sanitizeMiddleware");
app.use( sanitizeData );
// router
const router = require("./app/router");
app.use(router);
// launch server
app.listen( PORT, () => {
console.log(`Listening on ${PORT}`);
});