Giter VIP home page Giter VIP logo

cboard-api's Issues

Logger for cboard-api

I don't have enough knowledge in order to provide details here. Open to suggestions for everyone that wants to collaborate.

As a non-admin user, I shouldn't be able to update another user

The updateUser route is available to both admin and regular users. However, regular users are able to update any user and any field. This means that they can give themselves the admin role, take away another admin's privileges, change someone's email address, etc. This is a critical issue.

Acceptance criteria

  • A non-admin user gets a 403 if they try to update another user.
  • We can only update a subset of fields. Additional properties are simply ignored. Currently, the frontend only supports updating name, email, and birthdate.

I should be able to change my email without losing access to my data

The schemas for communicators and boards currently use the email field to identify the owner. This is problematic because a user loses access to their communicators and boards if they change their email address. A simple solution would be to update the documents when needed, but it would be preferable to use a stable identifier like the user id.

Suggested approach

  • Add a userId field to the Communicator and Board schemas. Migrate existing documents.
  • Update the listCommunicators and listBoards routes to only return the caller's communicators and boards. The user id should be taken from the token rather than passed explicitly by the caller. The frontend would need to be updated to use these routes instead of the /byemail versions.
  • Update the getCommunicatorsEmail and getBoardsEmail routes to return a 403 if a non-admin user sends the wrong email address. There would be no restriction for admins. Ideally we would only let admins call the routes, but we need to do this so that users with an older version of the app don't have to update.

@martinbedouret Does this make sense?

Session secret hard-coded into app.js?

Hi! I was just looking throughapp.js and noticed the following in it, around line 29:

  //use sessions for tracking logins
  app.use(
    session({
      secret: 'work hard',
      resave: true,
      saveUninitialized: false,
      store: new MongoStore({
        mongooseConnection: db
      })
    })
  );

The session secret is hard-coded to 'work hard'... I'm not sure what the full scope of your user sessions is, but I'm curious if this could lead to any kind of security vulnerabilities. Either way, it might be useful to either change (e.g. by pulling the secret from an environment variable) or document in a comment!

Update status attribute on subscriber

When a subscription is validated, the status attribute on subscriber controller is not beeing updated. The value, that status will have its the same than transaction.subscriptionState

image

Development of unit tests for the user controller

The goal is to develop a new suite of unit tests to check the following controller:
cboard-api\api\controllers\user.js
Use the following test suite as an example of what we have to do:
cboard-api\test\controllers\board.js

Check the Readme file to understand how to run the unit tests.
Here you have a tutorial on how to develop nodejs and express unit tests: https://medium.com/@ehtemam/writing-test-with-supertest-and-mocha-for-expressjs-routes-555d2910d2c2

Update code to write all config info under env/ path

We want to have following structure for config:

-- config
---- env
--------development.js
--------production.js
--------xxxx.js
---- index.js

Any env value should be available in code by doing:

var config = require('./config');
var value = config.anyConfigValue

And server must be run using the right env variable:

NODE_ENV=production swagger project start

Obtain the geolocation of users

Get geolocation of users and send it to cboard API.

RESOURCES

based on these Articles:
https://www.softwaretestinghelp.com/best-ip-geolocation-api/
https://stackoverflow.com/a/35123097
Consider the uses of the following resources:

  1. https://www.geoplugin.com
    prices to get SSL: https://www.geoplugin.com/webservices/ssl

๐Ÿ‘

  • Free Acces without a token.
  • High precision of city.

๐Ÿ‘Ž

  • No SSL connection without a paid account
  1. https://geolocation-db.com

๐Ÿ‘

  • Free Acces without a token.
  • SSL connection without a paid account

๐Ÿ‘Ž

  • Low precision of city.
  1. https://ipdata.co/
    prices: https://ipdata.co/pricing.html

๐Ÿ‘

  • 1500 free requests daily with a token. (should be stored on API)
  • SSL connection with a free account
  • High precision of city.

๐Ÿ‘Ž

  • is necessary a token that should be stored on our API.
  1. https://ip-api.com/
    Commercial use prices https://members.ip-api.com/#pricing

๐Ÿ‘

  • 1500 free requests daily with a token. (should be stored on API)
  • SSL connection with a free account
  • High precision of city.

๐Ÿ‘Ž

  • Non-commercial use for free.
  • No SSL connection without a paid account.

When should store data?

-Should store the location when a Cboard user creates a new account.
-In the case that users that already have accounts should evaluate when make the requests.
Consider checking if the location is available at a login moment. Compare if it is available to make the request or not

As a non-admin user, I shouldn't be able to delete another user's board

The deleteBoard route currently allows callers to delete boards owned by another user, even if the caller is not an admin.

Acceptance criteria

  • A non-admin user gets a 404 if they try to delete another user's board.
  • An admin can delete any board.
  • The tests added in #174 are not skipped and are passing.

it's possible change a password without owning the account.

it's possible to change the password of any account only with post an email on user/forgot and using the id of the user on user/store-password
image
Not only that, when post to /user/forgot endpoint is sending the private token in the response.
image

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.