added hashing on api calls

This commit is contained in:
2022-07-12 12:49:26 +01:00
parent f23ad2a300
commit be9f86b6b2
13 changed files with 234 additions and 158 deletions
+18 -4
View File
@@ -6,6 +6,7 @@ import {
uploadFile,
deleteBlob,
} from "../../../actions/azurestorage";
import { hashAPIPath } from "../../../actions";
import middleware from "../middleware/middleware";
import nextConnect from "next-connect";
@@ -16,11 +17,24 @@ ApiProxy.use(middleware);
ApiProxy.get(async (req, res) => {
var containerName = req.query.container;
var blobName = req.query.blobname;
console.log(containerName, blobName);
var checkHash = req.query.hash;
await deleteBlob(containerName, "files/" + blobName).then((data) => {
return res.status(200).json({ data: data });
});
var checkquerypath =
"/api/file/deleteblob?container=" +
containerName.toLowerCase() +
"&blobname=" +
blobName;
console.log(hashAPIPath(checkquerypath), checkHash);
console.log(hashAPIPath(checkquerypath) == "&hash=" + checkHash);
if (hashAPIPath(checkquerypath) == "&hash=" + checkHash) {
await deleteBlob(containerName, "files/" + blobName).then((data) => {
return res.status(200).json({ data: data });
});
} else {
return res.status(400).json();
}
});
export const config = {
-12
View File
@@ -37,18 +37,6 @@ ApiProxy.get(async (req, res) => {
"&blobname=" +
blobName;
console.log(
"containerName " +
containerName +
`\n` +
blobName +
`\n` +
checkHash +
`\n` +
checkquerypath
);
console.log(hashAPIPath(checkquerypath), checkHash);
console.log(hashAPIPath(checkquerypath) == "&hash=" + checkHash);
if (hashAPIPath(checkquerypath) == "&hash=" + checkHash) {
const downloaded = await downloadFile(containerName, blobName);
+14 -4
View File
@@ -5,6 +5,7 @@ import {
createBlob,
uploadFile,
} from "../../../actions/azurestorage";
import { hashAPIPath } from "../../../actions";
import middleware from "../middleware/middleware";
import nextConnect from "next-connect";
@@ -14,10 +15,19 @@ ApiProxy.use(middleware);
ApiProxy.get(async (req, res) => {
var containerName = req.query.container;
console.log(containerName);
await getBlobs(containerName).then((data) => {
return res.status(200).json({ files: data });
});
var checkHash = req.query.hash;
var checkquerypath = "/api/file/getbloblist?container=" + containerName;
console.log(hashAPIPath(checkquerypath), checkHash);
console.log(hashAPIPath(checkquerypath) == "&hash=" + checkHash);
if (hashAPIPath(checkquerypath) == "&hash=" + checkHash) {
await getBlobs(containerName).then((data) => {
return res.status(200).json({ files: data });
});
} else {
return res.status(400).json();
}
});
export const config = {
+10
View File
@@ -13,11 +13,18 @@ const ApiProxy = nextConnect();
ApiProxy.use(middleware);
ApiProxy.post(async (req, res) => {
var checkHash = req.query.hash;
console.log(JSON.parse(req.body.appealData));
console.log(req.files);
const appealData = JSON.parse(req.body.appealData);
// var checkquerypath = "/api/file/upload";
// console.log(hashAPIPath(checkquerypath), checkHash);
// console.log(hashAPIPath(checkquerypath) == "?hash=" + checkHash);
// if (hashAPIPath(checkquerypath) == "?hash=" + checkHash) {
createContainer(appealData.pinswg_name.trim()).then((containerName) => {
createBlob(appealData, containerName).then((data) => {
uploadFile(req.files, containerName, data);
@@ -25,6 +32,9 @@ ApiProxy.post(async (req, res) => {
});
return res.status(200).json({ data: "success" });
// } else {
// return res.status(400).json();
// }
});
export const config = {
+8 -18
View File
@@ -32,6 +32,7 @@ const Home = (props) => {
loginEmailStr,
loggedInUserEmail,
ggLocale,
hasLoginCode,
} = props;
let { t, lang } = useTranslation();
@@ -43,7 +44,7 @@ const Home = (props) => {
expDate.setDate(now.getDate() + 1);
//console.log("hashed email str", loginEmailStr);
_.isEmpty(loggedInUserId) != false && !hasGGCode
hasLoginCode != false
? console.log("no session")
: _.has(loggedInUserId, "value")
? _.isEmpty(loggedInUserId.value)
@@ -144,8 +145,8 @@ const Home = (props) => {
showLogin={showLogin}
showMap={showMap}
loggedInUserId={loggedInUserId}
GG_REDIRECT_URI={props.GG_REDIRECT_URI}
GG_CLIENT_ID={props.GG_CLIENT_ID}
// GG_REDIRECT_URI={props.GG_REDIRECT_URI}
// GG_CLIENT_ID={props.GG_CLIENT_ID}
/>
</>
)}
@@ -172,22 +173,13 @@ export const getServerSideProps = wrapper.getServerSideProps(
const hasLoginCode = thisSession != null;
let providerConfig = await getProviderConfig();
// let providerConfig = await getProviderConfig();
let ggLocale =
typeof query.ui_locales != "undefined" && query.ui_locales;
console.log(
"endpoint: ",
providerConfig.token_endpoint,
"\n",
"hasloginCode:",
hasLoginCode,
"\n",
"redirect:",
process.env.GG_REDIRECT_URI
);
console.log("\n", "hasloginCode:", hasLoginCode);
store.dispatch(getGovGatewayConfig(providerConfig));
// store.dispatch(getGovGatewayConfig(providerConfig));
let ggToken = {};
let ggUserInfo = {};
@@ -219,11 +211,9 @@ export const getServerSideProps = wrapper.getServerSideProps(
ggLocale: ggLocale,
showLogin: showLoginCheck,
showMap: showMapCheck,
hasGGCode: hasLoginCode,
hasSession: hasLoginCode,
loggedInUserId: portalUserObj,
loggedInUserEmail: loginEmailStr,
GG_REDIRECT_URI: process.env.GG_REDIRECT_URI,
GG_CLIENT_ID: process.env.GG_CLIENT_ID,
},
};
}
-7
View File
@@ -179,13 +179,6 @@ export const getServerSideProps = wrapper.getServerSideProps(
await getAwaitingSubmission(loggedInUser),
]);
//const cookiesMaker = nookies.get(ctx)
// console.log(
// "acc details:",
// accountDetails,
// _.has(accountDetails, "errorCode") != false
// );
if (_.has(accountDetails, "errorCode") != false) {
return {
redirect: {