- Added some school methods but will need to refactor the model calls
This commit is contained in:
@@ -8,46 +8,21 @@ let router = express.Router()
|
||||
const connection = require('../database/connection')
|
||||
const db = connection.db
|
||||
|
||||
// Validations
|
||||
const regexInt = RegExp(/^[1-9]\d*$/)
|
||||
const regexXSS = RegExp(/<[^>]*script/)
|
||||
// Repository
|
||||
const SchoolRepository = require('../repositories/school-repository');
|
||||
const Schools = new SchoolRepository();
|
||||
|
||||
// Model validation
|
||||
const Validator = require('jsonschema').Validator
|
||||
const v = new Validator()
|
||||
const School = require("../models/SchoolValidation")
|
||||
v.addSchema(School, "/SchoolModel")
|
||||
const regexInt = RegExp(/^[1-9]\d*$/)
|
||||
|
||||
// Error handling
|
||||
const { HttpError } = require('../models/Errors')
|
||||
|
||||
|
||||
// ROUTES
|
||||
// GET ALL ------------------
|
||||
const getSchools = () => {
|
||||
return new Promise((resolve, reject) => {
|
||||
|
||||
let query = "SELECT DISTINCT * FROM school"
|
||||
|
||||
db.query(query, async (err, result) => {
|
||||
if (err) {
|
||||
reject(new HttpError(500, 'Database error'))
|
||||
} else if (result.length == 0) {
|
||||
reject(new HttpError(404, 'No schools were found'))
|
||||
}
|
||||
|
||||
// Loops over the results to fetch the associated tables
|
||||
for (let i = 0; i < result.length; i++) {
|
||||
try {
|
||||
result[i] = await buildSchool(result[i])
|
||||
} catch (err) {
|
||||
reject(err)
|
||||
}
|
||||
}
|
||||
resolve(result)
|
||||
})
|
||||
})
|
||||
return Schools.getAll()
|
||||
.catch(err => {
|
||||
console.log(err)
|
||||
throw err
|
||||
})
|
||||
}
|
||||
@@ -70,23 +45,9 @@ router.get('/', async (req, res) => {
|
||||
|
||||
// GET ONE ------------------
|
||||
const getSchool = (id) => {
|
||||
return new Promise((resolve, reject) => {
|
||||
|
||||
let query = "SELECT * FROM school WHERE id = " + db.escape(id)
|
||||
|
||||
db.query(query, async (err, result) => {
|
||||
if (err) {
|
||||
reject(new HttpError(500, 'Database error'))
|
||||
}
|
||||
try {
|
||||
result = buildSchool(result[0])
|
||||
resolve(result)
|
||||
} catch (err) {
|
||||
reject(err)
|
||||
}
|
||||
})
|
||||
})
|
||||
return Schools.getOne(id)
|
||||
.catch(err => {
|
||||
console.log(err)
|
||||
throw err
|
||||
})
|
||||
}
|
||||
@@ -109,41 +70,9 @@ router.get('/:id/', async (req, res) => {
|
||||
|
||||
// CREATE ONE ------------------
|
||||
const addSchool = (s) => {
|
||||
return new Promise(async (resolve, reject) => {
|
||||
|
||||
// Checks if body exists and if the model fits, and throws errors if it doesn't
|
||||
if (isEmptyObject(s)) {
|
||||
reject(new HttpError(403, "Error: School cannot be nothing !"))
|
||||
} else if (!v.validate(s, School).valid) {
|
||||
reject(new HttpError(403, "Error: Schema is not valid - " + v.validate(s, School).errors))
|
||||
} else if (isXSSAttempt(s.name) || isXSSAttempt(s.description)) {
|
||||
reject(new HttpError(403, 'Injection attempt detected, aborting the request.'))
|
||||
} else {
|
||||
let query = `INSERT INTO school (name, description, id_meta_school) VALUES (${db.escape(s.name)}, ${db.escape(s.description)}, ${db.escape(s.id_meta_school)})`
|
||||
|
||||
db.query(query, (err, result) => {
|
||||
if (err) {
|
||||
if (err.errno == 1452) {
|
||||
reject(new HttpError(404, "Error: No meta school matching this ID"))
|
||||
} else {
|
||||
reject(new HttpError(500, 'Database error'))
|
||||
}
|
||||
} else {
|
||||
console.log(`Inserted "${s.name}" with ID ${result.insertId}, affecting ${result.affectedRows} row(s)`)
|
||||
|
||||
const new_school_id = result.insertId
|
||||
|
||||
getSchool(new_school_id)
|
||||
.then(v => {
|
||||
resolve(v)
|
||||
})
|
||||
.catch(err => {
|
||||
reject(err)
|
||||
})
|
||||
}
|
||||
})
|
||||
}
|
||||
}).catch(err => {
|
||||
return Schools.addOne(s)
|
||||
.catch(err => {
|
||||
console.log(err)
|
||||
throw err
|
||||
})
|
||||
}
|
||||
@@ -163,79 +92,74 @@ router.post('/', async (req, res) => {
|
||||
})
|
||||
})
|
||||
|
||||
// Param validation for single school
|
||||
// (check if id is int) (could be refactored)
|
||||
router.param('id', (req, res, next, id) => {
|
||||
const regex = RegExp(/^[1-9]\d*$/);
|
||||
try {
|
||||
if (regex.test(id)) {
|
||||
next()
|
||||
} else {
|
||||
throw new HttpError(403, 'Provided ID must be an integer')
|
||||
}
|
||||
} catch (err) {
|
||||
// UPDATE ONE ------------------
|
||||
const updateSchool = (id, s) => {
|
||||
return Schools.updateOne(id, s)
|
||||
.catch(err => {
|
||||
console.log(err)
|
||||
throw err
|
||||
})
|
||||
}
|
||||
router.put('/:id/', async (req, res) => {
|
||||
updateSchool(req.params.id, req.body)
|
||||
.then(v => {
|
||||
res.setHeader('Content-Type', 'application/json;charset=utf-8')
|
||||
res.send(JSON.stringify(v))
|
||||
})
|
||||
.catch(err => {
|
||||
res.status(err.code).send(JSON.stringify(
|
||||
{
|
||||
"error": err.message,
|
||||
"code": err.code
|
||||
})
|
||||
)
|
||||
}
|
||||
})
|
||||
})
|
||||
|
||||
// SHARED FUNCTIONS ------------------
|
||||
|
||||
// Builds the associated infos for a given school object
|
||||
const buildSchool = async (school) => {
|
||||
|
||||
// Fetches the school's parent school
|
||||
let fetchMetaSchoolData = (s) => {
|
||||
return new Promise((resolve, reject) => {
|
||||
|
||||
if (s == null) { reject(new HttpError(404, "Error: No school matching this ID"))}
|
||||
|
||||
let query =
|
||||
"SELECT ms.id, ms.name " +
|
||||
"FROM meta_school AS ms " +
|
||||
"WHERE ms.id = " + s.id_meta_school
|
||||
|
||||
|
||||
db.query(query, (err, result) => {
|
||||
if (err) {
|
||||
reject(new HttpError(500, 'Database error'))
|
||||
} else {
|
||||
delete s.id_meta_school
|
||||
s.meta_school = result
|
||||
resolve(s)
|
||||
}
|
||||
})
|
||||
})
|
||||
}
|
||||
|
||||
let s = fetchMetaSchoolData(school)
|
||||
// DELETE ONE ------------------
|
||||
const deleteSchool = (id) => {
|
||||
return Schools.deleteOne(id)
|
||||
.catch(err => {
|
||||
console.log(err)
|
||||
throw err
|
||||
})
|
||||
|
||||
return s
|
||||
}
|
||||
router.delete('/:id/', async (req, res) => {
|
||||
deleteSchool(req.params.id)
|
||||
.then(v => {
|
||||
res.setHeader('Content-Type', 'application/json;charset=utf-8')
|
||||
res.send(JSON.stringify(v))
|
||||
})
|
||||
.catch(err => {
|
||||
res.status(err.code).send(JSON.stringify(
|
||||
{
|
||||
"error": err.message,
|
||||
"code": err.code
|
||||
})
|
||||
)
|
||||
})
|
||||
})
|
||||
|
||||
// Check if object is null
|
||||
const isEmptyObject = (obj) => {
|
||||
if (Object.keys(obj).length === 0 && obj.constructor === Object) {
|
||||
return true
|
||||
} else {
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
// Check if script injection attempt
|
||||
const isXSSAttempt = (string) => {
|
||||
if (regexXSS.test(string)) {
|
||||
return true
|
||||
} else {
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = router
|
||||
// Param validation for ID
|
||||
// (check if id is int) (could be refactored)
|
||||
router.param('id', (req, res, next, id) => {
|
||||
try {
|
||||
if (regexInt.test(id)) {
|
||||
next()
|
||||
} else {
|
||||
throw new Error;
|
||||
}
|
||||
} catch (err) {
|
||||
err = new HttpError(403, 'Provided ID must be an integer and not zero')
|
||||
res.status(err.code).send(JSON.stringify(
|
||||
{
|
||||
"error": err.message,
|
||||
"code": err.code
|
||||
})
|
||||
)
|
||||
}
|
||||
})
|
||||
|
||||
module.exports = router
|
||||
|
||||
@@ -143,7 +143,7 @@ router.delete('/:id/', async (req, res) => {
|
||||
})
|
||||
|
||||
|
||||
// Param validation for single spell
|
||||
// Param validation for ID
|
||||
// (check if id is int) (could be refactored)
|
||||
router.param('id', (req, res, next, id) => {
|
||||
try {
|
||||
|
||||
Reference in New Issue
Block a user