Repository navigation
Expand file tree
/
Copy pathapp.js
More file actions
135 lines (120 loc) · 3.47 KB
/
Copy pathapp.js
File metadata and controls
135 lines (120 loc) · 3.47 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
const express = require('express');
const path = require('path');
const morgan = require('morgan');
const cookieParser = require('cookie-parser');
const rateLimit = require('express-rate-limit');
const helmet = require('helmet');
const mongoSanitize = require('express-mongo-sanitize');
const sanitizeHtml = require('sanitize-html');
const cors = require('cors');
const hpp = require('hpp');
const { stream } = require('./utils/logger');
const globalErrorHandler = require('./controllers/errorController');
const productRouter = require('./routes/productRoutes');
const searchRoutes = require('./routes/searchRoutes');
const userRouter = require('./routes/userRoutes');
const reviewRouter = require('./routes/reviewRoutes');
const orderRouter = require('./routes/orderRoutes');
const app = express();
// 1) GLOBAL MIDDLEWARES
// Enable CORS - Add this before other middleware
app.use(cors());
// Serve static files from the public directory
app.use(express.static(path.join(__dirname, 'public')));
// Set security HTTP headers
app.use(
helmet({
contentSecurityPolicy: {
useDefaults: true,
directives: {
'connect-src': [
"'self'",
'http://127.0.0.1:3000',
'http://localhost:3000',
],
'font-src': ["'self'", 'https://fonts.gstatic.com'],
'style-src': [
"'self'",
"'unsafe-inline'",
'https://fonts.googleapis.com',
],
'script-src': ["'self'"],
'frame-src': ["'self'"],
},
},
}),
);
// Logging configuration
if (process.env.NODE_ENV === 'development') {
app.use(morgan('dev', { stream }));
} else {
// Production logging
app.use(morgan('combined', { stream }));
}
// Limit requests from same API
const limiter = rateLimit({
max: 1000,
windowMs: 60 * 60 * 1000, // 1 hour window
message: 'Too many requests from this IP, please try again in an hour!',
});
app.use('/api', limiter);
// Body parser, reading data from body into req.body
app.use(express.json({ limit: '10kb' }));
app.use(express.urlencoded({ extended: true, limit: '10kb' }));
app.use(cookieParser());
// Data sanitization against NoSQL query injection
app.use(mongoSanitize());
// Data sanitization against XSS
app.use((req, res, next) => {
if (req.body) {
Object.keys(req.body).forEach((key) => {
if (typeof req.body[key] === 'string') {
req.body[key] = sanitizeHtml(req.body[key], {
allowedTags: [],
allowedAttributes: {},
});
}
});
}
next();
});
// Prevent parameter pollution
app.use(
hpp({
whitelist: [
'price',
'ratingsQuantity',
'ratingsAverage',
'stock',
'discount',
'category',
'size',
'brand',
'tags',
],
}),
);
// Request timestamp middleware
app.use((req, res, next) => {
req.requestTime = new Date().toISOString();
next();
});
// API Routes
app.use('/api/v1/products', productRouter);
app.use('/api/v1/search', searchRoutes);
app.use('/api/v1/orders', orderRouter);
app.use('/api/v1/users', userRouter);
app.use('/api/v1/reviews', reviewRouter);
app.post('/test-sanitize', (req, res) => {
res.json({ sanitizedInput: req.body });
});
// Handle undefined routes with JSON response
app.all('*', (req, res, next) => {
res.status(404).json({
status: 'error',
message: `Can't find ${req.originalUrl} on this server!`,
documentation: 'https://api.exclusive.com/docs', // Update with your actual docs URL
});
});
app.use(globalErrorHandler);
module.exports = app;