user.controller.js 18.4 KB
Newer Older
한규민's avatar
한규민 committed
1
2
import jwt from "jsonwebtoken";
import config from "../config/app.config.js";
Jiwon Yoon's avatar
Jiwon Yoon committed
3
import { User, Role, Guest, ConfirmNum } from '../db/index.js';
한규민's avatar
한규민 committed
4
import fs from "fs";
한규민's avatar
한규민 committed
5
import CryptoJS from "crypto-js";
한규민's avatar
한규민 committed
6
import validator from "validator";
한규민's avatar
한규민 committed
7
import axios from "axios";
한규민's avatar
한규민 committed
8
// 현재 유저 상태 결정
한규민's avatar
한규민 committed
9
10
const getUser = async (req, res) => {
    try {
한규민's avatar
한규민 committed
11
        if (req.cookies.butterStudio) {
한규민's avatar
한규민 committed
12
            const token = req.cookies.butterStudio;
한규민's avatar
한규민 committed
13
14
            const { id, role } = jwt.verify(token, config.jwtSecret);
            res.json( { id, role } );
한규민's avatar
한규민 committed
15
16
17
18
19
20
21
22
        } else {
            res.json({ id: 0, role: "user" });
        }
    } catch (error) {
        console.error(error);
        return res.status(500).send("유저를 가져오지 못했습니다.");
    }
}
한규민's avatar
한규민 committed
23
// 로그인
Jiwon Yoon's avatar
Jiwon Yoon committed
24
const login = async (req, res) => {
한규민's avatar
한규민 committed
25
26
27
28
29
30
31
    try {
        const { id, password } = req.body;
        //사용자 존재 확인
        const user = await User.scope("withPassword").findOne({ where: { userId: id } });
        if (!user) {
            return res.status(422).send(`사용자가 존재하지 않습니다`);
        }
한규민's avatar
한규민 committed
32
        // 2) 비밀번호 확인은 데이터베이스 프로토타입 메소드에서 처리(사용자가 입력한 비밀번호와 서버에 있는 비번 비교)
한규민's avatar
한규민 committed
33
34
35
        const passwordMatch = await user.comparePassword(password);
        if (passwordMatch) {
            // 3) 비밀번호가 맞으면 토큰 생성
한규민's avatar
push    
한규민 committed
36
            const userRole = await user.getRole();
한규민's avatar
한규민 committed
37
            const signData = {
한규민's avatar
한규민 committed
38
                id: user.id,
한규민's avatar
push    
한규민 committed
39
                role: userRole.name,
한규민's avatar
한규민 committed
40
41
42
43
44
45
46
47
48
49
50
51
52
            };
            const token = jwt.sign(signData, config.jwtSecret, {
                expiresIn: config.jwtExpires,
            });
            // 4) 토큰을 쿠키에 저장
            res.cookie(config.cookieName, token, {
                maxAge: config.cookieMaxAge,
                path: "/",
                httpOnly: config.env === "production",
                secure: config.env === "production",
            });
            // 5) 사용자 반환
            res.json({
한규민's avatar
한규민 committed
53
                id: user.id,
한규민's avatar
context    
한규민 committed
54
                role: userRole.name,
한규민's avatar
한규민 committed
55
56
57
58
59
60
61
62
63
64
            });
        } else {
            // 6) 비밀번호 불일치
            res.status(401).send("비밀번호가 일치하지 않습니다");
        }
    } catch (error) {
        console.error(error);
        return res.status(500).send("로그인 에러");
    }
}
한규민's avatar
한규민 committed
65
// 로그아웃
Jiwon Yoon's avatar
Jiwon Yoon committed
66
67
const logout = async (req, res) => {
    try {
한규민's avatar
한규민 committed
68
        res.clearCookie(config.cookieName);
한규민's avatar
한규민 committed
69
70
71
72
        res.json({
            id: 0,
            role: "user",
        })
한규민's avatar
한규민 committed
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
    } catch (error) {
        console.error(error);
        return res.status(500).send("로그인 에러");
    }
}

//비회원 예매확인 로그인
const guestLogin = async (req, res) => {
    try {
        const {guestName, guestEmail, guestBirthday, guestMbnum, guestPassword} = req.body;
        const guest = await Guest.findOne({ where : {
            name: guestName,
            email: guestEmail,
            birth: guestBirthday,
            phoneNumber: guestMbnum,
            password: guestPassword,
        }});
        if (!guest) {
            return res.status(422).send(`사용자가 존재하지 않습니다`);
        }else{
            const guestRole = await guest.getRole();
            const signData = {
                id: guest.id,
                role: guestRole.name
            };
            //토큰 생성
            const token = jwt.sign(signData, config.jwtSecret, {
                expiresIn: config.jwtExpires,
            });
            // 토큰을 쿠키에 저장
            res.cookie(config.cookieName, token, {
                maxAge: config.cookieMaxAge,
                path: "/",
                httpOnly: config.env === "production",
                secure: config.env === "production",
            });
            // 사용자 반환
            res.json(signData);
        }
Jiwon Yoon's avatar
Jiwon Yoon committed
112
    } catch (error) {
한규민's avatar
context    
한규민 committed
113
114
        console.error(error);
        return res.status(500).send("로그인 에러");
한규민's avatar
한규민 committed
115
    }
Jiwon Yoon's avatar
Jiwon Yoon committed
116
};
한규민's avatar
한규민 committed
117

한규민's avatar
한규민 committed
118
119
120
// 인증번호 발송
const confirmMbnum = async (req, res) => {
    try {
한규민's avatar
한규민 committed
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
        
        // 휴대폰 인증
        const NCP_serviceID = process.env.NCP_serviceID;
        const NCP_accessKey = process.env.NCP_accessKey;
        const NCP_secretKey = process.env.NCP_secretKey;
        
        const date = Date.now().toString();
        const uri = NCP_serviceID;
        const accessKey = NCP_accessKey;
        const secretKey = NCP_secretKey;
        const method = 'POST';
        const space = " ";
        const newLine = "\n";
        const url = `https://sens.apigw.ntruss.com/sms/v2/services/${uri}/messages`;
        const url2 = `/sms/v2/services/${uri}/messages`;
        
        //시크릿 키를 암호화하는 작업
        const hmac = CryptoJS.algo.HMAC.create(CryptoJS.algo.SHA256, secretKey);
        
        hmac.update(method);
        hmac.update(space);
        hmac.update(url2);
        hmac.update(newLine);
        hmac.update(date);
        hmac.update(newLine);
        hmac.update(accessKey);
        
        const hash = hmac.finalize();
        const signature = hash.toString(CryptoJS.enc.Base64);
        
한규민's avatar
한규민 committed
151
        const phoneNumber = req.params.phone;
한규민's avatar
한규민 committed
152
        console.log("phoneNumber: ", phoneNumber);
한규민's avatar
한규민 committed
153
154
        //인증번호 생성
        const verifyCode = Math.floor(Math.random() * (999999 - 100000)) + 100000;
한규민's avatar
한규민 committed
155
        console.log(verifyCode);
한규민's avatar
한규민 committed
156
        let today = new Date();
157
        let time = String(today.getTime());
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
        let result = await axios({
            method: method,
            json: true,
            url: url,
            headers: {
                'Content-Type': "application/json",
                'x-ncp-apigw-timestamp': date,
                'x-ncp-iam-access-key': accessKey,
                'x-ncp-apigw-signature-v2': signature,
            },
            data: {
                type: 'SMS',
                contentType: 'COMM',
                countryCode: '82',
                from: '01086074580',
                content: `[본인 확인] 인증번호 [${verifyCode}]를 입력해주세요.`,
                messages: [
                    {
                        to: `${phoneNumber}`,
                    },
                ],
            },
        });
한규민's avatar
한규민 committed
181

182
183
184
        const resultMs = result.data.messages;
        console.log('resultMs', resultMs);
        console.log('response', res.data, res['data']);
한규민's avatar
한규민 committed
185
        
한규민's avatar
한규민 committed
186
187
        const confirm = await ConfirmNum.findOne({ where: { phone: phoneNumber } });
        if (confirm) {
188
189
190
191
192
193
            await confirm.destroy();
            await ConfirmNum.create({
                confirmNum: String(verifyCode),
                phone: phoneNumber,
                startTime: time,
            });
한규민's avatar
한규민 committed
194
        } else {
195
196
197
198
199
            await ConfirmNum.create({
                confirmNum: String(verifyCode),
                phone: phoneNumber,
                startTime: time,
            }
한규민's avatar
한규민 committed
200
            );
201
202
        }
        res.json({ startTime: time, isSuccess: true, code: 202, message: "본인인증 문자 발송 성공", result: res.data });
한규민's avatar
한규민 committed
203
204
205
206
207
208
209
210
    } catch (error) {
        console.log("error: ", error);
        if (error.res == undefined) {
            res.json({ isSuccess: true, code: 200, message: "본인인증 문자 발송 성공", result: res.data });
        }
        else res.json({ isSuccess: true, code: 204, message: "본인인증 문자 발송에 문제가 있습니다.", result: error.res });
    }
};
211

한규민's avatar
한규민 committed
212
213
214
//  인증번호 확인
const confirmNum = async (req, res) => {
    try {
한규민's avatar
한규민 committed
215
216
        const { userMbnum, number, startTime } = req.body;
        const confirm = await ConfirmNum.findOne({ where: { phone: userMbnum, startTime: startTime } });
217

한규민's avatar
한규민 committed
218
        let today = new Date();
219
220
221
        let time = today.getTime();
        const elapsedMSec = time - confirm.startTime;
        const elapsedMin = String(elapsedMSec / 1000 / 60);
한규민's avatar
한규민 committed
222
        if (elapsedMin <= 5) {
223
            if (number !== confirm.confirmNum) {
한규민's avatar
한규민 committed
224
                res.send("실패");
한규민's avatar
한규민 committed
225
            } else {
226
                await confirm.destroy();
한규민's avatar
한규민 committed
227
228
                res.send("성공");
            }
한규민's avatar
한규민 committed
229
        } else {
230
            res.send("재전송")
한규민's avatar
한규민 committed
231
232
233
234
235
236
        }
    } catch (error) {
        console.error("error : ", error.message);
        res.status(500).send("잘못된 접근입니다.");
    }
};
한규민's avatar
한규민 committed
237

한규민's avatar
한규민 committed
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
//유효성 검사
const validation = (errorMsg, data, minLength, maxLength, dataType) => {
    if (validator.isLength(data, minLength, maxLength)) {
        errorMsg[dataType] = false;
    } else {
        errorMsg[dataType] = true;
    }
    if (dataType === "userEmail") {
        if (validator.isEmail(data, minLength, maxLength)) {
            errorMsg[dataType] = false;
        } else {
            errorMsg[dataType] = true;
        }

    }
};
한규민's avatar
한규민 committed
254
// 회원정보
한규민's avatar
한규민 committed
255
const signup = async (req, res) => {
256
    const { userId, userName, userEmail, userNickName, userBirthday, userMbnum, userPassword } = req.body;
한규민's avatar
한규민 committed
257
    try {
한규민's avatar
한규민 committed
258
259
260
261
262
263
264
265
266
        let errorMsg = {
            errorId: false,
            errorName: false,
            errorEmail: false,
            errorBirthday: false,
            errorNickName: false,
            errorMbnum: false,
            errorPassword: false,
        };
한규민's avatar
한규민 committed
267

한규민's avatar
한규민 committed
268
269
270
271
272
273
274
275
276
277
        //유효성 검사
        validation(errorMsg, userId, 5, 10, "errorId");
        validation(errorMsg, userName, 1, 10, "errorName");
        validation(errorMsg, userEmail, 3, 20, "errorEmail");
        validation(errorMsg, userBirthday, 6, 6, "errorBirthday");
        validation(errorMsg, userNickName, 1, 10, "errorNickName");
        validation(errorMsg, userMbnum, 11, 11, "errorMbnum");
        validation(errorMsg, userPassword, 8, 11, "errorPassword");

        let valid = !(Object.values(errorMsg).some((element) => (element)));
한규민's avatar
한규민 committed
278
279
        // db에서 데이터 중복검사
        const id = await User.findOne({ where: { userId: userId } });
한규민's avatar
한규민 committed
280
281
282
283
        const mbnum = await User.findOne({ where: { phoneNumber: userMbnum } });
        const email = await User.findOne({ where: { email: userEmail } });
        if (!valid) {
            res.json(errorMsg);
한규민's avatar
한규민 committed
284
        } else {
한규민's avatar
한규민 committed
285
286
287
288
289
290
291
            if (id) {
                return res.status(401).send(`이미 있는 아이디입니다.`);
            } else if (email) {
                return res.status(401).send(`이미 있는 이메일입니다.`);
            } else if (mbnum) {
                return res.status(401).send(`이미 있는 휴대폰번호입니다.`);
            } else{
한규민's avatar
한규민 committed
292
293
294
295
296
297
298
299
300
301
302
303
304
305
                const role = await Role.findOne({ where: { name: "member" } })
                await User.create({
                    userId: userId,
                    name: userName,
                    email: userEmail,
                    nickname: userNickName,
                    birth: userBirthday,
                    phoneNumber: userMbnum,
                    password: userPassword,
                    img: "",
                    roleId: role.id
                });
                res.json("성공");
            }
한규민's avatar
한규민 committed
306
307
308
309
310
311
312
        }
    } catch (error) {
        console.error(error.message);
        res.status(500).send("회원가입 에러. 나중에 다시 시도 해주세요");
    }
};

한규민's avatar
한규민 committed
313
const getMember = async (req, res) => {
한규민's avatar
한규민 committed
314
    try {
한규민's avatar
한규민 committed
315
        const token = req.cookies.butterStudio;
한규민's avatar
한규민 committed
316
317
318
        const { id, role } = jwt.verify(token, config.jwtSecret);
        if ( role === "member") {
            const user = await User.findOne({ where: { id: id } });
한규민's avatar
한규민 committed
319
            res.json({ nickname: user.nickname, img: user.img });
한규민's avatar
한규민 committed
320
        } else {
한규민's avatar
한규민 committed
321
            res.status(500).send("잘못된 접근입니다.");
한규민's avatar
한규민 committed
322
        }
한규민's avatar
한규민 committed
323
    } catch (error) {
한규민's avatar
한규민 committed
324
325
326
327
        console.error("error : ", error.message);
        res.status(500).send("잘못된 접근입니다.");
    }
}
한규민's avatar
한규민 committed
328
// 프로필 변경
한규민's avatar
한규민 committed
329
330
331
332
const uploadProfile = async (req, res) => {
    try {
        const image = req.file.filename;
        const token = req.cookies.butterStudio;
한규민's avatar
한규민 committed
333
        const { id } = jwt.verify(token, config.jwtSecret);
한규민's avatar
한규민 committed
334

한규민's avatar
한규민 committed
335
336
        if (id) {
            const img = await User.findOne({ where: { id: id }, attributes: ["img"] });
한규민's avatar
한규민 committed
337
            fs.unlink("upload" + `\\${img.img}`, function (data) { console.log(data); });
한규민's avatar
한규민 committed
338
339
340

            const user = await User.update({
                img: image
한규민's avatar
한규민 committed
341
            }, { where: { id: id } });
한규민's avatar
한규민 committed
342
            if (user) {
한규민's avatar
한규민 committed
343
                const success = await User.findOne({ where: { id: id }, attributes: ["img"] });
한규민's avatar
한규민 committed
344
                res.json(success)
한규민's avatar
한규민 committed
345
            } else {
한규민's avatar
한규민 committed
346
347
348
349
350
351
352
353
                throw new Error("프로필 등록 실패")
            }
        }
    } catch (error) {
        console.error(error.message);
        res.status(500).send("프로필 에러");
    }
}
한규민's avatar
한규민 committed
354
// 기본 비밀번호인지 확인
한규민's avatar
한규민 committed
355
356
357
358
const comparePw = async (req, res) => {
    try {
        //쿠키 안 토큰에서 id추출
        const token = req.cookies.butterStudio;
한규민's avatar
한규민 committed
359
        const { id } = jwt.verify(token, config.jwtSecret);
한규민's avatar
한규민 committed
360
        //해당 id의 행 추출
한규민's avatar
한규민 committed
361
        const user = await User.scope("withPassword").findOne({ where: { id: id } });
한규민's avatar
한규민 committed
362
363
364
365
366
367
368
369
370
371
372
        //입력한 비번과 해당 행 비번을 비교
        const passwordMatch = await user.comparePassword(req.params.pw);
        //클라이언트로 동일여부를 전송
        if (passwordMatch) {
            return res.json(true)
        } else {
            return res.json(false)
        }
    } catch (error) {
        console.error("error : ", error.message);
        res.status(500).send("인증 에러");
한규민's avatar
한규민 committed
373
374
    }
}
한규민's avatar
한규민 committed
375
// 회원정보 수정할 때 쓰는 함수
한규민's avatar
한규민 committed
376
const overlap = async ( id , dataType, data) => {
한규민's avatar
한규민 committed
377
    try {
한규민's avatar
한규민 committed
378
        let overlap = await User.findOne({ where: { id: id } });
한규민's avatar
한규민 committed
379
        // 변경할 데이터가 자기자신이면 true
한규민's avatar
한규민 committed
380
381
382
        if (overlap[dataType] === data) {
            return true
        } else {
한규민's avatar
한규민 committed
383
            // 그렇지 않으면 다른 데이터들 중에서 중복되는지 검사
한규민's avatar
한규민 committed
384
385
            let overlap2 = await User.findOne({ attributes: [dataType] });
            if (overlap2[dataType] === data) {
한규민's avatar
한규민 committed
386
387
388
389
390
                return false
            } else {
                return true
            }
        }
한규민's avatar
한규민 committed
391
    } catch (error) {
한규민's avatar
한규민 committed
392
393
394
        console.error(error.message);
    }
}
한규민's avatar
한규민 committed
395
// 회원정보 수정
한규민's avatar
한규민 committed
396
397
const modifyUser = async (req, res) => {
    try {
한규민's avatar
한규민 committed
398
        const token = req.cookies.butterStudio;
한규민's avatar
한규민 committed
399
        const { id } = jwt.verify(token, config.jwtSecret);
400
        const { userName, userEmail, userNickName, userMbnum, userPassword } = req.body;
한규민's avatar
한규민 committed
401

한규민's avatar
한규민 committed
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
        let errorMsg = {
            errorName: false,
            errorEmail: false,
            errorNickName: false,
            errorMbnum: false,
            errorPassword: false,
        };

        //유효성 검사
        validation(errorMsg, userName, 1, 10, "errorName");
        validation(errorMsg, userEmail, 3, 20, "errorEmail");
        validation(errorMsg, userNickName, 1, 10, "errorNickName");
        validation(errorMsg, userMbnum, 11, 11, "errorMbnum");
        validation(errorMsg, userPassword, 8, 11, "errorPassword");

        let valid = !(Object.values(errorMsg).some((element) => (element)));
한규민's avatar
한규민 committed
418
419
        const overlapEmail = await overlap( id , "email", userEmail);
        const overlapMbnum = await overlap( id , "phoneNumber", userMbnum);
한규민's avatar
한규민 committed
420
421
        if (!valid) {
            res.json(errorMsg);
한규민's avatar
한규민 committed
422
        } else {
한규민's avatar
한규민 committed
423
424
425
426
427
428
429
            if (overlapEmail && overlapMbnum) {
                await User.update({
                    name: userName,
                    email: userEmail,
                    nickname: userNickName,
                    phoneNumber: userMbnum,
                    password: userPassword,
한규민's avatar
한규민 committed
430
                }, { where: { id:  id }, individualHooks: true });
한규민's avatar
한규민 committed
431
432
433
434
435
436
437
438
                res.json("성공");
            } else if (!overlapEmail && overlapMbnum) {
                res.status(500).send("이미 있는 이메일입니다.");
            } else if (overlapEmail && !overlapMbnum) {
                res.status(500).send("이미 있는 핸드폰번호입니다.");
            } else {
                res.status(500).send("이미 있는 이메일, 핸드폰번호입니다.");
            }
한규민's avatar
한규민 committed
439
440
441
442
443
444
        }
    } catch (error) {
        console.error(error.message);
        res.status(500).send("수정 에러. 나중에 다시 시도 해주세요");
    }
};
445

한규민's avatar
한규민 committed
446
447
const getUserInfo = async (req, res) => {
    const { id } = req.body
Jiwon Yoon's avatar
Jiwon Yoon committed
448
    // console.log(id)
449
450
    try {
        const userInfo = await User.findOne({
한규민's avatar
한규민 committed
451
            where: { id: id },
452
            attributes: ["id", "userId", "email", "nickname", "birth", "phoneNumber"]
453
        })
Jiwon Yoon's avatar
Jiwon Yoon committed
454
        // console.log(userInfo)
455
456
        res.json(userInfo)
    } catch (error) {
Jiwon Yoon's avatar
Jiwon Yoon committed
457
458
459
460
461
462
        res.status(500).send("회원정보 불러오기 실패");
    }
}

const saveGuestInfo = async (req, res) => {
    try {
Jiwon Yoon's avatar
Jiwon Yoon committed
463
        const { name, email, birth, phoneNumber, password } = req.body
한규민's avatar
한규민 committed
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503

        let errorMsg = {
            errorName: false,
            errorEmail: false,
            errorNickName: false,
            errorMbnum: false,
            errorPassword: false,
        };

        validation(errorMsg, name, 1, 10, "errorName");
        validation(errorMsg, email, 3, 20, "errorEmail");
        validation(errorMsg, birth, 1, 10, "errorNickName");
        validation(errorMsg, phoneNumber, 11, 11, "errorMbnum");
        validation(errorMsg, password, 8, 11, "errorPassword");

        let valid = !(Object.values(errorMsg).some((element) => (element)));

        if(!valid){
            res.json(errorMsg);
        }else{
            const newGuest = await Guest.create({
                name: name,
                email: email,
                birth: birth,
                phoneNumber: phoneNumber,
                password: password,
                roleId:1
            });
            res.clearCookie(config.cookieName);
            const token = jwt.sign({id: newGuest.id, role: "guest"}, config.jwtSecret, {
                expiresIn: config.jwtExpires,
            });
            res.cookie(config.cookieName,token , {
                maxAge: config.cookieMaxAge,
                path: "/",
                httpOnly: config.env === "production",
                secure: config.env === "production",
            })
            res.json(newGuest);
        }
504
    } catch (error) {
Jiwon Yoon's avatar
Jiwon Yoon committed
505
        res.status(500).send("비회원정보 등록 실패");
506
507
    }
}
한규민's avatar
한규민 committed
508

509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
const getGuestInfo = async (req,res) => {
    const {guestId} = req.params
    // console.log(req.body)
    try {
        const guestInfo = await Guest.findOne({
            where: {
                id:guestId
            }
        })
        // console.log("guestInfo====", guestInfo)
        res.json(guestInfo)
    } catch (error) {
        res.status(500).send("비회원정보 불러오기 실패");
    }
}
한규민's avatar
한규민 committed
524
export default {
한규민's avatar
한규민 committed
525
    getUser,
한규민's avatar
한규민 committed
526
    login,
한규민's avatar
push    
한규민 committed
527
    logout,
한규민's avatar
한규민 committed
528
    guestLogin,
한규민's avatar
한규민 committed
529
    confirmMbnum,
한규민's avatar
한규민 committed
530
    confirmNum,
한규민's avatar
한규민 committed
531
    signup,
한규민's avatar
한규민 committed
532
    comparePw,
한규민's avatar
한규민 committed
533
    modifyUser,
Jiwon Yoon's avatar
Jiwon Yoon committed
534
535
536
    saveGuestInfo,
    getMember,
    uploadProfile,
537
538
    getUserInfo,
    getGuestInfo
한규민's avatar
한규민 committed
539
}