forked from Kirill89/prototype-pollution-explained
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathindex.js
79 lines (65 loc) · 1.98 KB
/
index.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
// This is a simple chat API:
//
// - All users can see all messages.
// - Registered users can post messages.
// - Administrators can delete messages.
//
// The challenge is to delete any message without admin password.
//
const express = require('express');
const bodyParser = require('body-parser');
const _ = require('lodash');
const app = express();
///////////////////////////////////////////////////////////////////////////////
// In order of simplicity we are not using any database. But you can write the
// same logic using MongoDB.
const users = [
// You know password for the user.
{name: 'user', password: 'pwd'},
// You don't know password for the admin.
{name: 'admin', password: Math.random().toString(32), canDelete: true},
];
let messages = [];
let lastId = 1;
function findUser(auth) {
return users.find((u) =>
u.name === auth.name &&
u.password === auth.password);
}
///////////////////////////////////////////////////////////////////////////////
app.use(bodyParser.json());
// Get all messages (publicly available).
app.get('/', (req, res) => {
res.send(messages);
});
// Post message (restricted for users only).
app.put('/', (req, res) => {
const user = findUser(req.body.auth || {});
if (!user) {
res.status(403).send({ok: false, error: 'Access denied'});
return;
}
const message = {
// Default message icon. Cen be overwritten by user.
icon: '👋',
};
_.merge(message, req.body.message, {
id: lastId++,
timestamp: Date.now(),
userName: user.name,
});
messages.push(message);
res.send({ok: true});
});
// Delete message by ID (restricted for users with flag "canDelete" only).
app.delete('/', (req, res) => {
const user = findUser(req.body.auth || {});
if (!user || !user.canDelete) {
res.status(403).send({ok: false, error: 'Access denied'});
return;
}
messages = messages.filter((m) => m.id !== req.body.messageId);
res.send({ok: true});
});
app.listen(3000);
console.log('Listening on port 3000...');