mirror of
https://github.com/kevin-DL/complete-node-bootcamp.git
synced 2026-01-18 05:45:11 +00:00
Initial commit 🚀
This commit is contained in:
87
4-natours/after-section-12/app.js
Normal file
87
4-natours/after-section-12/app.js
Normal file
@@ -0,0 +1,87 @@
|
||||
const path = require('path');
|
||||
const express = require('express');
|
||||
const morgan = require('morgan');
|
||||
const rateLimit = require('express-rate-limit');
|
||||
const helmet = require('helmet');
|
||||
const mongoSanitize = require('express-mongo-sanitize');
|
||||
const xss = require('xss-clean');
|
||||
const hpp = require('hpp');
|
||||
const cookieParser = require('cookie-parser');
|
||||
|
||||
const AppError = require('./utils/appError');
|
||||
const globalErrorHandler = require('./controllers/errorController');
|
||||
const tourRouter = require('./routes/tourRoutes');
|
||||
const userRouter = require('./routes/userRoutes');
|
||||
const reviewRouter = require('./routes/reviewRoutes');
|
||||
const viewRouter = require('./routes/viewRoutes');
|
||||
|
||||
const app = express();
|
||||
|
||||
app.set('view engine', 'pug');
|
||||
app.set('views', path.join(__dirname, 'views'));
|
||||
|
||||
// 1) GLOBAL MIDDLEWARES
|
||||
// Serving static files
|
||||
app.use(express.static(path.join(__dirname, 'public')));
|
||||
|
||||
// Set security HTTP headers
|
||||
app.use(helmet());
|
||||
|
||||
// Development logging
|
||||
if (process.env.NODE_ENV === 'development') {
|
||||
app.use(morgan('dev'));
|
||||
}
|
||||
|
||||
// Limit requests from same API
|
||||
const limiter = rateLimit({
|
||||
max: 100,
|
||||
windowMs: 60 * 60 * 1000,
|
||||
message: 'Too many requests from this IP, please try again in an hour!'
|
||||
});
|
||||
app.use('/api', limiter);
|
||||
|
||||
// Body parser, reading data from body into req.body
|
||||
app.use(express.json({ limit: '10kb' }));
|
||||
app.use(express.urlencoded({ extended: true, limit: '10kb' }));
|
||||
app.use(cookieParser());
|
||||
|
||||
// Data sanitization against NoSQL query injection
|
||||
app.use(mongoSanitize());
|
||||
|
||||
// Data sanitization against XSS
|
||||
app.use(xss());
|
||||
|
||||
// Prevent parameter pollution
|
||||
app.use(
|
||||
hpp({
|
||||
whitelist: [
|
||||
'duration',
|
||||
'ratingsQuantity',
|
||||
'ratingsAverage',
|
||||
'maxGroupSize',
|
||||
'difficulty',
|
||||
'price'
|
||||
]
|
||||
})
|
||||
);
|
||||
|
||||
// Test middleware
|
||||
app.use((req, res, next) => {
|
||||
req.requestTime = new Date().toISOString();
|
||||
console.log(req.cookies);
|
||||
next();
|
||||
});
|
||||
|
||||
// 3) ROUTES
|
||||
app.use('/', viewRouter);
|
||||
app.use('/api/v1/tours', tourRouter);
|
||||
app.use('/api/v1/users', userRouter);
|
||||
app.use('/api/v1/reviews', reviewRouter);
|
||||
|
||||
app.all('*', (req, res, next) => {
|
||||
next(new AppError(`Can't find ${req.originalUrl} on this server!`, 404));
|
||||
});
|
||||
|
||||
app.use(globalErrorHandler);
|
||||
|
||||
module.exports = app;
|
||||
Reference in New Issue
Block a user