Sign inSign up

mrcea/disxt

By mrcea

•Updated almost 6 years ago

Image
0

160

mrcea/disxt repository overview

⁠Disxt_Deliverable

Disxt_ Deliverable is a simple Rest API built using Mongodb, Express and Node that implements CRUD tasks on products as well as implements authentication and role-based authorization.

⁠NPM Scripts

To get the server running locally:

  • Clone this repo
  • npm install to install all required dependencies
  • npm run start:dev to start the local server
  • npm test to start server using testing environment

To run with docker:

  • Clone this repo
  • docker-compose build to build an image
  • create a .env file at the root folder of this project and put your environmental variables
  • docker-compose run to create a running container with default environment development

⁠Technologies

NodeJS⁠ - is a JavaScript runtime built on Chrome's V8 JavaScript engine.

The Express.js⁠ backend framework was used to build the server. Fast, unopinionated, minimalist web framework for Node.js

⁠Supporting Packages

Linter

  • ESLint⁠ - The pluggable linting utility for JavaScript and JSX

Test Tools

  • Jest⁠ - Jest is a delightful JavaScript Testing Framework with a focus on simplicity.
  • Supertest⁠

⁠API Documentation

The API endpoints for the server has a BaseUrl of (http://localhost:3000/api/v1⁠)

⁠USERS


⁠User Routes
MethodEndpointAccess ControlDescription
POST/auth/loginall usersReturns info for the logged in user.
POST/auth/signupall usersAdds a user to the database.
GET/auth/logoutauthenticated usersLogs out a user
GET/users/:idauthenticated usersClient can view personal info, admins can view info of other users
PATCH/users/:idadminsAdmins can assign the role of admins to clients

{
  _id objectId
  username string unique required
  firstname string  required
  lastname string required
  age number required
  password string required
}
⁠Actions
⁠Add a new user [POST]

URL: {BaseUrl}/auth/signup

Returns: An object containing the user credentials.

Input

{
 "username": "username",
 "firstname": "userfirstname",
 "lastname": "userlastname",
 "password": "n17chrobmn",
 "age": 20
}

Returns

{
  "status": 201,
  "data": {
    "id": "5fa5c57e29e83b05c8b000cb",
    "username": "username",
    "firstname": "userfirstname",
    "lastname": "userlastname",
    "age": "20"
  }
}
⁠Login a user [POST]

URL: {BaseUrl}/auth/login

Returns: An object containing the user credentials.

Input

{
 "username": "username",
 "password": "n17chrobmn",
}

Returns

{
  "status": 200,
  "data": {
    "id": "5fa5c57e29e83b05c8b000cb",
    "username": "username"
  }
}

and generate a jwt embedded in a cookie for better security against XSS

⁠Edit User Role [PATCH]

URL: {BaseUrl}/users/5fa5c57e29e83b05c8b000cb

Returns: An object which holds the users credentials.

Input

{
 "role": "admin"
}

Returns


{ "status":200,
  "data": {
    "_id": "5fa5c57e29e83b05c8b000cb",
    "username": "username",
    "firstname": "userfirstname",
    "lastname": "userlastname",
    "age": "20",
    "role": "admin"
  }
}

⁠Get a user [GET]

URL: {BaseURl}/users/5fa5c57e29e83b05c8b000cb

Returns: An object with the user details

Returns


{ "status": 200,
  "data": {
    "_id": "5fa5c57e29e83b05c8b000cb",
    "username": "username",
    "firstname": "userfirstname",
    "lastname": "userlastname",
    "age": "20",
    "role": "admin"
  }
}
⁠Logout a user [GET]

URL: {BaseURl}/auth/logout

Returns

{
  "status": 200,
  "data": "Logout Successful"
}

⁠Products


⁠Product Routes
MethodEndpointAccess ControlDescription
GET/productsauthenticated usersReturns all products
GET/products/:productIdauthenticated usersReturns a single product with the created_by option showing for only admins
POST/productsonly adminsAdds a product
PUT/products/:productIdonly adminsUpdate the product information
DELETE/products/:productIdonly adminsDeletes a product
{
  _id objectId
  name string required
  description string required
  price number required
  created_by objectId ref("users") required
}
⁠Actions
⁠Add a new products [POST]

URL: {BaseUrl}/products

Returns: An object containing the product information.

Input

{
	"name": "amaglobe",
	"description": "finder",
	"price": 300.00000067
}

Returns

{
  "status": 201,
  "data": {
    "_id": "5fa536a56e382a039be74e2c",
    "name": "amaglobe",
    "description": "finder",
    "price": 300.00000067,
    "created_by": "5fa5c57e29e83b05c8b000cb"
    }
  }
}

⁠Update a product [PUT]

URL: {BaseUrl}/products/5fa536a56e382a039be74e2c

Returns: An object containing the product information.

Input

{
 "name": "amafly",
 "description": "something different",
}

Returns

{
  "status": 200,
  "data": {
    "_id": "5fa536a56e382a039be74e2c",
    "name": "amafly",
    "description": "something  different",
    "price": 300.00000067,
    "created_by":
       {
        "_id": "5fa51ee1bf11b5001f4c177d",
        "username": "b1"
      }
  }
}
⁠Get a product [GET]

URL: {BaseUrl}/products/5fa5c57e29e83b05c8b000cb

Returns: An object with product information.

Returns


{ "status":200,
  "data": {
    "_id": "5fa5c57e29e83b05c8b000cb",
    "name": "rollercoster",
    "description": "something  different",
    "price": 300.00000067,
    "created_by": {
        "_id": "5fa51ee1bf11b5001f4c177d",
        "username": "b1"
      }
  }
}

⁠Get all products [GET]

URL: {BaseURl}/products

Returns: List of all products

Returns


{
  "status": 200,
  "data": [
    {
      "_id": "5fa53047eec46902cc1497ef",
      "name": "Amavibes",
      "price": 3000,
      "description": "Amazon campaign for musics",
      "created_by": { // this field shows where the logged in user is an admin
        "_id": "5fa51ee1bf11b5001f4c177d",
        "username": "b1"
      }
    },
    {
      "_id": "5fa536a56e382a039be74e2c",
      "name": "Amafly",
      "price": 3000,
      "description": "Amazon campaign for musics",
      "created_by": {  // this field shows where the logged in user is an admin
        "_id": "5fa51ee1bf11b5001f4c177d",
        "username": "b1"
      }
    }
  ]
}

⁠Delete a Product [DELETE]

URL: {BaseUrl}/products/5fa5c57e29e83b05c8b000cb

Returns

{
  "status": 200,
  "data": "Product Deleted"
}

⁠Environment Variables

In order for the app to function correctly, the user must set up their own environment variables.

create a .env file that includes the following:

  • PORT - The port the server will start on functionality not available in SQLite
  • MONGO_URL - mongodb development and production url
  • TEST_URL - mongodb test url
  • ADMIN_LOGIN - one time password for assigning first signup user to admin role, must meet the format for password
  • ACCESS_SECRET - secret for signing JWT

⁠Error Handling

⁠Input Validation Errors

All validation errors are in the form of

{
  "status": 400,
  "error": [
    "role must be one of [admin, client]",
    "role contains an invalid value",
    "role is not allowed to be empty"
  ]
}
⁠Other Errors

other errors are in the form of

{
  "status": {ErrorstatusCode},
  "error": "error message"
}

Tag summary

Content type

Image

Digest

Size

50.3 MB

Last updated

almost 6 years ago

docker pull mrcea/disxt