Disxt_ Deliverable is a simple Rest API built using Mongodb, Express and Node that implements CRUD tasks on products as well as implements authentication and role-based authorization.
To get the server running locally:
To run with docker:
NodeJS - is a JavaScript runtime built on Chrome's V8 JavaScript engine.
The Express.js backend framework was used to build the server. Fast, unopinionated, minimalist web framework for Node.js
Linter
Test Tools
The API endpoints for the server has a BaseUrl of (http://localhost:3000/api/v1)
| Method | Endpoint | Access Control | Description |
|---|---|---|---|
| POST | /auth/login | all users | Returns info for the logged in user. |
| POST | /auth/signup | all users | Adds a user to the database. |
| GET | /auth/logout | authenticated users | Logs out a user |
| GET | /users/:id | authenticated users | Client can view personal info, admins can view info of other users |
| PATCH | /users/:id | admins | Admins can assign the role of admins to clients |
{
_id objectId
username string unique required
firstname string required
lastname string required
age number required
password string required
}
URL: {BaseUrl}/auth/signup
Returns: An object containing the user credentials.
Input
{
"username": "username",
"firstname": "userfirstname",
"lastname": "userlastname",
"password": "n17chrobmn",
"age": 20
}
Returns
{
"status": 201,
"data": {
"id": "5fa5c57e29e83b05c8b000cb",
"username": "username",
"firstname": "userfirstname",
"lastname": "userlastname",
"age": "20"
}
}
URL: {BaseUrl}/auth/login
Returns: An object containing the user credentials.
Input
{
"username": "username",
"password": "n17chrobmn",
}
Returns
{
"status": 200,
"data": {
"id": "5fa5c57e29e83b05c8b000cb",
"username": "username"
}
}
and generate a jwt embedded in a cookie for better security against XSS
URL: {BaseUrl}/users/5fa5c57e29e83b05c8b000cb
Returns: An object which holds the users credentials.
Input
{
"role": "admin"
}
Returns
{ "status":200,
"data": {
"_id": "5fa5c57e29e83b05c8b000cb",
"username": "username",
"firstname": "userfirstname",
"lastname": "userlastname",
"age": "20",
"role": "admin"
}
}
URL: {BaseURl}/users/5fa5c57e29e83b05c8b000cb
Returns: An object with the user details
Returns
{ "status": 200,
"data": {
"_id": "5fa5c57e29e83b05c8b000cb",
"username": "username",
"firstname": "userfirstname",
"lastname": "userlastname",
"age": "20",
"role": "admin"
}
}
URL: {BaseURl}/auth/logout
Returns
{
"status": 200,
"data": "Logout Successful"
}
| Method | Endpoint | Access Control | Description |
|---|---|---|---|
| GET | /products | authenticated users | Returns all products |
| GET | /products/:productId | authenticated users | Returns a single product with the created_by option showing for only admins |
| POST | /products | only admins | Adds a product |
| PUT | /products/:productId | only admins | Update the product information |
| DELETE | /products/:productId | only admins | Deletes a product |
{
_id objectId
name string required
description string required
price number required
created_by objectId ref("users") required
}
URL: {BaseUrl}/products
Returns: An object containing the product information.
Input
{
"name": "amaglobe",
"description": "finder",
"price": 300.00000067
}
Returns
{
"status": 201,
"data": {
"_id": "5fa536a56e382a039be74e2c",
"name": "amaglobe",
"description": "finder",
"price": 300.00000067,
"created_by": "5fa5c57e29e83b05c8b000cb"
}
}
}
URL: {BaseUrl}/products/5fa536a56e382a039be74e2c
Returns: An object containing the product information.
Input
{
"name": "amafly",
"description": "something different",
}
Returns
{
"status": 200,
"data": {
"_id": "5fa536a56e382a039be74e2c",
"name": "amafly",
"description": "something different",
"price": 300.00000067,
"created_by":
{
"_id": "5fa51ee1bf11b5001f4c177d",
"username": "b1"
}
}
}
URL: {BaseUrl}/products/5fa5c57e29e83b05c8b000cb
Returns: An object with product information.
Returns
{ "status":200,
"data": {
"_id": "5fa5c57e29e83b05c8b000cb",
"name": "rollercoster",
"description": "something different",
"price": 300.00000067,
"created_by": {
"_id": "5fa51ee1bf11b5001f4c177d",
"username": "b1"
}
}
}
URL: {BaseURl}/products
Returns: List of all products
Returns
{
"status": 200,
"data": [
{
"_id": "5fa53047eec46902cc1497ef",
"name": "Amavibes",
"price": 3000,
"description": "Amazon campaign for musics",
"created_by": { // this field shows where the logged in user is an admin
"_id": "5fa51ee1bf11b5001f4c177d",
"username": "b1"
}
},
{
"_id": "5fa536a56e382a039be74e2c",
"name": "Amafly",
"price": 3000,
"description": "Amazon campaign for musics",
"created_by": { // this field shows where the logged in user is an admin
"_id": "5fa51ee1bf11b5001f4c177d",
"username": "b1"
}
}
]
}
URL: {BaseUrl}/products/5fa5c57e29e83b05c8b000cb
Returns
{
"status": 200,
"data": "Product Deleted"
}
In order for the app to function correctly, the user must set up their own environment variables.
create a .env file that includes the following:
All validation errors are in the form of
{
"status": 400,
"error": [
"role must be one of [admin, client]",
"role contains an invalid value",
"role is not allowed to be empty"
]
}
other errors are in the form of
{
"status": {ErrorstatusCode},
"error": "error message"
}
Content type
Image
Digest
Size
50.3 MB
Last updated
almost 6 years ago
docker pull mrcea/disxt