jschan - Anonymous imageboard software. Classic look, modern features and feel. Works without JavaScript and supports Tor, I2P, Lokinet, etc.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

136 lines
3.3 KiB

5 years ago
'use strict';
process
.on('uncaughtException', console.error)
.on('unhandledRejection', console.error);
5 years ago
const express = require('express')
, session = require('express-session')
5 years ago
, MongoStore = require('connect-mongo')(session)
, path = require('path')
, app = express()
5 years ago
, bodyParser = require('body-parser')
, cookieParser = require('cookie-parser')
, configs = require(__dirname+'/configs/main.json')
, refererRegex = new RegExp(configs.refererRegex)
, Mongo = require(__dirname+'/db/db.js')
, { createHash } = require('crypto');
5 years ago
(async () => {
console.log('Starting in mode:', process.env.NODE_ENV);
5 years ago
// let db connect
console.log('connecting to db');
5 years ago
await Mongo.connect();
// disable useless express header
app.disable('x-powered-by');
// parse forms
5 years ago
app.use(bodyParser.urlencoded({extended: true}));
app.use(bodyParser.json());
//parse cookies
app.use(cookieParser());
5 years ago
// session store
app.use(session({
secret: configs.sessionSecret,
store: new MongoStore({ db: Mongo.client.db('sessions') }),
resave: false,
saveUninitialized: false,
cookie: {
httpOnly: true,
secure: true,
sameSite: 'strict',
}
5 years ago
}));
//trust proxy for nginx
app.set('trust proxy', 1);
5 years ago
//referer header check
app.use((req, res, next) => {
const ip = req.headers['x-real-ip'] || req.connection.remoteAddress
const ipHash = createHash('sha256').update(configs.ipHashSecret + ip).digest('base64');
res.locals.ip = ipHash;
if (req.method !== 'POST') {
return next();
}
if (configs.refererCheck === true && (!req.headers.referer || !req.headers.referer.match(refererRegex))) {
return res.status(403).render('message', {
'title': 'Forbidden',
'message': 'Invalid or missing "Referer" header. Are you posting from the correct URL?'
});
}
next();
})
5 years ago
// use pug view engine
app.set('view engine', 'pug');
app.set('views', path.join(__dirname, 'views/pages'));
if (configs.cacheTemplates === true) {
app.enable('view cache');
}
5 years ago
// routes
app.use('/forms', require(__dirname+'/controllers/forms.js'));
app.use('/', require(__dirname+'/controllers/pages.js'));
5 years ago
//404 catchall
5 years ago
app.get('*', (req, res) => {
res.status(404).render('404');
5 years ago
})
// catch any unhandled errors
5 years ago
app.use((err, req, res, next) => {
if (err.code === 'EBADCSRFTOKEN') {
return res.status(403).send('Invalid CSRF token');
5 years ago
}
console.error(err.stack);
return res.status(500).render('message', {
'title': 'Internal Server Error',
'redirect': req.headers.referer || '/'
});
5 years ago
})
// listen
const server = app.listen(configs.port, '127.0.0.1', () => {
console.log(`listening on port ${configs.port}`);
5 years ago
//let PM2 know that this is ready (for graceful reloads)
if (typeof process.send === 'function') { //make sure we are a child process
console.info('sending ready signal to PM2');
process.send('ready');
}
});
process.on('SIGINT', () => {
console.info('SIGINT signal received');
// Stops the server from accepting new connections and finishes existing connections.
server.close((err) => {
// if error, log and exit with error (1 code)
console.info('closing http server');
if (err) {
console.error(err);
process.exit(1);
}
// close database connection
console.info('closing db connection');
Mongo.client.close();
// now close without error
process.exit(0);
})
})
5 years ago
})();