-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathorders-router.js
64 lines (59 loc) · 2.08 KB
/
orders-router.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
const { ObjectId } = require('bson');
const express = require('express');
let router = express.Router();
router.get("/", getOrderForm);
router.post("/", userOrder);
router.get("/:ordId", getOrderSum);
function getOrderForm(req, res, next){
if (req.session.loggedIn){
res.status(200).render("orderForm.pug", {users: {session: req.session}});
} else {
res.status(401).send("You are not logged in");
next();
}
}
function getOrderSum(req, res, next){
try {
let orderId = new ObjectId(req.params.ordId);
req.app.locals.db.collection("orders").findOne({_id: orderId}, function(err, result){
if (err){
res.status(500).send("Error occured when finding order");
next();
} else if(result == null){
throw err;
} else {
let data = {session: req.session, 'order': result, 'user': {}};
let userId = new ObjectId(result.user_id);
req.app.locals.db.collection("users").findOne({_id: userId}, function(err, result){
if (result.privacy == true && req.session.username != result.username){
res.status(403).send("User is private");
next();
} else {
data['user'] = result;
res.status(200).render("orderSum.pug", {users: data});
}
});
}
});
} catch(err) {
res.status(404).send("Order not found");
next();
}
}
function userOrder(req, res, next){
//add order to db storing the user _id
let id = req.session.userId.toString();
let order = {};
order['user_id'] = id;
order['order'] = req.body;
req.app.locals.db.collection("orders").insertOne(order, function(err, result){
if (err){
res.status(500).send("Error occured when adding order to db");
next();
} else {
res.status(200).send("Order added to db");
next();
}
});
}
module.exports = router;