Gitlab@Informatics
Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
P
prjcloud_65160270
Manage
Activity
Members
Labels
Plan
Issues
Issue boards
Milestones
Wiki
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Package registry
Container registry
Model registry
Operate
Environments
Terraform modules
Monitor
Incidents
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
GitLab community forum
Contribute to GitLab
Provide feedback
Terms and privacy
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
65160270
prjcloud_65160270
Commits
b59744e8
Commit
b59744e8
authored
4 months ago
by
65160270
Browse files
Options
Downloads
Patches
Plain Diff
update-server
parent
f778f2cf
Branches
Branches containing commit
No related tags found
No related merge requests found
Changes
2
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
server.js
+27
-39
27 additions, 39 deletions
server.js
shop-routes/order.js
+1
-1
1 addition, 1 deletion
shop-routes/order.js
with
28 additions
and
40 deletions
server.js
+
27
−
39
View file @
b59744e8
...
...
@@ -5,8 +5,7 @@ const bcrypt = require("bcrypt");
const
pool
=
require
(
"
./config/database
"
);
require
(
"
dotenv
"
).
config
();
const
app
=
express
();
// ประกาศ app ที่นี่
const
app
=
express
();
const
MySQLStore
=
require
(
'
express-mysql-session
'
)(
session
);
const
sessionStore
=
new
MySQLStore
({
clearExpired
:
true
,
...
...
@@ -28,11 +27,13 @@ app.use(session({
secret
:
process
.
env
.
SESSION_SECRET
||
"
mysecret
"
,
resave
:
false
,
saveUninitialized
:
false
,
store
:
sessionStore
,
// ใช้ MySQL Store
store
:
sessionStore
,
rolling
:
true
,
// ต่ออายุ session ทุก request
cookie
:
{
maxAge
:
24
*
60
*
60
*
1000
,
// 24 hours
secure
:
false
,
// true ถ้าใช้ HTTPS
secure
:
process
.
env
.
NODE_ENV
===
"
production
"
,
// ใช้ secure ถ้าเป็น production
httpOnly
:
true
,
sameSite
:
"
strict
"
},
}));
...
...
@@ -40,6 +41,7 @@ app.use(session({
app
.
use
(
express
.
static
(
path
.
join
(
__dirname
,
"
public
"
)));
app
.
use
(
express
.
json
());
app
.
use
(
express
.
urlencoded
({
extended
:
true
}));
// Middleware เช็ค Session
app
.
use
((
req
,
res
,
next
)
=>
{
console
.
log
(
"
Session Middleware Checked
"
);
...
...
@@ -66,14 +68,10 @@ app.use("/", indexRoutes);
app
.
use
(
"
/cart
"
,
cartRoutes
);
app
.
use
(
"
/order
"
,
orderRoutes
);
//
Route สำหรับ
Checkout
// Checkout
Route
app
.
get
(
'
/order/checkout
'
,
isLoggedIn
,
(
req
,
res
)
=>
{
console
.
log
(
"
Session:
"
,
req
.
session
);
// ตรวจสอบ Session
res
.
render
(
'
checkout
'
);
// แสดงหน้า Checkout
});
app
.
get
(
'
/register
'
,
(
req
,
res
)
=>
{
res
.
render
(
'
register
'
);
// ตรวจสอบว่า 'views/login.ejs' มีอยู่จริง
console
.
log
(
"
Session:
"
,
req
.
session
);
res
.
render
(
'
checkout
'
,
{
user
:
req
.
session
.
user
});
});
// Register Route (POST)
...
...
@@ -86,13 +84,11 @@ app.post("/register", async (req, res) => {
const
hashedPassword
=
await
bcrypt
.
hash
(
password
,
10
);
const
[
existingUser
]
=
await
pool
.
execute
(
"
SELECT * FROM users WHERE email = ?
"
,
[
email
]);
if
(
existingUser
.
length
>
0
)
{
return
res
.
status
(
400
).
json
({
message
:
"
Email is already registered.
"
});
}
await
pool
.
execute
(
"
INSERT INTO users (email, password, name) VALUES (?, ?, ?)
"
,
[
email
,
hashedPassword
,
name
]);
console
.
log
(
"
User registered successfully.
"
);
res
.
status
(
201
).
json
({
success
:
true
,
message
:
"
Registration successful.
"
});
}
catch
(
error
)
{
console
.
error
(
"
Registration error:
"
,
error
);
...
...
@@ -100,10 +96,6 @@ app.post("/register", async (req, res) => {
}
});
app
.
get
(
'
/login
'
,
(
req
,
res
)
=>
{
res
.
render
(
'
login
'
);
// ตรวจสอบว่า 'views/login.ejs' มีอยู่จริง
});
// Login Route (POST)
app
.
post
(
"
/login
"
,
async
(
req
,
res
)
=>
{
try
{
...
...
@@ -123,12 +115,14 @@ app.post("/login", async (req, res) => {
return
res
.
status
(
400
).
json
({
message
:
"
Invalid email or password.
"
});
}
req
.
session
.
regenerate
((
err
)
=>
{
if
(
err
)
{
console
.
error
(
"
Session regeneration failed:
"
,
err
);
return
res
.
status
(
500
).
json
({
message
:
"
Login failed.
"
});
}
req
.
session
.
user
=
{
id
:
user
.
id
,
email
:
user
.
email
};
console
.
log
(
"
Session after login:
"
,
req
.
session
);
// Redirect ไปยังหน้า Checkout
return
res
.
redirect
(
'
/order/checkout
'
);
res
.
redirect
(
'
/order/checkout
'
);
});
}
catch
(
error
)
{
console
.
error
(
"
Login error:
"
,
error
);
res
.
status
(
500
).
json
({
message
:
"
Login failed.
"
});
...
...
@@ -136,30 +130,24 @@ app.post("/login", async (req, res) => {
});
// Logout Route
app
.
get
(
"
/logout
"
,
(
req
,
res
)
=>
{
req
.
session
.
destroy
((
err
)
=>
{
if
(
err
)
{
console
.
error
(
"
Logout error:
"
,
err
);
return
res
.
status
(
500
).
json
({
message
:
"
Logout failed.
"
});
}
res
.
redirect
(
"
/login
"
);
});
});
app
.
post
(
'
/logout
'
,
(
req
,
res
)
=>
{
req
.
session
.
destroy
(
err
=>
{
if
(
err
)
{
return
res
.
status
(
500
).
json
({
message
:
"
Logout failed
"
});
}
res
.
clearCookie
(
'
connect.sid
'
);
// ล้าง session cookie
res
.
clearCookie
(
'
connect.sid
'
);
res
.
status
(
200
).
json
({
message
:
"
Logged out successfully
"
});
});
});
// Search Route (ป้องกัน SQL Injection)
app
.
get
(
"
/search
"
,
async
(
req
,
res
)
=>
{
const
searchQuery
=
req
.
query
.
query
;
try
{
const
sanitizedQuery
=
searchQuery
.
replace
(
/
[
%_
]
/g
,
"
\\
$&
"
);
const
[
results
]
=
await
pool
.
execute
(
"
SELECT * FROM products WHERE name LIKE ? OR description LIKE ?
"
,
[
`%
${
s
earch
Query
}
%`
,
`%
${
s
earch
Query
}
%`
]
[
`%
${
s
anitized
Query
}
%`
,
`%
${
s
anitized
Query
}
%`
]
);
res
.
render
(
"
index
"
,
{
products
:
results
});
}
catch
(
err
)
{
...
...
This diff is collapsed.
Click to expand it.
shop-routes/order.js
+
1
−
1
View file @
b59744e8
...
...
@@ -51,7 +51,7 @@ router.get('/history', isAuthenticated, async (req, res) => {
});
// แสดงรายละเอียดออเดอร์ (เฉพาะผู้ที่ Login)
router
.
get
(
'
/
order-
detail
s
/:orderId
'
,
isAuthenticated
,
async
(
req
,
res
)
=>
{
router
.
get
(
'
/detail/:orderId
'
,
isAuthenticated
,
async
(
req
,
res
)
=>
{
try
{
if
(
!
req
.
session
.
id
)
{
return
res
.
status
(
400
).
json
({
message
:
"
Session ID not found. Please login again.
"
});
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment