mirror of
https://github.com/HabitRPG/habitica.git
synced 2025-12-18 15:17:25 +01:00
* Change update username API call
The call no longer requires a password and also validates the username.
* Implement API call to verify username without setting it
* Improve coding style
* Apply username verification to registration
* Update error messages
* Validate display names.
* Fix API early Stat Point allocation (#10680)
* Refactor hasClass check to common so it can be used in shared & server-side code
* Check that user has selected class before allocating stat points
* chore(event): end Ember Hatching Potions
* chore(analytics): reenable navigation tracking
* update bcrypt
* Point achievement modal links to main site (#10709)
* Animal ears after death (#10691)
* Animal Ears purchasable with Gold if lost in Death
* remove ears from pinned items when set is bought
* standardise css and error handling for gems and coins
* revert accidental new line
* fix client tests
* Reduce margin-bottom of checklist-item from 10px to -3px. (#10684)
* chore(i18n): update locales
* 4.61.1
* feat(content): Subscriber Items and Magic Potions
* chore(sprites): compile
* chore(i18n): update locales
* 4.62.0
* Display notification for users to confirm their username
* fix typo
* WIP(usernames): Changes to address #10694
* WIP(usernames): Further changes for #10694
* fix(usernames): don't show spurious headings
* Change verify username notification to new version
* Improve feedback for invalid usernames
* Allow user to set their username again to confirm it
* Improve validation display for usernames
* Temporarily move display name validation outside of schema
* Improve rendering banner about sleeping in the inn
See #10695
* Display settings in one column
* Position inn banner when window is resized
* Update inn banner handling
* Fix banner offset on initial load
* Fix minor issues.
* Issue: 10660 - Fixed. Changed default to Please Enter A Value (#10718)
* Issue: 10660 - Fixed. Changed default to Please Enter A Value
* Issue: 10660 - Fixed/revision 2 Changed default to Enter A Value
* chore(news): Bailey announcements
* chore(i18n): update locales
* 4.62.1
* adjust wiki link for usernameInfo string
https://github.com/HabitRPG/habitica-private/issues/7#issuecomment-425405425
* raise coverage for tasks api calls (#10029)
* - updates a group task - approval is required
- updates a group task with checklist
* add expect to test the new checklist length
* - moves tasks to a specified position out of length
* remove unused line
* website getter tasks tests
* re-add sanitizeUserChallengeTask
* change config.json.example variable to be a string not a boolean
* fix tests - pick the text / up/down props too
* fix test - remove changes on text/up/down - revert sanitize condition - revert sanitization props
* Change update username API call
The call no longer requires a password and also validates the username.
* feat(content): Subscriber Items and Magic Potions
* Re-add register call
* Fix merge issue
* Fix issue with setting username
* Implement new alert style
* Display username confirmation status in settings
* Add disclaimer to change username field
* validate username in settings
* Allow specific fields to be focused when opening site settings
* Implement requested changes.
* Fix merge issue
* Fix failing tests
* verify username when users register with username and password
* Set ID for change username notification
* Disable submit button if username is invalid
* Improve username confirmation handling
* refactor(settings): address remaining code comments on auth form
* Revert "refactor(settings): address remaining code comments on auth form"
This reverts commit 9b6609ad64.
* Social user username (#10620)
* Refactored private functions to library
* Refactored social login code
* Added username to social registration
* Changed id library
* Added new local auth check
* Fixed export error. Fixed password check error
* fix(settings): password not available on client
* refactor(settings): more sensible placement of methods
* chore(migration): script to hand out procgen usernames
* fix(migration): don't give EVERYONE new names you doofus
* fix(migration): limit data retrieved, be extra careful about updates
* fix(migration): use missing field, not migration tag, for query
* fix(migration): unused var
* fix(usernames): only generate 20 characters
* fix(migration): set lowerCaseUsername
252 lines
6.4 KiB
JavaScript
252 lines
6.4 KiB
JavaScript
import common from '../../../common';
|
|
import * as Tasks from '../../models/task';
|
|
import _ from 'lodash';
|
|
import {
|
|
BadRequest,
|
|
NotAuthorized,
|
|
} from '../../libs/errors';
|
|
import { model as User } from '../../models/user';
|
|
import {nameContainsSlur} from './validation';
|
|
|
|
|
|
export async function get (req, res, { isV3 = false }) {
|
|
const user = res.locals.user;
|
|
let userToJSON;
|
|
|
|
if (isV3) {
|
|
userToJSON = await user.toJSONWithInbox();
|
|
} else {
|
|
userToJSON = user.toJSON();
|
|
}
|
|
|
|
// Remove apiToken from response TODO make it private at the user level? returned in signup/login
|
|
delete userToJSON.apiToken;
|
|
|
|
if (!req.query.userFields) {
|
|
let {daysMissed} = user.daysUserHasMissed(new Date(), req);
|
|
userToJSON.needsCron = false;
|
|
if (daysMissed > 0) userToJSON.needsCron = true;
|
|
User.addComputedStatsToJSONObj(userToJSON.stats, userToJSON);
|
|
}
|
|
|
|
return res.respond(200, userToJSON);
|
|
}
|
|
|
|
const updatablePaths = [
|
|
'_ABtests.counter',
|
|
|
|
'flags.customizationsNotification',
|
|
'flags.showTour',
|
|
'flags.tour',
|
|
'flags.tutorial',
|
|
'flags.communityGuidelinesAccepted',
|
|
'flags.welcomed',
|
|
'flags.cardReceived',
|
|
'flags.warnedLowHealth',
|
|
'flags.newStuff',
|
|
|
|
'achievements',
|
|
|
|
'party.order',
|
|
'party.orderAscending',
|
|
'party.quest.completed',
|
|
'party.quest.RSVPNeeded',
|
|
|
|
'preferences',
|
|
'profile',
|
|
'stats',
|
|
'inbox.optOut',
|
|
'tags',
|
|
];
|
|
|
|
// This tells us for which paths users can call `PUT /user`.
|
|
// The trick here is to only accept leaf paths, not root/intermediate paths (see http://goo.gl/OEzkAs)
|
|
let acceptablePUTPaths = _.reduce(require('./../../models/user').schema.paths, (accumulator, val, leaf) => {
|
|
let found = _.find(updatablePaths, (rootPath) => {
|
|
return leaf.indexOf(rootPath) === 0;
|
|
});
|
|
|
|
if (found) accumulator[leaf] = true;
|
|
|
|
return accumulator;
|
|
}, {});
|
|
|
|
const restrictedPUTSubPaths = [
|
|
'stats.class',
|
|
|
|
'preferences.disableClasses',
|
|
'preferences.sleep',
|
|
'preferences.webhooks',
|
|
];
|
|
|
|
_.each(restrictedPUTSubPaths, (removePath) => {
|
|
delete acceptablePUTPaths[removePath];
|
|
});
|
|
|
|
const requiresPurchase = {
|
|
'preferences.background': 'background',
|
|
'preferences.shirt': 'shirt',
|
|
'preferences.size': 'size',
|
|
'preferences.skin': 'skin',
|
|
'preferences.hair.bangs': 'hair.bangs',
|
|
'preferences.hair.base': 'hair.base',
|
|
'preferences.hair.beard': 'hair.beard',
|
|
'preferences.hair.color': 'hair.color',
|
|
'preferences.hair.flower': 'hair.flower',
|
|
'preferences.hair.mustache': 'hair.mustache',
|
|
};
|
|
|
|
function checkPreferencePurchase (user, path, item) {
|
|
let itemPath = `${path}.${item}`;
|
|
let appearance = _.get(common.content.appearances, itemPath);
|
|
if (!appearance) return false;
|
|
if (appearance.price === 0) return true;
|
|
|
|
return _.get(user.purchased, itemPath);
|
|
}
|
|
|
|
export async function update (req, res, { isV3 = false }) {
|
|
const user = res.locals.user;
|
|
|
|
let promisesForTagsRemoval = [];
|
|
|
|
if (req.body['profile.name'] !== undefined) {
|
|
const newName = req.body['profile.name'];
|
|
if (newName === null) throw new BadRequest(res.t('invalidReqParams'));
|
|
if (newName.length > 30) throw new BadRequest(res.t('displaynameIssueLength'));
|
|
if (nameContainsSlur(newName)) throw new BadRequest(res.t('displaynameIssueSlur'));
|
|
}
|
|
|
|
_.each(req.body, (val, key) => {
|
|
let purchasable = requiresPurchase[key];
|
|
|
|
if (purchasable && !checkPreferencePurchase(user, purchasable, val)) {
|
|
throw new NotAuthorized(res.t('mustPurchaseToSet', { val, key }));
|
|
}
|
|
|
|
if (acceptablePUTPaths[key] && key !== 'tags') {
|
|
_.set(user, key, val);
|
|
} else if (key === 'tags') {
|
|
if (!Array.isArray(val)) throw new BadRequest('mustBeArray');
|
|
|
|
const removedTagsIds = [];
|
|
|
|
const oldTags = [];
|
|
|
|
// Keep challenge and group tags
|
|
user.tags.forEach(t => {
|
|
if (t.group) {
|
|
oldTags.push(t);
|
|
} else {
|
|
removedTagsIds.push(t.id);
|
|
}
|
|
});
|
|
|
|
user.tags = oldTags;
|
|
|
|
val.forEach(t => {
|
|
let oldI = removedTagsIds.findIndex(id => id === t.id);
|
|
if (oldI > -1) {
|
|
removedTagsIds.splice(oldI, 1);
|
|
}
|
|
|
|
user.tags.push(t);
|
|
});
|
|
|
|
// Remove from all the tasks
|
|
// NOTE each tag to remove requires a query
|
|
|
|
promisesForTagsRemoval = removedTagsIds.map(tagId => {
|
|
return Tasks.Task.update({
|
|
userId: user._id,
|
|
}, {
|
|
$pull: {
|
|
tags: tagId,
|
|
},
|
|
}, {multi: true}).exec();
|
|
});
|
|
} else {
|
|
throw new NotAuthorized(res.t('messageUserOperationProtected', { operation: key }));
|
|
}
|
|
});
|
|
|
|
|
|
await Promise.all([user.save()].concat(promisesForTagsRemoval));
|
|
|
|
let userToJSON = user;
|
|
|
|
if (isV3) userToJSON = await user.toJSONWithInbox();
|
|
|
|
return res.respond(200, userToJSON);
|
|
}
|
|
|
|
export async function reset (req, res, { isV3 = false }) {
|
|
const user = res.locals.user;
|
|
|
|
const tasks = await Tasks.Task.find({
|
|
userId: user._id,
|
|
...Tasks.taskIsGroupOrChallengeQuery,
|
|
}).select('_id type challenge group').exec();
|
|
|
|
const resetRes = common.ops.reset(user, tasks);
|
|
if (isV3) {
|
|
resetRes[0].user = await resetRes[0].user.toJSONWithInbox();
|
|
}
|
|
|
|
await Promise.all([
|
|
Tasks.Task.remove({_id: {$in: resetRes[0].tasksToRemove}, userId: user._id}),
|
|
user.save(),
|
|
]);
|
|
|
|
res.analytics.track('account reset', {
|
|
uuid: user._id,
|
|
hitType: 'event',
|
|
category: 'behavior',
|
|
});
|
|
|
|
res.respond(200, ...resetRes);
|
|
}
|
|
|
|
export async function reroll (req, res, { isV3 = false }) {
|
|
let user = res.locals.user;
|
|
let query = {
|
|
userId: user._id,
|
|
type: {$in: ['daily', 'habit', 'todo']},
|
|
...Tasks.taskIsGroupOrChallengeQuery,
|
|
};
|
|
let tasks = await Tasks.Task.find(query).exec();
|
|
const rerollRes = common.ops.reroll(user, tasks, req, res.analytics);
|
|
if (isV3) {
|
|
rerollRes[0].user = await rerollRes[0].user.toJSONWithInbox();
|
|
}
|
|
|
|
let promises = tasks.map(task => task.save());
|
|
promises.push(user.save());
|
|
|
|
await Promise.all(promises);
|
|
|
|
res.respond(200, ...rerollRes);
|
|
}
|
|
|
|
export async function rebirth (req, res, { isV3 = false }) {
|
|
const user = res.locals.user;
|
|
const tasks = await Tasks.Task.find({
|
|
userId: user._id,
|
|
type: {$in: ['daily', 'habit', 'todo']},
|
|
...Tasks.taskIsGroupOrChallengeQuery,
|
|
}).exec();
|
|
|
|
const rebirthRes = common.ops.rebirth(user, tasks, req, res.analytics);
|
|
if (isV3) {
|
|
rebirthRes[0].user = await rebirthRes[0].user.toJSONWithInbox();
|
|
}
|
|
|
|
const toSave = tasks.map(task => task.save());
|
|
|
|
toSave.push(user.save());
|
|
|
|
await Promise.all(toSave);
|
|
|
|
res.respond(200, ...rebirthRes);
|
|
}
|