1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143
| const fs = require('fs'); const express = require('express'); const session = require('express-session'); const bodyParse = require('body-parser'); const app = express(); const PORT = process.env.PORT || 80; const SECRET = process.env.SECRET || "cybershop_challenge_secret"
const adminUser = { username: "admin", password: "😀admin😀", money: 9999 };
app.use(bodyParse.urlencoded({extended: false})); app.use(express.json()); app.use(session({ secret: SECRET, saveUninitialized: false, resave: false, cookie: { maxAge: 3600 * 1000 } })); app.use(express.static("static"));
app.get('/isLogin', function(req, res) { if(req.session.username) { return res.json({ code: 2, username: req.session.username, money: req.session.money }); }else{ return res.json({code: 0, msg: 'Please login!'}); } });
app.post('/login', function(req, res) { let username = req.body.username; let password = req.body.password; if (typeof username !== 'string' || username === '' || typeof password !== 'string' || password === '') { return res.json({code: 4, msg: 'illegal username or password!'}) }
if(username === adminUser.username && password === adminUser.password.substring(1,6)) {//only admin need password req.session.username = username; req.session.money = adminUser.money; return res.json({ code: 1, username: username, money: req.session.money, msg: 'admin login success!' }); } req.session.username = username; req.session.money = 10; return res.json({ code: 1, username: username, money: req.session.money, msg: `${username} login success!` }); });
app.post('/changeUsername', function(req, res) { if(!req.session.username) { return res.json({ code: 0, msg: 'please login!' }); } let username = req.body.username; if (typeof username !== 'string' || username === '') { return res.json({code: 4, msg: 'illegal username!'}) } req.session.username = username; return res.json({ code: 2, username: username, money: req.session.money, msg: 'Username change success' }); });
//购买商品的接口 function buyApi(user, product) { let order = {}; if(!order[user.username]) { order[user.username] = {}; }
Object.assign(order[user.username], product);
if(product.id === 1) { //buy fakeFlag if(user.money >= 10) { user.money -= 10; Object.assign(order, { msg: fs.readFileSync('/fakeFlag').toString() }); }else{ Object.assign(order,{ msg: "you don't have enough money!" }); } }else if(product.id === 2) { //buy flag if(user.money >= 11 && user.token) { //do u have token? if(JSON.stringify(product).includes("flag")) { Object.assign(order,{ msg: "hint: go to 'readFileSync'!!!!" }); }else{ user.money -= 11; Object.assign(order,{ msg: fs.readFileSync(product.name).toString() }); } }else { Object.assign(order,{ msg: "nononono!" }); } }else { Object.assign(order,{ code: 0, msg: "no such product!" }); } Object.assign(order, { username: user.username, code: 3, money: user.money }); return order; }
app.post('/buy', function(req, res) { if(!req.session.username) { return res.json({ code: 0, msg: 'please login!' }); } var user = { username: req.session.username, money: req.session.money }; var order = buyApi(user, req.body); req.session.money = user.money; res.json(order); });
app.get('/logout', function(req, res) { req.session.destroy(); return res.json({ code: 0, msg: 'logout success!' }); });
app.listen(PORT, () => {console.log(`APP RUN IN ${PORT}`)});
|