| 12
 3
 4
 5
 6
 7
 8
 9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
 100
 101
 102
 103
 104
 105
 106
 107
 108
 109
 110
 111
 112
 113
 114
 115
 116
 117
 118
 119
 120
 121
 122
 123
 124
 125
 126
 127
 128
 129
 130
 131
 132
 133
 134
 135
 136
 137
 138
 139
 140
 141
 142
 143
 
 | const fs = require('fs');const express = require('express');
 const session = require('express-session');
 const bodyParse = require('body-parser');
 const app = express();
 const PORT = process.env.PORT || 80;
 const SECRET = process.env.SECRET || "cybershop_challenge_secret"
 
 const adminUser = {
 username: "admin",
 password: "😀admin😀",
 money: 9999
 };
 
 app.use(bodyParse.urlencoded({extended: false}));
 app.use(express.json());
 app.use(session({
 secret: SECRET,
 saveUninitialized: false,
 resave: false,
 cookie: { maxAge: 3600 * 1000 }
 }));
 app.use(express.static("static"));
 
 app.get('/isLogin', function(req, res) {
 if(req.session.username) {
 return res.json({
 code: 2,
 username: req.session.username,
 money: req.session.money
 });
 }else{
 return res.json({code: 0, msg: 'Please login!'});
 }
 });
 
 
 app.post('/login', function(req, res) {
 let username = req.body.username;
 let password = req.body.password;
 if (typeof username !== 'string' || username === '' || typeof password !== 'string' || password === '') {
 return res.json({code: 4, msg: 'illegal username or password!'})
 }
 
 if(username === adminUser.username && password === adminUser.password.substring(1,6)) {//only admin need password
 req.session.username = username;
 req.session.money = adminUser.money;
 return res.json({
 code: 1,
 username: username,
 money: req.session.money,
 msg: 'admin login success!'
 });
 }
 req.session.username = username;
 req.session.money = 10;
 return res.json({
 code: 1,
 username: username,
 money: req.session.money,
 msg: `${username} login success!`
 });
 });
 
 app.post('/changeUsername', function(req, res) {
 if(!req.session.username) {
 return res.json({
 code: 0,
 msg: 'please login!'
 });
 }
 let username = req.body.username;
 if (typeof username !== 'string' || username === '') {
 return res.json({code: 4, msg: 'illegal username!'})
 }
 req.session.username = username;
 return res.json({
 code: 2,
 username: username,
 money: req.session.money,
 msg: 'Username change success'
 });
 });
 
 //购买商品的接口
 function buyApi(user, product) {
 let order = {};
 if(!order[user.username]) {
 order[user.username] = {};
 }
 
 Object.assign(order[user.username], product);
 
 if(product.id === 1) {             //buy fakeFlag
 if(user.money >= 10) {
 user.money -= 10;
 Object.assign(order, { msg:  fs.readFileSync('/fakeFlag').toString() });
 }else{
 Object.assign(order,{ msg: "you don't have enough money!" });
 }
 }else if(product.id === 2) {        //buy flag
 if(user.money >= 11 && user.token) {  //do u have token?
 if(JSON.stringify(product).includes("flag")) {
 Object.assign(order,{ msg: "hint: go to 'readFileSync'!!!!" });
 }else{
 user.money -= 11;
 Object.assign(order,{ msg: fs.readFileSync(product.name).toString() });
 }
 }else {
 Object.assign(order,{ msg: "nononono!" });
 }
 }else {
 Object.assign(order,{ code: 0, msg: "no such product!" });
 }
 Object.assign(order, { username: user.username, code: 3, money: user.money });
 return order;
 }
 
 app.post('/buy', function(req, res) {
 if(!req.session.username) {
 return res.json({
 code: 0,
 msg: 'please login!'
 });
 }
 var user = {
 username: req.session.username,
 money: req.session.money
 };
 var order = buyApi(user, req.body);
 req.session.money = user.money;
 res.json(order);
 });
 
 app.get('/logout', function(req, res) {
 req.session.destroy();
 return res.json({
 code: 0,
 msg: 'logout success!'
 });
 });
 
 app.listen(PORT, () => {console.log(`APP RUN IN ${PORT}`)});
 
 |