diff --git a/src/routes/aliases.js b/src/routes/aliases.js index 76b99af..d504216 100644 --- a/src/routes/aliases.js +++ b/src/routes/aliases.js @@ -3,13 +3,14 @@ const router = express.Router(); const Aliases = require('../controllers/aliases'); const Pages = require('../controllers/pages'); const Alias = require('../models/alias'); +const verifyToken = require('./middlewares/token'); /** * GET /* * * Return document with given alias */ -router.get('*', async (req, res) => { +router.get('*', verifyToken, async (req, res) => { try { const alias = await Aliases.get(req.originalUrl.slice(1)); // Cuts first '/' character diff --git a/src/routes/auth.js b/src/routes/auth.js index 5ba1b0a..8eb861c 100644 --- a/src/routes/auth.js +++ b/src/routes/auth.js @@ -28,6 +28,10 @@ router.get('/auth', csrfProtection, function (req, res) { router.post('/auth', parseForm, csrfProtection, async (req, res) => { let userDoc = await Users.get(); + if (!userDoc) { + throw new Error('Password not set'); + } + const passHash = userDoc.passHash; bcrypt.compare(req.body.password, passHash, async (err, result) => {