# uni-society-manager [![travisbadge](https://travis-ci.org/Alpha-Atom/uni-society-manager.svg)](https://travis-ci.org/Alpha-Atom/uni-society-manager/builds) ![dankmeme](https://img.shields.io/badge/contains-dank%20memes-brightgreen.svg) Server for Integrated Project, powered by Express.js and Redis, listens for HTTPS requests on port 443 and HTTP requests on port 80 and port 3000. Certificate provided for free by the brilliant __[Lets Encrypt!](https://letsencrypt.org/)__ project. Routes with a ✓ next to them are tested on each commit with __[Travis CI](https://travis-ci.org/)__. Other routes are either so trivial that testing is not necessary, see `/hello/:name/` or have simply been tested by a human as unit tests have not yet been written. ![HTTPS Screenshot](http://i.imgur.com/HUOTv2o.png "HTTPS Hello World") * [uni-society-manager](#uni-society-manager) * [Installation](#installation) * [Running](#running) * [Testing](#testing) * [API](#api) * __Misc__ * [/hello/:name/](#helloname) * __User__ * [/user/register/](#userregister) ✓ * [/user/auth/](#userauth) * [/user/view/](#userview) * [/user/view/:user](#userviewuser) * __Society__ * [/society/create/](#societycreate) * [/society/view/](#societyview) * [/society/view/:society\_name](#societyviewsociety_name) * [/society/view/:society\_name/events](#societyviewsociety_nameevents) * [/society/join/](#societyjoin) * [/society/leave/](#societyleave) * [/society/promote/](#societypromote) * [/society/kick/](#societykick) * __Events__ * [/events/create/](#eventscreate) * [/events/view/:eventid](#eventsvieweventid) * [/events/pending/](#eventspending) * [/events/accepted/](#eventsaccepted) * [/events/declined/](#eventsdeclined) * [/events/accept/:eventid](#eventsaccepteventid) * [/events/decline/:eventid](#eventsdeclineeventid) * [/events/cancel/:eventid](#eventscanceleventid) * __Friends__ * [/friends/add/](#friendsadd) * [/friends/remove/](#friendsremove) ### Installation Instructions are for OSX El Capitan at time of writing. First install the Redis server: ``` brew install redis ``` Then clone this repository: ``` git clone https://github.com/Alpha-Atom/ip-project-server.git ``` And finally, install the dependencies ``` npm install ``` ### Running To run, first start Redis: ``` redis-server ``` Then start the Express framework using: ``` node index.js ``` A production environment, using HTTPS can be started using: ``` node index.js -p ``` Do note that this requires both cert.pem and key.pem to be in the root directory of the project for SSL or it will not start. ### Testing To test, start a __new__ Redis server somewhere other than the main database with: ``` redis-server ``` Then start up the Express framework using: ``` node index.js ``` You do not need to use the production environment for this. Finally run the tests with: ``` npm test ``` __DO NOT__ run `npm test` whilst the main database is running on `localhost:6379/0`. The testing command flushes that database at the end of the tests and this will occur regardless of test passes or failures. # API ### /hello/:name/ Returns "Hello :name!" or simply "Hello World!" if no name is present. Useful for checking if the server is running :) ### /user/register/ In order to register a new user account, a `POST` request should be sent, with the following data: ```javascript { "user": "FooBar", // Desired username goes here "password": "hunter2" // Desired password goes here } ``` The server will then respond with a JSON object that looks something like this: ```javascript { "registered": 1, // Value is 1 or 0 based on whether registration was successful "auth-key": "$2a$10$.X9YrNyd2R7b2ycAumHn.ONiINs2bCkRDupugu6sjZkUkPmXSaSra", // Value is an authentication key to be used in API requests "error": 0 // Error code, if an error occured. 0 indicates no error. } ``` The value of the error code will be `1` if the username already exists, and `2` if the request was malformed. ### /user/auth/ In order to log into an account, or essentially request a new authentication token, a `POST` request should be sent with the following data: ```javascript { "user": "FooBar", // Username goes here "password": "hunter2", // Password goes here } ``` Using this will then generate a new authentication key, **invalidating** any existing authentication key for that account. Note that you do not need to use /auth/ after registering as a new auth key is already generated. ```javascript { "logged_in": 1, // Value is 1 or 0 whether or not the login was successful "auth-key": "$2a$10$.X9YrNyd2R7b2ycAumHn.ONiINs2bCkRDupugu6sjZkUkPmXSaSra", // Only present if logged_in == 1, to be used in API requests "error": 0 // Error code, if an error occured. 0 indicates no error. } ``` The error codes are as follows, `1` indicates the username or password was invalid and `2` indicates that the login request was malformed. ### /user/view/ To view all the public information for all users at once, a `GET` request should be sent with no data, and the returned response will look like this: ```javascript { "users": [ { "username": "test1", "societies": [ "TestSociety2" ], "friends": [], "accepted_events": [] }, { "username": "test2", "societies": [ "TestSociety2" ], "friends": [], "accepted_events": [] }, { ... } // More items here ] } ``` There are no error codes for this route. ### /user/view/:user To view the public information for any given `:user`, a `GET` request should be sent with no data, and the returned response will look like this: ```javascript { "user": { "username": "test1", "societies": [ "TestSociety2" ], "friends": [], "accepted_events": [] }, "error": 0 } ``` The error codes are as follows, `1` indicates that the user does not exist. ### /society/create/ To create a new society, a `POST` request should be sent with the following data: ```javascript { "society": "FooBarSociety", // The name of the society to be created. "admins": ["FooBar", "BarFoo", "FarBoo"], // List of initial admins to be added, this list MUST include the user creating the society "description": "A description of the FooBarSociety society.", "auth": "$2a$10$.X9YrNyd2R7b2ycAumHn.ONiINs2bCkRDupugu6sjZkUkPmXSaSra", "image": "" } ``` If the society does not already exist, the new values will be added to the database and a response will be sent looking like this: ```javascript { "success": 1, // Indicates if a society was successfully created. "society": { "name": "FooBarSociety", "admins": ["FooBar", "BarFoo", "FarBoo"], "description": "A description of the FooBarSociety society.", "users": ["FooBar", "BarFoo", "FarBoo"], // At this point the users will simply be the admin list "image": "" }, // An object representing the society "error": 0 } ``` The error codes are as follows, `1` indicates a malformed request, `2` indicates that a society with that name already exists, and `3` indicates that the user does not have authorisation to create that society. (Note that the admin list must contain the username that is creating it.) ### /society/view/ To view a list of all the societies, a `GET` request should be sent with no data to this route with no parameter. The response will be formed as follows: ```javascript { "societies": [ { "name": "TestSociety", "admins": [ "test1", "test2" ], "description": "This is a test", "users": [ "test1", "test2" ] }, { "name": "TestSociety2", "admins": [ "test1", "test2" ], "description": "This is a test", "users": [ "test1", "test2" ] } ] } ``` There are no error codes for this route. ### /society/view/:society\_name To view a created society, :society\_name, a `GET` request should be sent with no data. The response will then be formed as follows: ```javascript { "society": { // Society object containing information about the society "name": "FooBarSociety", "admins": ["FooBar", "BarFoo", "FarBoo"], "description": "A description of the FooBarSociety society.", "users": ["FooBar", "BarFoo", "FarBoo"] }, "error": 0 // Error code if an error occured, 0 indicates no error. } ``` The error codes are as follows, `1` indicates that the society does not exist. ### /society/view/:society\_name/events To view all the events for a society, :society\_name, a `GET` request should be sent with the following data: ```javascript { "auth": "$2a$10$ruuu6QfYLjW1QKOwONVvkelXuh8EVFyug/kJvfaTNL0aXNGyODZ9K" } ``` Then the server will respond like this: ```javascript { "events": [ { "name": "Super Mario Kart Party", "location": "Marioland", "society": "TestSociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1" }, { "name": "Super Mario Kart Party 2", "location": "Marioland", "society": "TestSociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1" }, { ... }, { ... }, { ... }, { ... } ], "error": 0 } ``` The error codes are as follows, `1` indicates an invalid authentication key and `2` indicates a malformed request. ### /society/join/ To join a society, a `POST` request should be sent with the following data: ```javascript { "society": "TestSociety", // Society name here "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" // Auth key here } ``` The response is then formed as follows: ```javascript { "success": 1, // Indicates successfulness "error": 0 } ``` The error codes are as follows, `1` indicates that the user is already a member of that society and `2` indicates a malformed request. ### /society/leave/ To leave a society, a `POST` request should be sent with the following data: ```javascript { "society": "TestSociety", // Society name here "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" // Auth key here } ``` The response is then formed as follows: ```javascript { "success": 1, // Indicates successfulness "error": 0 } ``` The error codes are as follows, `1` indicates that the user isn't a member of that society and `2` indicates a malformed request. ### /society/promote/ To promote a user within a society, a `POST` request should be sent with the following data: ```javascript { "user": "Test1", "society": "TestSociety", "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then be formed as follows: ```javascript { "success": 1, "error": 0 } ``` The error codes are as follows, `1` indicates that the auth key is invalid, `2` indicates that the user does not belong to the society, `3` indicates that the user is already an admin and `4` indicates a malformed request. ### /society/kick/ To kick a user from a society, a `POST` request should be sent with the following data: ```javascript { "user": "Test3", "society": "TestSociety", "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then be formed as follows: ```javascript { "success": 1, "error": 0 } ``` The error codes are as follows, `1` indicates that the auth key is invalid, `2` indicates that the user does not belong to the society, `3` indicates that the user is an admin therefore cannot be kicked and `4` indicates a malformed request. ### /events/create/ To create a new event, a `POST` request should be sent with the following data: ```javascript { "society": "TestSociety", "name": "Test Event", "location": "Test Location", "start": "1460552065702", "end": "1460552065734", "details": "Some details about the test event", "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` Note that the end time of the event must be greater than the start time and the start time must be greater than Date.now(). Perhaps some client side verification that ensures, for example, the time of the event is the next day. The response will look like this: ```javascript { "success": 1, "event": { "id": "101898721", "name": "Super Mario Kart Party", "organiser": "test1", "attendees": [], "location": "Marioland", "society": "TestSociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us" }, "error": 0 } ``` The error codes are as follows, `1` indicates that the user is not an admin of the society, `2` indicates that the event times are in some way invalid and `3` indicates that the request was malformed. ### /events/view/:eventid To view any individual event, a `GET` request should be sent with the following data: ```javascript { "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "event": { "name": "Super Mario Kart Party", "location": "Marioland", "society": "TestSociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1", "attendees": [ "test1", "test2" ], "id": "101898721" }, "error": 0 } ``` The error codes are as follows, `1` indicates that the event does not exist, and `2` indicates a malformed request. ### /events/pending/ To get a users pending events, a `GET` request should be sent with the following data: ```javascript { "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "pending_events": [ { "name": "Super Mario Kart Party 5", "location": "Marioland", "society": "testsociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1", "attendees": [ "test1", "test2" ], "id": "851133039" }, { "name": "Super Mario Kart Party 6", "location": "Marioland", "society": "testsociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1", "attendees": [ "test1", "test2" ], "id": "838450388" }, { ... } ], "error": 0 } ``` The error codes are as follows, `1` indicates an invalid auth code and `2` indicates a malformed request. ### /events/accepted/ To get a users accepted events, a `GET` request should be sent with the following data: ```javascript { "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "accepted_events": [ { "name": "Super Mario Kart Party 5", "location": "Marioland", "society": "testsociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1", "attendees": [ "test1", "test2" ], "id": "851133039" }, { "name": "Super Mario Kart Party 6", "location": "Marioland", "society": "testsociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1", "attendees": [ "test1", "test2" ], "id": "838450388" }, { ... } ], "error": 0 } ``` The error codes are as follows, `1` indicates an invalid auth code and `2` indicates a malformed request. ### /events/declined/ To get a users declined events, a `GET` request should be sent with the following data: ```javascript { "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "declined_events": [ { "name": "Super Mario Kart Party 5", "location": "Marioland", "society": "testsociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1", "attendees": [ "test1", "test2" ], "id": "851133039" }, { "name": "Super Mario Kart Party 6", "location": "Marioland", "society": "testsociety", "start": "14605026110490", "end": "14605026110500", "details": "Play some Mario Kart with us", "organiser": "test1", "attendees": [ "test1", "test2" ], "id": "838450388" }, { ... } ], "error": 0 } ``` The error codes are as follows, `1` indicates an invalid auth code and `2` indicates a malformed request. ### /events/accept/:eventid To accept an event, a `POST` request should be sent with the following data: ```javascript { "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "success": 1, "error": 0 } ``` The error codes are as follows, `1` indicates an invalid auth code, `2` indicates the event could not be found and `3` indicates a malformed request. ### /events/decline/:eventid To decline an event, a `POST` request should be sent with the following data: ```javascript { "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "success": 1, "error": 0 } ``` The error codes are as follows, `1` indicates an invalid auth code, `2` indicates the event could not be found and `3` indicates a malformed request. ### /events/cancel/:eventid To cancel an event, a `POST` request should be sent with the following data: ```javascript { "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "success": 1, "error": 0 } ``` The error codes are as follows, `1` indicates an invalid auth code, `2` indicates the event could not be found and `3` indicates a malformed request. ### /friends/add/ To add a new friend, a `POST` request should be sent with the following data: ```javascript { "friend": "MyFriend", "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "success": 1, "error": 0 } ``` The error codes are as follows, `1` indicates an invalid auth code, `2` indicates that the user is already a friend, `3` indicates that the user you are trying to add does not exist and `4` indicates a malformed request. ### /friends/remove/ To remove a friend from the friends list, a `POST` request should be sent with the following data: ```javascript { "friend": "MyFriend", "auth": "$2a$10$qjkvbcPZ4YC7/a/I0ZpTaeJp6auXjGrG9pgAdI3PP61u4CftQPSL2" } ``` The response will then look like this: ```javascript { "success": 1, "error": 0 } ``` The error codes are as follows, `1` indicates an invalid auth code, `2` indicates that the user you are trying to remove is not an existing friend and `3` indicates a malformed request.