-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathindex.js
More file actions
129 lines (114 loc) · 3.9 KB
/
Copy pathindex.js
File metadata and controls
129 lines (114 loc) · 3.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
const express = require('express')
const mongoose = require('mongoose')
const cors = require('cors')
const cookieParser = require('cookie-parser')
const dotenv = require('dotenv')
dotenv.config()
const userRoutes = require('./src/routes/user.routes')
const postRoutes = require('./src/routes/post.routes')
const commentRoutes = require('./src/routes/comment.routes')
const app = express()
app.use(cookieParser())
app.use(cors({
origin: process.env.CLIENT_URL,
credentials: true
}))
app.use(express.urlencoded({ extended: false }))
app.use(express.json())
app.use('/uploads', express.static('uploads'))
app.use('/users', userRoutes)
app.use('/posts', postRoutes)
app.use('/comments', commentRoutes)
app.get('/', (req, res) => {
res.json({
message: 'Welcome to Social Media API',
now: new Date()
})
})
mongoose.connect(process.env.MONGODB_URL)
.then(() => {
console.log('MongoDB connected successfully ✅')
app.listen(process.env.PORT, () => {
console.log(`Server is running on ${process.env.PORT} ✅`)
})
})
/*
# Social Media App
- Model
- User
- username (String, unique)
- email (String, unique)
- fullName (String)
- bio (String)
- profilePic (String)
- timestamps (Date)
- Post
- author (ObjectId ref -> User)
- content (String)
- likes (Array[ObjectId ref -> User])
- timestamps (Date)
- Comment
- post (ObjectId ref -> Post)
- author (ObjectId ref -> User)
- content (String)
- timestamps (Date)
- Routes:
- users
- GET /users (READ)
- POST /users (CREATE)
- PATCH /users/:id (UPDATE)
- DELETE /users/:id (DELETE)
- posts
- GET /posts?author= (READ)
- POST /posts (CREATE)
- PATCH /posts/:id (UPDATE)
- DELETE /posts/:id (DELETE)
- POST /posts/:id/like-toggle (CREATE)
- comment
- GET /comments?postId= (GET)
- POST /comments (CREATE)
- PATCH /comments/:id (UPDATE)
- DELETE /comments/:id (DELETE)
------------------------------------------
# Social Media App (w/ Auth)
- Model
- User ✅
- password (String)
- Auth Middlewares
- Authentication ✅
- users
- isProfileOwner ✅
- Routes:
- users (All routes are protected except signup and signin ✅)
- GET /users (READ)
- Response body: Remove sensitive info (email, password) ✅
- POST /users (CREATE)
-> POST /users/signup ✅
- Auth Flow: Register a user + bcrypt
-> POST /users/signin ✅
- Auth Flow: Signing in a user + bcrypt + jwt
- PATCH /users/:id (UPDATE)
- Authorization: A user can update only their profile ✅
- DELETE /users/:id (DELETE)
- Authorization: A user can delete only their profile ✅
- posts (All routes are protected ✅)
- GET /posts?author= (READ)
- POST /posts (CREATE)
- Authorization: A user can create a post only for their account ✅
- PATCH /posts/:id (UPDATE)
- Authorization: A post can only be updated by the author ✅
- DELETE /posts/:id (DELETE)
- Authorization: A post can only be deleted by the author ✅
- POST /posts/:id/like-toggle (CREATE)
- Authorization: A user can like/unlike only for their account ✅
- comment (All routes are protected ✅)
- GET /comments?postId= (GET)
- POST /comments (CREATE)
- Authorization: A user can create a comment only for their account
- PATCH /comments/:id (UPDATE)
- Authorization: A comment can only be updated by the author of the comment ✅
- DELETE /comments/:id (DELETE)
- Authorization: A comment can be deleted by
- the author of the comment ✅
- the author of the post ✅
*/