|
@@ -3,6 +3,7 @@ const path = require('path')
|
|
|
const cookieParser = require('cookie-parser')
|
|
const cookieParser = require('cookie-parser')
|
|
|
const logger = require('morgan')
|
|
const logger = require('morgan')
|
|
|
const cors = require('cors')
|
|
const cors = require('cors')
|
|
|
|
|
+const csrf = require('tiny-csrf')
|
|
|
const response = require('./utils/responseHandler')
|
|
const response = require('./utils/responseHandler')
|
|
|
const dokumenController = require('./controller/dokumen.controller')
|
|
const dokumenController = require('./controller/dokumen.controller')
|
|
|
const app = express()
|
|
const app = express()
|
|
@@ -13,7 +14,8 @@ app.use(logger('dev'))
|
|
|
app.use(express.json())
|
|
app.use(express.json())
|
|
|
app.use(cors({ origin: true, credentials: true }))
|
|
app.use(cors({ origin: true, credentials: true }))
|
|
|
app.use(express.urlencoded({ extended: false }))
|
|
app.use(express.urlencoded({ extended: false }))
|
|
|
-app.use(cookieParser())
|
|
|
|
|
|
|
+app.use(cookieParser(process.env.SRU51))
|
|
|
|
|
+app.use(csrf("XwHsY7X1spE#pdhgdGe9G$Cw&mF7n8=$", ['POST'], ['/v1/auth/login']))
|
|
|
app.use(express.static(path.join(__dirname, 'public')))
|
|
app.use(express.static(path.join(__dirname, 'public')))
|
|
|
|
|
|
|
|
app.get('/', (req, res) => {
|
|
app.get('/', (req, res) => {
|