-
Notifications
You must be signed in to change notification settings - Fork 0
/
server.js
153 lines (127 loc) · 3.69 KB
/
server.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
require('dotenv').config();
const express = require('express');
const path = require('path');
const fetch = require('node-fetch');
const bodyParser = require('body-parser');
const app = express();
// Serve static files from the React app
app.use(express.static(path.join(__dirname, 'client/build')));
app.use(bodyParser.json());
//Connect to postgres
//use connection pooling so that can run multiple times
const { Pool, Client } = require('pg');
const pool = new Pool({
connectionString: process.env.DATABASE_URL,
ssl: true,
})
// Put all API endpoints under here
///// GET ALL NOTES
// callback - checkout a client
app.get('/api/all-notes', (req, resp) => {
//use connection pooling so that can run multiple times
pool.connect((err, client, done) => {
if (err) throw err
client.query('SELECT * FROM notes ORDER BY updated_at DESC;', (err, res) => {
done()
let messages = res.rows;
if (err) {
console.log(err.stack)
} else {
console.log("********************")
resp.json({messages})
}
})
})
})
///// GET A SINGLE NOTE
app.get('/api/notes/:id', (req, resp) => {
var id = req.params.id;
pool.connect((err, client, done) => {
console.log("fix single note for SQL injection protection")
if (err) throw err
client.query(`SELECT * FROM notes WHERE id=${id}`, (err, res) => {
done()
let message = res.rows;
if (err) {
console.log(err.stack)
} else {
console.log("Single Row ********************")
resp.json(message)
}
})
})
})
///// POST A SINGLE NOTE
app.post('/api/notes/create', (req, resp) => {
var body = req.body.note;
var title = body.title;
var note = body.note;
pool.connect((err, client, done) => {
if (err) throw err;
console.log(title);
console.log(note);
client.query(`INSERT INTO notes (title, note, created_at, updated_at, user_id)
VALUES ($token$${title}$token$, $token$${note}$token$, current_timestamp, current_timestamp, 1) returning id`, (err, res) => {
if (err) {
console.log(err)
} else {
console.log("Success")
var newlyCreatedNoteId = res.rows[0].id;
resp.json(newlyCreatedNoteId)
}
done()
})
})
})
///// update a Note
app.put('/api/notes/edit/:id', (req, resp) => {
var id = req.params.id;
var body = req.body.note;
var title = body.title;
var note = body.note;
pool.connect((err, client, done) => {
if (err) throw err;
console.log(id);
console.log(title);
console.log(note);
client.query(`UPDATE notes
SET title = $token$${title}$token$,
note = $token$${note}$token$,
updated_at = current_timestamp
WHERE id = ${id};`, (err, res) => {
if (err) {
console.log(err)
} else {
console.log("Success")
resp.json(res);
}
done()
})
})
})
//// Delete a single note
app.delete('/api/notes/:id', (req, resp) => {
var id = req.params.id;
pool.connect((err, client, done) => {
if (err) throw err;
client.query(`DELETE FROM notes
WHERE id=${id}
AND user_id=1`, (err, res) => {
if (err) {
console.log(err)
} else {
console.log("Success")
resp.json(res);
}
done()
})
})
})
// The "catchall" handler: for any request that doesn't
// match one above, send back React's index.html file.
app.get('*', (req, res) => {
res.sendFile(path.join(__dirname+'/client/build/index.html'));
});
const port = process.env.PORT || 5000;
app.listen(port);
console.log(`Server listening on ${port}`);