-
Notifications
You must be signed in to change notification settings - Fork 16
/
index.js
41 lines (35 loc) · 1.17 KB
/
index.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
// index.js
const express = require('express');
const bodyParser = require('body-parser');
const User = require('./models/User');
const app = express();
const PORT = process.env.PORT || 3000;
app.use(bodyParser.json());
// Endpoint de login (vulnerável a SQL Injection)
app.post('/login', async (req, res) => {
const { username, password } = req.body;
const user = await User.findOne({ where: { username, password } });
if (user) {
res.json({ message: 'Login successful', user });
} else {
res.status(401).json({ message: 'Invalid credentials' });
}
});
// Endpoint de listagem de usuários (expondo dados sensíveis)
app.get('/users', async (req, res) => {
const users = await User.findAll({ attributes: ['id', 'username', 'password'] });
res.json(users);
});
// Endpoint de detalhe do usuário logado (expondo senha)
app.get('/profile', async (req, res) => {
const { username } = req.query;
const user = await User.findOne({ where: { username: username ?? null } });
if (user) {
res.json(user);
} else {
res.status(404).json({ message: 'User not found' });
}
});
app.listen(PORT, () => {
console.log(`Server is running on port ${PORT}`);
});