diff --git a/lib/cartodb/api/auth_api.js b/lib/cartodb/api/auth_api.js index e4525929..0f31e721 100644 --- a/lib/cartodb/api/auth_api.js +++ b/lib/cartodb/api/auth_api.js @@ -1,6 +1,3 @@ -var assert = require('assert'); -var step = require('step'); - /** * * @param {PgConnection} pgConnection @@ -91,53 +88,52 @@ AuthApi.prototype.authorizedByAPIKey = function(user, req, callback) { * @param callback function(err, allowed) is access allowed not? */ AuthApi.prototype.authorize = function(req, res, callback) { - var self = this; var user = res.locals.user; - step( - function () { - self.authorizedByAPIKey(user, req, this); - }, - function checkApiKey(err, authorized){ - req.profiler.done('authorizedByAPIKey'); - assert.ifError(err); - - // if not authorized by api_key, continue - if (!authorized) { - // not authorized by api_key, check if authorized by signer - return self.authorizedBySigner(res, this); - } + this.authorizedByAPIKey(user, req, (err, isAuthorizedByApikey) => { + if (err) { + return callback(err); + } + if (isAuthorizedByApikey) { const asMaster = false; - // authorized by api key, login as the given username and stop - self.pgConnection.setDBAuth(user, res.locals, asMaster, function(err) { - callback(err, true); // authorized (or error) + return this.pgConnection.setDBAuth(user, res.locals, asMaster, function (err) { + req.profiler.done('setDBAuth'); + + if (err) { + return callback(err); + } + + callback(null, true); }); - }, - function checkSignAuthorized(err, authorized) { + } + + this.authorizedBySigner(res, (err, isAuthorizedBySigner) => { if (err) { return callback(err); } + + if (isAuthorizedBySigner) { + const asMaster = true; + return this.pgConnection.setDBAuth(user, res.locals, asMaster, function (err) { + req.profiler.done('setDBAuth'); + + if (err) { + return callback(err); + } - if ( ! authorized ) { - // request not authorized by signer. - - // if no signer name was given, let dbparams and - // PostgreSQL do the rest. - // - if ( ! res.locals.signer ) { - return callback(null, true); // authorized so far - } - - // if signer name was given, return no authorization - return callback(null, false); + callback(null, true); + }); } - const asMaster = true; - self.pgConnection.setDBAuth(user, res.locals, asMaster, function(err) { - req.profiler.done('setDBAuth'); - callback(err, true); // authorized (or error) - }); - } - ); + // if no signer name was given, let dbparams and + // PostgreSQL do the rest. + if (!res.locals.signer) { + return callback(null, true); // authorized so far + } + + // if signer name was given, return no authorization + return callback(null, false); + }); + }); };