server.ts 3.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112
  1. import 'reflect-metadata'
  2. import 'newrelic'
  3. import * as Sentry from '@sentry/node'
  4. import * as busboy from 'connect-busboy'
  5. import '../src/Controller/HealthCheckController'
  6. import '../src/Controller/FilesController'
  7. import helmet from 'helmet'
  8. import * as cors from 'cors'
  9. import { urlencoded, json, raw, Request, Response, NextFunction, RequestHandler, ErrorRequestHandler } from 'express'
  10. import * as winston from 'winston'
  11. // eslint-disable-next-line @typescript-eslint/no-var-requires
  12. const robots = require('express-robots-txt')
  13. import { InversifyExpressServer } from 'inversify-express-utils'
  14. import { ContainerConfigLoader } from '../src/Bootstrap/Container'
  15. import TYPES from '../src/Bootstrap/Types'
  16. import { Env } from '../src/Bootstrap/Env'
  17. const container = new ContainerConfigLoader()
  18. void container.load().then((container) => {
  19. const env: Env = new Env()
  20. env.load()
  21. const server = new InversifyExpressServer(container)
  22. server.setConfig((app) => {
  23. app.use((_request: Request, response: Response, next: NextFunction) => {
  24. response.setHeader('X-Files-Version', container.get(TYPES.VERSION))
  25. next()
  26. })
  27. app.use(
  28. busboy({
  29. highWaterMark: 2 * 1024 * 1024,
  30. }),
  31. )
  32. /* eslint-disable */
  33. app.use(helmet({
  34. contentSecurityPolicy: {
  35. directives: {
  36. defaultSrc: ["https: 'self'"],
  37. baseUri: ["'self'"],
  38. childSrc: ["*", "blob:"],
  39. connectSrc: ["*"],
  40. fontSrc: ["*", "'self'"],
  41. formAction: ["'self'"],
  42. frameAncestors: ["*", "*.standardnotes.org", "*.standardnotes.com"],
  43. frameSrc: ["*", "blob:"],
  44. imgSrc: ["'self'", "*", "data:"],
  45. manifestSrc: ["'self'"],
  46. mediaSrc: ["'self'"],
  47. objectSrc: ["'self'"],
  48. scriptSrc: ["'self'"],
  49. styleSrc: ["'self'"]
  50. }
  51. }
  52. }))
  53. /* eslint-enable */
  54. app.use(json({ limit: '50mb' }))
  55. app.use(raw({ limit: '50mb', type: 'application/octet-stream' }))
  56. app.use(urlencoded({ extended: true, limit: '50mb' }))
  57. app.use(
  58. cors({
  59. exposedHeaders: ['Content-Range', 'Accept-Ranges'],
  60. }),
  61. )
  62. app.use(
  63. robots({
  64. UserAgent: '*',
  65. Disallow: '/',
  66. }),
  67. )
  68. if (env.get('SENTRY_DSN', true)) {
  69. Sentry.init({
  70. dsn: env.get('SENTRY_DSN'),
  71. integrations: [new Sentry.Integrations.Http({ tracing: false, breadcrumbs: true })],
  72. tracesSampleRate: 0,
  73. })
  74. app.use(Sentry.Handlers.requestHandler() as RequestHandler)
  75. }
  76. })
  77. const logger: winston.Logger = container.get(TYPES.Logger)
  78. server.setErrorConfig((app) => {
  79. if (env.get('SENTRY_DSN', true)) {
  80. app.use(Sentry.Handlers.errorHandler() as ErrorRequestHandler)
  81. }
  82. app.use((error: Record<string, unknown>, _request: Request, response: Response, _next: NextFunction) => {
  83. logger.error(error.stack)
  84. response.status(500).send({
  85. error: {
  86. message:
  87. "Unfortunately, we couldn't handle your request. Please try again or contact our support if the error persists.",
  88. },
  89. })
  90. })
  91. })
  92. const serverInstance = server.build()
  93. serverInstance.listen(env.get('PORT'))
  94. logger.info(`Server started on port ${process.env.PORT}`)
  95. })