+/* LMNO middleware to lookup the game. */
+app.use('/empires/:game_id([a-zA-Z0-9]{4})', (request, response, next) => {
+ const game_id = request.params.game_id;
+ const canon_id = lmno_canonize(game_id);
+
+ /* Redirect user to page with the canonical ID in it. */
+ if (game_id !== canon_id) {
+ const new_url = request.originalUrl.replace("/empires/" + game_id,
+ "/empires/" + canon_id);
+ response.redirect(301, new_url);
+ return;
+ }
+
+ /* See if there is any game with this ID. */
+ const game = lmno.ids[game_id];
+ if (game === undefined) {
+ response.sendStatus(404);
+ return;
+ }
+
+ /* Stash the game onto the request to be used by the game-specific code. */
+ request.game = game.game;
+ next();
+});
+
+function auth_admin(request, response, next) {
+ /* If there is no user associated with this session, redirect to the login
+ * page (and set a "next" query parameter so we can come back here).
+ */
+ if (! request.session.user) {
+ response.redirect(302, "/login?next=" + request.path);
+ return;
+ }
+
+ /* If the user is logged in but not authorized to view the page then
+ * we return that error. */
+ if (request.session.user.role !== "admin") {
+ response.status(401).send("Unauthorized");
+ return;
+ }
+ next();
+}
+
+app.get('/logout', (request, response) => {
+ request.session.user = undefined;
+
+ response.send("You are now logged out.");
+});
+
+app.get('/login', (request, response) => {
+ if (request.session.user) {
+ response.send("Welcome, " + request.session.user + ".");
+ return;
+ }
+
+ response.sendFile(path.join(__dirname, './login.html'));
+});
+
+app.post('/login', async (request, response) => {
+ const username = request.body.username;
+ const password = request.body.password;
+ const user = lmno_config.users[username];
+ if (! user) {
+ response.sendStatus(404);
+ return;
+ }
+ const match = await bcrypt.compare(password, user.password_hash_bcrypt);
+ if (! match) {
+ response.sendStatus(404);
+ return;
+ }
+ request.session.user = { username: user.username, role: user.role };
+ response.sendStatus(200);
+ return;
+});
+
+/* A stats page (only available to admin users) */
+app.get('/stats/', auth_admin, (request, response) => {
+ let active = 0;
+ let idle = 0;
+
+ for (let id in lmno.ids) {
+ if (lmno.ids[id].game.clients.length)
+ active++;
+ else
+ idle++;
+ }
+ response.send(`<html><body>Active games: ${active}.<br>
+Idle games: ${idle}</body></html>`);
+});
+
+
+/* Mount sub apps. only _after_ we have done all the middleware we need. */
+app.use('/empires/[a-zA-Z0-9]{4}/', empires.app);
+