How refactor this code?

I'm little frustrated because I dont know how will I can refactor this script. I write the authenticate function but it's too complicated, maybe too large in one function, and seems a little spagetti :(, how I will be make this a little better? Some clues? Thanks.

"use strict";
var errorResponse = require('../errorResponse'),
    paynopain = require('../../core/paynopain'),
    User = require('../../core/User'),
    cache = require('../../core/cache/cache'),
    validateValues = require('../validateValues'),
    API_PATH = 'v1/';


function authenticate(req, res, next) {

    if (req.url.indexOf(API_PATH) !== -1){

        var pnpUserId;
        var validated = validateValues(req, ['pnp_access_token']);
        if(validated.error){
            return next(validated.error);
        }
        var pnpAccessToken = req.params.pnp_access_token;

        cache.read('pnpToken:' + pnpAccessToken)
            .then(function(userId){
                if(userId){
                    storeUserIdInRequest(req, next, userId);
                }else{
                    var user = new User(req.logger);
                    return paynopain.getIdFromAccessToken(pnpAccessToken)
                        .then(function(pnpUserIdResult){
                            pnpUserId = pnpUserIdResult;
                            return user.findByPnpID(pnpUserIdResult);
                        })
                        .then(function(userData){

                            if(userData._id){
                                return storeUserIdInRequest(req, next, userData._id.toString());
                            }else{
                                var newUser = {
                                    pnpId: pnpUserId,
                                    radius: 1000
                                };
                                return user.create(newUser)
                                    .then(function(userData){
                                        return storeUserIdInRequest(req, next, userData._id);
                                    });
                            }

                        });
                }
            })
            .fail(function(e){

                if(e.message === 'invalid_grant'){
                    next(errorResponse.unauthorized());
                }else{
                    req.logger.log('error', 'Error authenticating', {
                        error: {
                            message: e.message,
                            stack: e.stack
                        }
                    });
                    next(errorResponse.internalError());
                }

            });

    }else{
        next();
    }

}

function storeUserIdInRequest(req, next, userId){

    var oneHour = 1000 * 60 * 60;
    cache.write('pnpToken:' + req.params.pnp_access_token, userId, {
        expire: oneHour
    })
        .then(function(){
            req.userId = userId;
            req.logger.setExtra({
                userId: userId
            });
            next();
        });

}

function init(server){
    server.use(authenticate);
    require('./configuration/routes')(API_PATH, server);
    require('./products/routes')(API_PATH, server);
    require('./tracking/routes')(API_PATH, server);
    require('./lists/routes')(API_PATH, server);
}
module.exports = init;

It not much better, because i cant see and change behavior of User, cache and other objects methods, but I hope you can use some ideas from that:

"use strict";
var errorResponse = require('../errorResponse'),
    paynopain = require('../../core/paynopain'),
    User = require('../../core/User'),
    cache = require('../../core/cache/cache'),
    validateValues = require('../validateValues'),
    API_PATH = 'v1/';


function authenticate(req, res, next) {
    if (req.url.indexOf(API_PATH) == -1) {
        return next();
    }

    var validated = validateValues(req, ['pnp_access_token']);

    if (validated.error){
        return next(validated.error);
    }

    var pnpAccessToken = req.params.pnp_access_token;

    cache.read('pnpToken:' + pnpAccessToken)
        .then(function(userId){
            if (userId) return userId;

            var user = new User(req.logger);
            return paynopain.getIdFromAccessToken(pnpAccessToken)
                .then(function(pnpUserIdResult){
                    return [ user.findByPnpID(pnpUserIdResult), pnpUserIdResult ];
                })
                .spread(function(userData, pnpUserId){
                    if (userData._id){
                        return userData;
                    }

                    return user.create({
                        pnpId: pnpUserId,
                        radius: 1000
                    });
                }).then(function(user) {
                    return user._id.toString();
                });
        })
        .then(function(userID) {
            return storeUserIdInRequest(req, userId);
        })
        .then(next)
        .fail(function(e){

            if(e.message === 'invalid_grant'){
                next(errorResponse.unauthorized());
            }else{
                req.logger.log('error', 'Error authenticating', {
                    error: {
                        message: e.message,
                        stack: e.stack
                    }
                });
                next(errorResponse.internalError());
            }

        });

}

function storeUserIdInRequest(req, userId){

    var oneHour = 1000 * 60 * 60;
    return cache.write('pnpToken:' + req.params.pnp_access_token, userId, {
        expire: oneHour
    })
    .then(function(){
        req.userId = userId;
        req.logger.setExtra({
            userId: userId
        });
    });

}

function init(server){
    server.use(authenticate);
    require('./configuration/routes')(API_PATH, server);
    require('./products/routes')(API_PATH, server);
    require('./tracking/routes')(API_PATH, server);
    require('./lists/routes')(API_PATH, server);
}
module.exports = init;

Note: I cant test it, so I dont know if it realy works fine!

Tips:

  • use Q.reject for pass and process errors (especialy in your User, and other 'core' object methods)
  • not use else when in don't realy need
  • See ODM\ORM apis (Mongoose \ Mongoose-q is a good sample) to understand how to design clean programming interface