diff --git a/Documentation/Auth-API.md b/Documentation/Auth-API.md index f07ce72..9537601 100644 --- a/Documentation/Auth-API.md +++ b/Documentation/Auth-API.md @@ -56,8 +56,8 @@ POST: http://localhost:3070/api/auth/login "email": "sathira@niolla.lk", "firstName": "Jhon", "lastName": "Doe", - "role": "System Developer", - "accountType": "admin" + "accountType": "admin", + "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9......" } } ``` @@ -90,7 +90,6 @@ No Body "firstName": "Sathira", "lastName": "Sri Sathsara", "email": "sathira@niolla.lk", - "role": "System Developer", "accountType": "admin", "iat": 1778865265, "exp": 1778868865, diff --git a/Documentation/User-API.md b/Documentation/User-API.md index f57aa43..c18a991 100644 --- a/Documentation/User-API.md +++ b/Documentation/User-API.md @@ -18,7 +18,9 @@ emailVerifiedAt = null POST: http://localhost:3070/api/user ``` -**Request Body** +**Request Body customer** + +accontType = customer and bussiness_customer ```json { @@ -26,6 +28,10 @@ POST: http://localhost:3070/api/user "lastName": "Bimsara", "email": "ibimsara00@gmail.com", "password": "Hello@12346" + "accountType": "customer", + + "address": "Colombo, Sri Lanka", + "phoneNumber": "0771234567" } ``` @@ -45,21 +51,20 @@ POST: http://localhost:3070/api/user } ``` -After registration, the user receives an email containing a verification link. -``` -#### Verify Email +After registration, the user receives an email containing a verification link. + + + +#### Verify Email Verifies the customer's email using the raw verification token received by email. -The backend hashes the received token and compares the resulting hash with the `tokenHash` stored in the `email_verifications` table. The token must: ```text -Exist in the database -Not have been used -Not have expired +store in redis and expire token ``` **Endpoint** @@ -107,7 +112,44 @@ usedAt = This prevents the same verification token from being successfully used again. ---- +#### Get user's details + +**Endpoint** + +``` +GET: http://localhost:3070/api/profile +``` + +**Respond** + +```json +{ + "success": true, + "message": "User profile retrieved successfully", + "data": { + "user": { + "id": "usr_572gtlpi", + "firstName": "Isuru", + "lastName": "Bimsara", + "email": "ibimsara00@gmail.com", + "accountType": "customer", + "accountStatus": "ACTIVE", + "emailVerifiedAt": "2026-08-20T16:26:04.000Z", + "passwordChangedAt": "2026-08-21T05:29:16.000Z", + "createdAt": "2026-08-20T16:25:30.000Z", + "updatedAt": "2026-08-21T05:29:16.000Z" + }, + "accountDetails": { + "customer_id": "cust_c8avqwbc", + "user_id": "usr_572gtlpi", + "address": "Colombo, Sri Lanka", + "phoneNumber": "0771234567", + "createdAt": "2026-08-20T16:25:31.000Z", + "updatedAt": "2026-08-20T16:25:31.000Z" + } + } +} +``` #### Get All Users diff --git a/app/controllers/auth.controller.js b/app/controllers/auth.controller.js index 2c5f27c..dbb480c 100644 --- a/app/controllers/auth.controller.js +++ b/app/controllers/auth.controller.js @@ -377,12 +377,57 @@ exports.resetPassword = async (req, res) => { // Logout: Clear the JWT cookie -exports.logout = (req, res) => { - res.clearCookie("access_token", { - httpOnly: true, - secure: process.env.NODE_ENV === "production", - sameSite: process.env.NODE_ENV === "production" ? "None" : "Lax", - }); +exports.logout = async (req, res) => { + try { + // 1. Get refresh token from cookie + const refreshToken = req.cookies?.refresh_token; - res.json({ success: true, message: "Logged out successfully" }); + // 2. If refresh token exists, find its session + if (refreshToken) { + const session = validateRefreshSession(refreshToken); + + // 3. Delete refresh session from server RAM + if (session) { + deleteRefreshSession(session.sessionId); + + console.log( + `Refresh session deleted: ${session.sessionId}` + ); + } + } + + // 4. Clear access token cookie + res.clearCookie("access_token", { + httpOnly: true, + secure: process.env.NODE_ENV === "production", + sameSite: + process.env.NODE_ENV === "production" + ? "None" + : "Lax", + }); + + // 5. Clear refresh token cookie + res.clearCookie("refresh_token", { + httpOnly: true, + secure: process.env.NODE_ENV === "production", + sameSite: + process.env.NODE_ENV === "production" + ? "None" + : "Lax", + }); + + // 6. Send response + return res.status(200).json({ + success: true, + message: "Logged out successfully", + }); + + } catch (error) { + console.error("LOGOUT ERROR:", error); + + return res.status(500).json({ + success: false, + message: "Failed to logout", + }); + } }; diff --git a/app/utils/jwt.util.js b/app/utils/jwt.util.js index 7d91279..f612f8a 100644 --- a/app/utils/jwt.util.js +++ b/app/utils/jwt.util.js @@ -13,7 +13,7 @@ const jwt = require("jsonwebtoken"); require("dotenv").config(); const JWT_SECRET = process.env.JWT_SECRET || "your_jwt_secret_key"; -const JWT_EXPIRES_IN = process.env.JWT_EXPIRES_IN || "1d"; // token validity +const JWT_EXPIRES_IN = process.env.JWT_EXPIRES_IN || "15m"; // token validity const REFRESH_TOKEN_SECRET = process.env.REFRESH_TOKEN_SECRET || "your_refresh_token_secret_key"; const REFRESH_TOKEN_DAYS = process.env.REFRESH_TOKEN_DAYS || "7d"; // refresh token validity