feat: implement identity and security features
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
+9
-2
@@ -18,9 +18,14 @@ REDIS_PASSWORD=replace_with_local_redis_password
|
||||
|
||||
# Use separate randomly generated values of at least 32 characters.
|
||||
JWT_SECRET=replace_with_a_random_value_at_least_32_chars
|
||||
REFRESH_TOKEN_SECRET=replace_with_a_different_random_32_char_value
|
||||
JWT_EXPIRES_IN=15m
|
||||
REFRESH_TOKEN_DAYS=7d
|
||||
JWT_ISSUER=zumri-api
|
||||
JWT_AUDIENCE=zumri-clients
|
||||
ACCESS_TOKEN_TTL=15m
|
||||
REFRESH_TOKEN_TTL_DAYS=7
|
||||
REMEMBER_ME_REFRESH_TOKEN_TTL_DAYS=30
|
||||
LOGIN_OTP_TTL_SECONDS=900
|
||||
LOGIN_OTP_MAX_ATTEMPTS=5
|
||||
|
||||
# Runtime controls
|
||||
RUN_CRON=false
|
||||
@@ -58,3 +63,5 @@ DEFAULT_PASSWORD=
|
||||
PASSWORD_RESET_TTL_SECONDS=900
|
||||
EMAIL_VERIFICATION_TTL_SECONDS=86400
|
||||
PUPPETEER_EXECUTABLE_PATH=
|
||||
GOOGLE_CLIENT_ID=
|
||||
APPLE_CLIENT_ID=
|
||||
|
||||
Reference in New Issue
Block a user