feat: implement identity and security features
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
@@ -44,7 +44,6 @@ exports.createNewUser = async (req, res) => {
|
||||
lastName,
|
||||
email,
|
||||
password,
|
||||
accountType,
|
||||
address,
|
||||
phoneNumber,
|
||||
businessName,
|
||||
@@ -56,23 +55,23 @@ exports.createNewUser = async (req, res) => {
|
||||
note,
|
||||
} = req.body;
|
||||
|
||||
if (!firstName || !lastName || !email || !password || !accountType) {
|
||||
if (!firstName || !lastName || !email || !password) {
|
||||
await transaction.rollback();
|
||||
|
||||
return res.status(400).send({
|
||||
success: false,
|
||||
message:
|
||||
"First name, last name, email, password and account type are required",
|
||||
"First name, last name, email and password are required",
|
||||
});
|
||||
}
|
||||
|
||||
if (accountType !== "customer" && accountType !== "business_customer") {
|
||||
if (req.body.accountType && req.body.accountType !== "customer") {
|
||||
await transaction.rollback();
|
||||
|
||||
return res.status(400).send({
|
||||
success: false,
|
||||
message:
|
||||
"Invalid account type. Must be either 'customer' or 'business_customer'",
|
||||
"Public registration creates customer accounts only",
|
||||
});
|
||||
}
|
||||
|
||||
@@ -118,7 +117,7 @@ exports.createNewUser = async (req, res) => {
|
||||
lastName,
|
||||
email,
|
||||
password: hashedPassword,
|
||||
accountType,
|
||||
accountType: "customer",
|
||||
accountStatus: "PENDING_VERIFICATION",
|
||||
emailVerifiedAt: null,
|
||||
},
|
||||
@@ -139,8 +138,8 @@ exports.createNewUser = async (req, res) => {
|
||||
{ transaction },
|
||||
);
|
||||
|
||||
//create customer and business customer
|
||||
if (accountType === "customer") {
|
||||
// Create the customer identity extension for public registration.
|
||||
{
|
||||
const customerData = {
|
||||
address,phoneNumber,
|
||||
};
|
||||
@@ -150,23 +149,6 @@ exports.createNewUser = async (req, res) => {
|
||||
customerData,
|
||||
transaction,
|
||||
);
|
||||
} else if (accountType === "business_customer") {
|
||||
const businessData = {
|
||||
businessName,
|
||||
businessRegistrationNumber,
|
||||
businessType,
|
||||
contactName,
|
||||
phoneNumber,
|
||||
businessEmail,
|
||||
expectedMonthlyVolume,
|
||||
note,
|
||||
};
|
||||
|
||||
await createBusinessCustomerDetails(
|
||||
newUser.id,
|
||||
businessData,
|
||||
transaction,
|
||||
);
|
||||
}
|
||||
|
||||
await transaction.commit();
|
||||
@@ -449,6 +431,7 @@ exports.updateUser = async (req, res) => {
|
||||
});
|
||||
|
||||
if (!user) {
|
||||
await transaction.rollback();
|
||||
return res.status(404).send({
|
||||
success: false,
|
||||
message: "User not found",
|
||||
@@ -456,6 +439,7 @@ exports.updateUser = async (req, res) => {
|
||||
}
|
||||
|
||||
if (!UserProfile) {
|
||||
await transaction.rollback();
|
||||
return res.status(404).send({
|
||||
success: false,
|
||||
message: "User profile not found",
|
||||
@@ -533,6 +517,7 @@ exports.deleteUser = async (req, res) => {
|
||||
where: { id },
|
||||
});
|
||||
if (!user) {
|
||||
await transaction.rollback();
|
||||
return res.status(404).send({
|
||||
success: false,
|
||||
message: "User not found",
|
||||
@@ -560,3 +545,22 @@ exports.deleteUser = async (req, res) => {
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
exports.getCurrentUser = async (req, res, next) => {
|
||||
try {
|
||||
const user = await User.findByPk(req.user.id, { attributes: { exclude: ["password", "tokenVersion", "passwordChangedAt"] }, include: [{ model: Profile, as: "profile" }] });
|
||||
res.json({ success: true, data: user });
|
||||
} catch (error) { next(error); }
|
||||
};
|
||||
|
||||
exports.updateCurrentUser = async (req, res, next) => {
|
||||
try {
|
||||
const allowed = ["firstName", "lastName"];
|
||||
const supplied = Object.keys(req.body);
|
||||
if (supplied.some((key) => !allowed.includes(key))) return res.status(400).json({ success: false, error: { code: "UNSAFE_FIELD", message: "Only firstName and lastName may be updated" } });
|
||||
const updates = Object.fromEntries(supplied.map((key) => [key, req.body[key]]).filter(([, value]) => typeof value === "string" && value.trim()));
|
||||
await User.update(updates, { where: { id: req.user.id } });
|
||||
const user = await User.findByPk(req.user.id, { attributes: ["id", "firstName", "lastName", "email", "accountType", "accountStatus"] });
|
||||
res.json({ success: true, data: user });
|
||||
} catch (error) { next(error); }
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user