feat: implement identity and security features

- Added account types and privileged account types constants.
- Created admin user controller for updating user security fields.
- Developed role assignment controller for managing user roles.
- Implemented validation middleware for request schemas.
- Defined user role and auth session models for database interactions.
- Created services for authentication, email notifications, and OTP handling.
- Developed OAuth service for Google and Apple authentication.
- Added JWT utility functions for token generation and verification.
- Implemented comprehensive tests for authentication, session management, and password policies.
- Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
Sathira Sri Sathara
2026-09-03 13:56:18 +05:30
parent 267e80e2ec
commit 9d3d431416
54 changed files with 1389 additions and 1076 deletions
+22
View File
@@ -0,0 +1,22 @@
module.exports = (sequelize, DataTypes) => {
const AuthSession = sequelize.define("AuthSession", {
id: { type: DataTypes.UUID, primaryKey: true },
user_id: { type: DataTypes.STRING, allowNull: false },
token_family_id: { type: DataTypes.UUID, allowNull: false },
refresh_token_hash: { type: DataTypes.STRING(64), allowNull: false },
device_name: DataTypes.STRING,
user_agent: DataTypes.STRING(500),
ip_address: DataTypes.STRING(64),
remember_me: { type: DataTypes.BOOLEAN, allowNull: false, defaultValue: false },
token_version: { type: DataTypes.INTEGER, allowNull: false },
last_used_at: DataTypes.DATE,
expires_at: { type: DataTypes.DATE, allowNull: false },
revoked_at: DataTypes.DATE,
revoked_reason: DataTypes.STRING,
replaced_by_session_id: DataTypes.UUID,
}, { tableName: "auth_sessions", timestamps: true, indexes: [
{ fields: ["user_id"] }, { fields: ["token_family_id"] }, { fields: ["expires_at"] },
] });
AuthSession.associate = (db) => AuthSession.belongsTo(db.User, { foreignKey: "user_id", as: "user" });
return AuthSession;
};
+7 -2
View File
@@ -33,10 +33,10 @@ module.exports = (sequelize, DataTypes) => {
},
password: {
type: DataTypes.STRING,
allowNull: false,
allowNull: true,
},
accountType: {
type: DataTypes.ENUM("business_customer", "customer"),
type: DataTypes.ENUM("superadmin", "admin", "manager", "business_customer", "rider", "customer", "support_agent"),
defaultValue: "customer",
},
accountStatus: {
@@ -59,6 +59,8 @@ module.exports = (sequelize, DataTypes) => {
allowNull: true,
defaultValue: null,
},
tokenVersion: { type: DataTypes.INTEGER, allowNull: false, defaultValue: 0 },
lastLoginAt: { type: DataTypes.DATE, allowNull: true },
},
{
tableName: "users",
@@ -83,6 +85,9 @@ module.exports = (sequelize, DataTypes) => {
foreignKey: "user_id",
as: "businessCustomer",
});
User.hasMany(db.AuthSession, { foreignKey: "user_id", as: "authSessions" });
User.hasMany(db.UserIdentity, { foreignKey: "user_id", as: "identities" });
User.hasMany(db.UserRole, { foreignKey: "user_id", as: "userRoles" });
};
return User;
+13
View File
@@ -0,0 +1,13 @@
module.exports = (sequelize, DataTypes) => {
const UserIdentity = sequelize.define("UserIdentity", {
id: { type: DataTypes.UUID, primaryKey: true },
user_id: { type: DataTypes.STRING, allowNull: false },
provider: { type: DataTypes.ENUM("google", "apple"), allowNull: false },
provider_subject: { type: DataTypes.STRING, allowNull: false },
provider_email: DataTypes.STRING,
}, { tableName: "user_identities", timestamps: true, indexes: [
{ unique: true, fields: ["provider", "provider_subject"] }, { fields: ["user_id"] },
] });
UserIdentity.associate = (db) => UserIdentity.belongsTo(db.User, { foreignKey: "user_id", as: "user" });
return UserIdentity;
};