feat: implement identity and security features
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
@@ -0,0 +1,22 @@
|
||||
module.exports = (sequelize, DataTypes) => {
|
||||
const AuthSession = sequelize.define("AuthSession", {
|
||||
id: { type: DataTypes.UUID, primaryKey: true },
|
||||
user_id: { type: DataTypes.STRING, allowNull: false },
|
||||
token_family_id: { type: DataTypes.UUID, allowNull: false },
|
||||
refresh_token_hash: { type: DataTypes.STRING(64), allowNull: false },
|
||||
device_name: DataTypes.STRING,
|
||||
user_agent: DataTypes.STRING(500),
|
||||
ip_address: DataTypes.STRING(64),
|
||||
remember_me: { type: DataTypes.BOOLEAN, allowNull: false, defaultValue: false },
|
||||
token_version: { type: DataTypes.INTEGER, allowNull: false },
|
||||
last_used_at: DataTypes.DATE,
|
||||
expires_at: { type: DataTypes.DATE, allowNull: false },
|
||||
revoked_at: DataTypes.DATE,
|
||||
revoked_reason: DataTypes.STRING,
|
||||
replaced_by_session_id: DataTypes.UUID,
|
||||
}, { tableName: "auth_sessions", timestamps: true, indexes: [
|
||||
{ fields: ["user_id"] }, { fields: ["token_family_id"] }, { fields: ["expires_at"] },
|
||||
] });
|
||||
AuthSession.associate = (db) => AuthSession.belongsTo(db.User, { foreignKey: "user_id", as: "user" });
|
||||
return AuthSession;
|
||||
};
|
||||
Reference in New Issue
Block a user