feat: implement identity and security features

- Added account types and privileged account types constants.
- Created admin user controller for updating user security fields.
- Developed role assignment controller for managing user roles.
- Implemented validation middleware for request schemas.
- Defined user role and auth session models for database interactions.
- Created services for authentication, email notifications, and OTP handling.
- Developed OAuth service for Google and Apple authentication.
- Added JWT utility functions for token generation and verification.
- Implemented comprehensive tests for authentication, session management, and password policies.
- Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
Sathira Sri Sathara
2026-09-03 13:56:18 +05:30
parent 267e80e2ec
commit 9d3d431416
54 changed files with 1389 additions and 1076 deletions
+22 -31
View File
@@ -1,36 +1,27 @@
/**
* Copyright (c) 2026 Niolla
* All rights reserved.
*
* This source code is proprietary and confidential.
* Unauthorized copying, modification, distribution, or use
* of this file, via any medium, is strictly prohibited.
*/
const express = require("express");
const auth = require("../controllers/auth.controller");
const user = require("../controllers/user.controller");
const { authenticate } = require("../middleware/auth.middleware");
const validate = require("../middleware/validate.middleware");
const schemas = require("../validation/auth.schemas");
const { sensitiveLimiter } = require("../middleware/rateLimit.middleware");
// app/routes/auth.routes.js
const express = require('express');
const router = express.Router();
const authController = require('../controllers/auth.controller');
const {authenticate} = require('../middleware/auth.middleware');
const { sensitiveLimiter } = require('../middleware/rateLimit.middleware');
router.use(sensitiveLimiter);
// GET /api/auth/me
router.get("/me", authenticate, (req, res) => {
res.json({
authenticated: true,
user: req.user
});
});
router.post('/req-otp', authController.loginReq);
router.post('/login', authController.login);
router.post('/refresh', authController.refreshToken);
router.post('/forgot-password', authController.forgotPassword);
router.post('/reset-password', authController.resetPassword);
router.post('/change-password', authenticate, authController.changePassword);
router.post('/logout', authController.logout);
router.post("/register", validate(schemas.register), user.createNewUser);
router.post("/login", validate(schemas.login), auth.login);
router.post("/req-otp", validate(schemas.login), auth.loginReq);
router.post("/verify-otp", validate(schemas.verifyOtp), auth.verifyOtp);
router.post("/refresh", validate(schemas.refresh), auth.refreshToken);
router.post("/logout", auth.logout);
router.post("/logout-all", authenticate, auth.logoutAll);
router.post("/forgot-password", validate(schemas.forgot), auth.forgotPassword);
router.post("/reset-password", validate(schemas.reset), auth.resetPassword);
router.post("/change-password", authenticate, validate(schemas.change), auth.changePassword);
router.post("/verify-email", validate(schemas.verifyEmail), auth.verifyEmail);
router.post("/resend-verification", validate(schemas.resend), auth.resendVerification);
router.post("/google", validate(schemas.oauth), auth.oauth("google"));
router.post("/apple", validate(schemas.oauth), auth.oauth("apple"));
router.get("/me", authenticate, auth.me);
module.exports = router;