feat: implement identity and security features

- Added account types and privileged account types constants.
- Created admin user controller for updating user security fields.
- Developed role assignment controller for managing user roles.
- Implemented validation middleware for request schemas.
- Defined user role and auth session models for database interactions.
- Created services for authentication, email notifications, and OTP handling.
- Developed OAuth service for Google and Apple authentication.
- Added JWT utility functions for token generation and verification.
- Implemented comprehensive tests for authentication, session management, and password policies.
- Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
Sathira Sri Sathara
2026-09-03 13:56:18 +05:30
parent 267e80e2ec
commit 9d3d431416
54 changed files with 1389 additions and 1076 deletions
+10 -6
View File
@@ -12,6 +12,7 @@
const express = require("express");
const router = express.Router();
const profileController = require("../controllers/profile.controller.js");
const authController = require("../controllers/auth.controller.js");
const { authenticate } = require("../middleware/auth.middleware");
const {
@@ -20,29 +21,32 @@ const {
} = require("../middleware/permission.middleware");
const PERMISSIONS = require("../constants/permissions");
const { sensitiveLimiter } = require("../middleware/rateLimit.middleware");
const validate = require("../middleware/validate.middleware");
const schemas = require("../validation/auth.schemas");
const { requireOwnership } = require("../middleware/permission.middleware");
router.post("/req-reset-password", sensitiveLimiter, profileController.requestPasswordReset);
router.post("/req-reset-password", sensitiveLimiter, validate(schemas.forgot), authController.forgotPassword);
router.post("/reset-password", sensitiveLimiter, profileController.resetPassword);
router.post("/reset-password", sensitiveLimiter, validate(schemas.reset), authController.resetPassword);
router.post(
"/change-password",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
profileController.changePassword,
validate(schemas.change),
authController.changePassword,
);
router.get(
"/avatar/:userId",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
requireOwnership("userId"),
profileController.getProfileAvatar,
);
router.get(
"/background/:userId",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
requireOwnership("userId"),
profileController.getProfileBackgroundImage,
);