feat: implement identity and security features
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
@@ -12,6 +12,7 @@
|
||||
const express = require("express");
|
||||
const router = express.Router();
|
||||
const profileController = require("../controllers/profile.controller.js");
|
||||
const authController = require("../controllers/auth.controller.js");
|
||||
const { authenticate } = require("../middleware/auth.middleware");
|
||||
|
||||
const {
|
||||
@@ -20,29 +21,32 @@ const {
|
||||
} = require("../middleware/permission.middleware");
|
||||
const PERMISSIONS = require("../constants/permissions");
|
||||
const { sensitiveLimiter } = require("../middleware/rateLimit.middleware");
|
||||
const validate = require("../middleware/validate.middleware");
|
||||
const schemas = require("../validation/auth.schemas");
|
||||
const { requireOwnership } = require("../middleware/permission.middleware");
|
||||
|
||||
router.post("/req-reset-password", sensitiveLimiter, profileController.requestPasswordReset);
|
||||
router.post("/req-reset-password", sensitiveLimiter, validate(schemas.forgot), authController.forgotPassword);
|
||||
|
||||
router.post("/reset-password", sensitiveLimiter, profileController.resetPassword);
|
||||
router.post("/reset-password", sensitiveLimiter, validate(schemas.reset), authController.resetPassword);
|
||||
|
||||
router.post(
|
||||
"/change-password",
|
||||
authenticate,
|
||||
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
||||
profileController.changePassword,
|
||||
validate(schemas.change),
|
||||
authController.changePassword,
|
||||
);
|
||||
|
||||
router.get(
|
||||
"/avatar/:userId",
|
||||
authenticate,
|
||||
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
||||
requireOwnership("userId"),
|
||||
profileController.getProfileAvatar,
|
||||
);
|
||||
|
||||
router.get(
|
||||
"/background/:userId",
|
||||
authenticate,
|
||||
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
||||
requireOwnership("userId"),
|
||||
profileController.getProfileBackgroundImage,
|
||||
);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user