feat: implement identity and security features
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
@@ -19,6 +19,9 @@ const {
|
||||
const { authorizedAccountType, checkPermission } = require("../middleware/permission.middleware");
|
||||
const PERMISSIONS = require("../constants/permissions");
|
||||
|
||||
router.get("/me", authenticate, userController.getCurrentUser);
|
||||
router.patch("/me", authenticate, userController.updateCurrentUser);
|
||||
|
||||
|
||||
router.post(
|
||||
"/",
|
||||
@@ -41,7 +44,7 @@ router.get(
|
||||
router.get(
|
||||
"/",
|
||||
authenticate,
|
||||
authorizedAccountType(["admin"]),
|
||||
authorizedAccountType(["admin", "superadmin"]),
|
||||
userController.getAllUsers
|
||||
);
|
||||
|
||||
@@ -55,14 +58,14 @@ router.get(
|
||||
router.patch(
|
||||
"/:id",
|
||||
authenticate,
|
||||
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
||||
authorizedAccountType(["superadmin"]),
|
||||
userController.updateUser
|
||||
);
|
||||
|
||||
router.delete(
|
||||
"/:id",
|
||||
authenticate,
|
||||
authorizedAccountType(["admin"]),
|
||||
authorizedAccountType(["superadmin"]),
|
||||
userController.deleteUser
|
||||
);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user