feat: implement identity and security features
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
+20
-45
@@ -1,51 +1,26 @@
|
||||
/**
|
||||
* Copyright (c) 2026 Niolla
|
||||
* All rights reserved.
|
||||
*
|
||||
* This source code is proprietary and confidential.
|
||||
* Unauthorized copying, modification, distribution, or use
|
||||
* of this file, via any medium, is strictly prohibited.
|
||||
*/
|
||||
|
||||
// app/utils/jwt.util.js
|
||||
|
||||
const jwt = require("jsonwebtoken");
|
||||
require("dotenv").config();
|
||||
|
||||
const JWT_EXPIRES_IN = process.env.JWT_EXPIRES_IN || "15m"; // token validity
|
||||
|
||||
const REFRESH_TOKEN_DAYS = process.env.REFRESH_TOKEN_DAYS || "7d"; // refresh token validity
|
||||
|
||||
const getSecret = (name) => {
|
||||
const value = process.env[name];
|
||||
if (!value || value.length < 32) throw new Error(`${name} is not configured securely`);
|
||||
return value;
|
||||
const secret = () => {
|
||||
if (!process.env.JWT_SECRET || process.env.JWT_SECRET.length < 32) throw new Error("JWT_SECRET is not configured securely");
|
||||
return process.env.JWT_SECRET;
|
||||
};
|
||||
|
||||
/**
|
||||
* Generate JWT token
|
||||
* @param {Object} payload - usually { id, email, role }
|
||||
* @returns string
|
||||
*/
|
||||
const generateToken = (payload) => {
|
||||
return jwt.sign(payload, getSecret("JWT_SECRET"), { expiresIn: JWT_EXPIRES_IN });
|
||||
};
|
||||
const generateToken = ({ userId, sessionId, tokenVersion }) => jwt.sign(
|
||||
{ sid: sessionId, tokenVersion },
|
||||
secret(),
|
||||
{
|
||||
algorithm: "HS256",
|
||||
subject: userId,
|
||||
issuer: process.env.JWT_ISSUER || "zumri-api",
|
||||
audience: process.env.JWT_AUDIENCE || "zumri-clients",
|
||||
expiresIn: process.env.ACCESS_TOKEN_TTL || "15m",
|
||||
},
|
||||
);
|
||||
|
||||
/**
|
||||
* Verify JWT token
|
||||
* @param {string} token
|
||||
* @returns payload or throws error
|
||||
*/
|
||||
const verifyToken = (token) => {
|
||||
return jwt.verify(token, getSecret("JWT_SECRET"));
|
||||
};
|
||||
const verifyToken = (token) => jwt.verify(token, secret(), {
|
||||
algorithms: ["HS256"],
|
||||
issuer: process.env.JWT_ISSUER || "zumri-api",
|
||||
audience: process.env.JWT_AUDIENCE || "zumri-clients",
|
||||
});
|
||||
|
||||
const generateRefreshToken = (payload) => {
|
||||
return jwt.sign(payload, getSecret("REFRESH_TOKEN_SECRET"), { expiresIn: REFRESH_TOKEN_DAYS });
|
||||
}
|
||||
|
||||
const verifyRefreshToken = (token) => {
|
||||
return jwt.verify(token, getSecret("REFRESH_TOKEN_SECRET"));
|
||||
}
|
||||
|
||||
module.exports = { generateToken, verifyToken, generateRefreshToken, verifyRefreshToken };
|
||||
module.exports = { generateToken, verifyToken };
|
||||
|
||||
Reference in New Issue
Block a user