feat: implement identity and security features

- Added account types and privileged account types constants.
- Created admin user controller for updating user security fields.
- Developed role assignment controller for managing user roles.
- Implemented validation middleware for request schemas.
- Defined user role and auth session models for database interactions.
- Created services for authentication, email notifications, and OTP handling.
- Developed OAuth service for Google and Apple authentication.
- Added JWT utility functions for token generation and verification.
- Implemented comprehensive tests for authentication, session management, and password policies.
- Created migration for updating user schema and adding new tables for auth sessions and user identities.
This commit is contained in:
Sathira Sri Sathara
2026-09-03 13:56:18 +05:30
parent 267e80e2ec
commit 9d3d431416
54 changed files with 1389 additions and 1076 deletions
+22
View File
@@ -0,0 +1,22 @@
const jwt = require("jsonwebtoken");
const { generateToken, verifyToken } = require("../../app/utils/jwt.util");
describe("access JWT", () => {
test("contains only session security claims and validates issuer/audience", () => {
const token = generateToken({ userId: "usr-1", sessionId: "sid-1", tokenVersion: 3 });
const payload = verifyToken(token);
expect(payload).toMatchObject({ sub: "usr-1", sid: "sid-1", tokenVersion: 3, iss: "zumri-api", aud: "zumri-clients" });
expect(payload.password).toBeUndefined();
});
test("rejects the wrong issuer and audience", () => {
const token = jwt.sign({ sid: "sid", tokenVersion: 0 }, process.env.JWT_SECRET, { algorithm: "HS256", subject: "usr", issuer: "attacker", audience: "wrong", expiresIn: "1m" });
expect(() => verifyToken(token)).toThrow();
});
test("rejects expired and malformed tokens", () => {
const expired = jwt.sign({ sid: "sid", tokenVersion: 0 }, process.env.JWT_SECRET, { algorithm: "HS256", subject: "usr", issuer: "zumri-api", audience: "zumri-clients", expiresIn: -1 });
expect(() => verifyToken(expired)).toThrow();
expect(() => verifyToken("not-a-token")).toThrow();
});
});