Auth #1
@@ -29,7 +29,7 @@ const {
|
|||||||
verifyPasswordResetToken,
|
verifyPasswordResetToken,
|
||||||
deletePasswordReset,
|
deletePasswordReset,
|
||||||
sendPasswordResetEmail,
|
sendPasswordResetEmail,
|
||||||
sendPasswordChangedEmail
|
sendPasswordChangedEmail,
|
||||||
} = require("../utils/passwordReset.utill");
|
} = require("../utils/passwordReset.utill");
|
||||||
const db = require("../models");
|
const db = require("../models");
|
||||||
const { log } = require("../utils/consoleLog.utill");
|
const { log } = require("../utils/consoleLog.utill");
|
||||||
@@ -250,7 +250,6 @@ exports.forgotPassword = async (req, res) => {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
email = email.trim().toLowerCase();
|
email = email.trim().toLowerCase();
|
||||||
|
|
||||||
if (!validateEmail(email)) {
|
if (!validateEmail(email)) {
|
||||||
@@ -292,151 +291,91 @@ exports.forgotPassword = async (req, res) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
exports.resetPassword = async (req, res) => {
|
exports.resetPassword = async (req, res) => {
|
||||||
|
|
||||||
try {
|
try {
|
||||||
|
const { token, newPassword, confirmPassword } = req.body;
|
||||||
|
|
||||||
const {
|
if (!token || !newPassword || !confirmPassword) {
|
||||||
token,
|
|
||||||
newPassword,
|
|
||||||
confirmPassword,
|
|
||||||
} = req.body;
|
|
||||||
|
|
||||||
|
|
||||||
if (!token ||!newPassword || !confirmPassword) {
|
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
success: false,
|
success: false,
|
||||||
message:
|
message: "Token, new password and confirm password are required",
|
||||||
"Token, new password and confirm password are required",
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
if (
|
if (newPassword !== confirmPassword) {
|
||||||
newPassword !==
|
|
||||||
confirmPassword
|
|
||||||
) {
|
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
success: false,
|
success: false,
|
||||||
message:
|
message: "Passwords do not match",
|
||||||
"Passwords do not match",
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!validatePassword(newPassword)) {
|
||||||
if (
|
|
||||||
!validatePassword(newPassword)
|
|
||||||
) {
|
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
success: false,
|
success: false,
|
||||||
message:
|
message: "Password does not meet the required criteria",
|
||||||
"Password does not meet the required criteria",
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const verification =
|
const verification = await verifyPasswordResetToken(token);
|
||||||
await verifyPasswordResetToken(
|
|
||||||
token
|
|
||||||
);
|
|
||||||
|
|
||||||
|
|
||||||
if (!verification) {
|
if (!verification) {
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
success: false,
|
success: false,
|
||||||
message:
|
message: "Reset token is invalid or expired",
|
||||||
"Reset token is invalid or expired",
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const { userId, redisKey } = verification;
|
||||||
|
|
||||||
const {
|
const user = await User.findByPk(userId);
|
||||||
userId,
|
|
||||||
redisKey,
|
|
||||||
} = verification;
|
|
||||||
|
|
||||||
const user =
|
|
||||||
await User.findByPk(userId);
|
|
||||||
|
|
||||||
|
|
||||||
if (!user) {
|
if (!user) {
|
||||||
|
await deletePasswordReset(redisKey);
|
||||||
await deletePasswordReset(
|
|
||||||
redisKey
|
|
||||||
);
|
|
||||||
|
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
success: false,
|
success: false,
|
||||||
message:
|
message: "Reset token is invalid or expired",
|
||||||
"Reset token is invalid or expired",
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const samePassword =
|
const samePassword = await checkPassword(newPassword, user.password);
|
||||||
await checkPassword(
|
|
||||||
newPassword,
|
|
||||||
user.password
|
|
||||||
);
|
|
||||||
|
|
||||||
|
|
||||||
if (samePassword) {
|
if (samePassword) {
|
||||||
return res.status(400).send({
|
return res.status(400).send({
|
||||||
success: false,
|
success: false,
|
||||||
message:
|
message: "New password must be different from the current password",
|
||||||
"New password must be different from the current password",
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const hashedPassword = await hashPassword(newPassword);
|
||||||
|
|
||||||
const hashedPassword =
|
user.password = hashedPassword;
|
||||||
await hashPassword(
|
|
||||||
newPassword
|
|
||||||
);
|
|
||||||
|
|
||||||
|
|
||||||
user.password =
|
|
||||||
hashedPassword;
|
|
||||||
|
|
||||||
user.passwordChangedAt =
|
|
||||||
new Date();
|
|
||||||
|
|
||||||
|
user.passwordChangedAt = new Date();
|
||||||
|
|
||||||
await user.save();
|
await user.save();
|
||||||
|
|
||||||
await sendPasswordChangedEmail(
|
await sendPasswordChangedEmail(user.email, user.firstName);
|
||||||
user.email,
|
|
||||||
user.firstName
|
|
||||||
);
|
|
||||||
|
|
||||||
await deletePasswordReset(
|
await deletePasswordReset(redisKey);
|
||||||
redisKey
|
|
||||||
);
|
|
||||||
|
|
||||||
deleteAllUserSessions(
|
|
||||||
user.id
|
|
||||||
);
|
|
||||||
|
|
||||||
|
deleteAllUserSessions(user.id);
|
||||||
|
|
||||||
return res.status(200).send({
|
return res.status(200).send({
|
||||||
success: true,
|
success: true,
|
||||||
message:
|
message: "Password reset successfully. Please login again.",
|
||||||
"Password reset successfully. Please login again.",
|
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
console.error("RESET PASSWORD ERROR:", error);
|
||||||
console.error(
|
|
||||||
"RESET PASSWORD ERROR:",
|
|
||||||
error
|
|
||||||
);
|
|
||||||
|
|
||||||
|
|
||||||
return res.status(500).send({
|
return res.status(500).send({
|
||||||
success: false,
|
success: false,
|
||||||
message:
|
message: "Failed to reset password",
|
||||||
"Failed to reset password",
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
// Logout: Clear the JWT cookie
|
// Logout: Clear the JWT cookie
|
||||||
exports.logout = (req, res) => {
|
exports.logout = (req, res) => {
|
||||||
res.clearCookie("access_token", {
|
res.clearCookie("access_token", {
|
||||||
|
|||||||
@@ -30,6 +30,7 @@ const {
|
|||||||
sendVerificationEmail,
|
sendVerificationEmail,
|
||||||
deleteEmailVerification,
|
deleteEmailVerification,
|
||||||
} = require("../utils/emailVerification.util");
|
} = require("../utils/emailVerification.util");
|
||||||
|
const { getUserProfile } = require("../utils/users/userProfileDetails.util");
|
||||||
const User = db.User;
|
const User = db.User;
|
||||||
const Profile = db.Profile;
|
const Profile = db.Profile;
|
||||||
|
|
||||||
@@ -345,36 +346,81 @@ exports.getAllUsers = async (req, res) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
// Get user details by ID
|
//get user profile details
|
||||||
exports.getUserById = async (req, res) => {
|
exports.userProfile = async (req, res) => {
|
||||||
try {
|
|
||||||
const { id } = req.params;
|
|
||||||
const user = await User.findOne({
|
|
||||||
where: { id },
|
|
||||||
attributes: { exclude: ["password"] },
|
|
||||||
include: [{ model: Profile, as: "profile" }],
|
|
||||||
});
|
|
||||||
|
|
||||||
if (!user) {
|
try {
|
||||||
|
const userId = req.user.id;
|
||||||
|
|
||||||
|
const profile =
|
||||||
|
await getUserProfile(userId);
|
||||||
|
|
||||||
|
|
||||||
|
if (!profile) {
|
||||||
return res.status(404).send({
|
return res.status(404).send({
|
||||||
success: false,
|
success: false,
|
||||||
message: "User not found",
|
message: "User not found",
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
res.status(200).send({
|
|
||||||
|
return res.status(200).send({
|
||||||
success: true,
|
success: true,
|
||||||
data: user,
|
message:
|
||||||
|
"User profile retrieved successfully",
|
||||||
|
|
||||||
|
data: profile,
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
res.status(500).send({
|
|
||||||
|
console.error(
|
||||||
|
"GET USER PROFILE ERROR:",
|
||||||
|
error
|
||||||
|
);
|
||||||
|
|
||||||
|
|
||||||
|
return res.status(500).send({
|
||||||
success: false,
|
success: false,
|
||||||
message: "Failed to retrieve user",
|
message:
|
||||||
error: error.message,
|
"Failed to retrieve user profile",
|
||||||
});
|
});
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// Get user details by ID
|
||||||
|
// exports.getUserById = async (req, res) => {
|
||||||
|
// try {
|
||||||
|
// const { id } = req.params;
|
||||||
|
// const user = await User.findOne({
|
||||||
|
// where: { id },
|
||||||
|
// attributes: { exclude: ["password"] },
|
||||||
|
// include: [{ model: Profile, as: "profile" }],
|
||||||
|
// });
|
||||||
|
|
||||||
|
// if (!user) {
|
||||||
|
// return res.status(404).send({
|
||||||
|
// success: false,
|
||||||
|
// message: "User not found",
|
||||||
|
// });
|
||||||
|
// }
|
||||||
|
|
||||||
|
// res.status(200).send({
|
||||||
|
// success: true,
|
||||||
|
// data: user,
|
||||||
|
// });
|
||||||
|
// } catch (error) {
|
||||||
|
// res.status(500).send({
|
||||||
|
// success: false,
|
||||||
|
// message: "Failed to retrieve user",
|
||||||
|
// error: error.message,
|
||||||
|
// });
|
||||||
|
// }
|
||||||
|
// };
|
||||||
|
|
||||||
// Update user details
|
// Update user details
|
||||||
exports.updateUser = async (req, res) => {
|
exports.updateUser = async (req, res) => {
|
||||||
const transaction = await db.sequelize.transaction();
|
const transaction = await db.sequelize.transaction();
|
||||||
|
|||||||
@@ -32,6 +32,12 @@ router.post(
|
|||||||
userController.verifyEmail
|
userController.verifyEmail
|
||||||
);
|
);
|
||||||
|
|
||||||
|
router.get(
|
||||||
|
"/profile",
|
||||||
|
authenticate,
|
||||||
|
userController.userProfile
|
||||||
|
);
|
||||||
|
|
||||||
router.get(
|
router.get(
|
||||||
"/",
|
"/",
|
||||||
authenticate,
|
authenticate,
|
||||||
@@ -39,12 +45,12 @@ router.get(
|
|||||||
userController.getAllUsers
|
userController.getAllUsers
|
||||||
);
|
);
|
||||||
|
|
||||||
router.get(
|
// router.get(
|
||||||
"/:id",
|
// "/:id",
|
||||||
authenticate,
|
// authenticate,
|
||||||
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
// authorizedAccountType(["admin", "management", "team_head", "user"]),
|
||||||
userController.getUserById
|
// userController.getUserById
|
||||||
);
|
// );
|
||||||
|
|
||||||
router.patch(
|
router.patch(
|
||||||
"/:id",
|
"/:id",
|
||||||
|
|||||||
@@ -0,0 +1,56 @@
|
|||||||
|
// app/services/userProfile.service.js
|
||||||
|
|
||||||
|
const db = require("../../models");
|
||||||
|
|
||||||
|
const User = db.User;
|
||||||
|
const Customer = db.Customer;
|
||||||
|
const BusinessCustomer = db.BusinessCustomer;
|
||||||
|
|
||||||
|
|
||||||
|
const getUserProfile = async (userId) => {
|
||||||
|
|
||||||
|
const user = await User.findByPk(userId, {
|
||||||
|
attributes: {
|
||||||
|
exclude: ["password"],
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
|
||||||
|
if (!user) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
let accountDetails = null;
|
||||||
|
|
||||||
|
if (user.accountType === "customer") {
|
||||||
|
|
||||||
|
accountDetails = await Customer.findOne({
|
||||||
|
where: {
|
||||||
|
user_id: user.id,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
else if (user.accountType === "business_customer") {
|
||||||
|
|
||||||
|
accountDetails =
|
||||||
|
await BusinessCustomer.findOne({
|
||||||
|
where: {
|
||||||
|
user_id: user.id,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
user,
|
||||||
|
accountDetails,
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
getUserProfile,
|
||||||
|
};
|
||||||
Reference in New Issue
Block a user