Auth #1
@@ -29,7 +29,7 @@ const {
|
||||
verifyPasswordResetToken,
|
||||
deletePasswordReset,
|
||||
sendPasswordResetEmail,
|
||||
sendPasswordChangedEmail
|
||||
sendPasswordChangedEmail,
|
||||
} = require("../utils/passwordReset.utill");
|
||||
const db = require("../models");
|
||||
const { log } = require("../utils/consoleLog.utill");
|
||||
@@ -250,7 +250,6 @@ exports.forgotPassword = async (req, res) => {
|
||||
});
|
||||
}
|
||||
|
||||
|
||||
email = email.trim().toLowerCase();
|
||||
|
||||
if (!validateEmail(email)) {
|
||||
@@ -292,151 +291,91 @@ exports.forgotPassword = async (req, res) => {
|
||||
};
|
||||
|
||||
exports.resetPassword = async (req, res) => {
|
||||
|
||||
try {
|
||||
|
||||
const {
|
||||
token,
|
||||
newPassword,
|
||||
confirmPassword,
|
||||
} = req.body;
|
||||
|
||||
const { token, newPassword, confirmPassword } = req.body;
|
||||
|
||||
if (!token || !newPassword || !confirmPassword) {
|
||||
return res.status(400).send({
|
||||
success: false,
|
||||
message:
|
||||
"Token, new password and confirm password are required",
|
||||
message: "Token, new password and confirm password are required",
|
||||
});
|
||||
}
|
||||
|
||||
if (
|
||||
newPassword !==
|
||||
confirmPassword
|
||||
) {
|
||||
if (newPassword !== confirmPassword) {
|
||||
return res.status(400).send({
|
||||
success: false,
|
||||
message:
|
||||
"Passwords do not match",
|
||||
message: "Passwords do not match",
|
||||
});
|
||||
}
|
||||
|
||||
|
||||
if (
|
||||
!validatePassword(newPassword)
|
||||
) {
|
||||
if (!validatePassword(newPassword)) {
|
||||
return res.status(400).send({
|
||||
success: false,
|
||||
message:
|
||||
"Password does not meet the required criteria",
|
||||
message: "Password does not meet the required criteria",
|
||||
});
|
||||
}
|
||||
|
||||
const verification =
|
||||
await verifyPasswordResetToken(
|
||||
token
|
||||
);
|
||||
|
||||
const verification = await verifyPasswordResetToken(token);
|
||||
|
||||
if (!verification) {
|
||||
return res.status(400).send({
|
||||
success: false,
|
||||
message:
|
||||
"Reset token is invalid or expired",
|
||||
message: "Reset token is invalid or expired",
|
||||
});
|
||||
}
|
||||
|
||||
const { userId, redisKey } = verification;
|
||||
|
||||
const {
|
||||
userId,
|
||||
redisKey,
|
||||
} = verification;
|
||||
|
||||
const user =
|
||||
await User.findByPk(userId);
|
||||
|
||||
const user = await User.findByPk(userId);
|
||||
|
||||
if (!user) {
|
||||
|
||||
await deletePasswordReset(
|
||||
redisKey
|
||||
);
|
||||
await deletePasswordReset(redisKey);
|
||||
|
||||
return res.status(400).send({
|
||||
success: false,
|
||||
message:
|
||||
"Reset token is invalid or expired",
|
||||
message: "Reset token is invalid or expired",
|
||||
});
|
||||
}
|
||||
|
||||
const samePassword =
|
||||
await checkPassword(
|
||||
newPassword,
|
||||
user.password
|
||||
);
|
||||
|
||||
const samePassword = await checkPassword(newPassword, user.password);
|
||||
|
||||
if (samePassword) {
|
||||
return res.status(400).send({
|
||||
success: false,
|
||||
message:
|
||||
"New password must be different from the current password",
|
||||
message: "New password must be different from the current password",
|
||||
});
|
||||
}
|
||||
|
||||
const hashedPassword = await hashPassword(newPassword);
|
||||
|
||||
const hashedPassword =
|
||||
await hashPassword(
|
||||
newPassword
|
||||
);
|
||||
|
||||
|
||||
user.password =
|
||||
hashedPassword;
|
||||
|
||||
user.passwordChangedAt =
|
||||
new Date();
|
||||
user.password = hashedPassword;
|
||||
|
||||
user.passwordChangedAt = new Date();
|
||||
|
||||
await user.save();
|
||||
|
||||
await sendPasswordChangedEmail(
|
||||
user.email,
|
||||
user.firstName
|
||||
);
|
||||
await sendPasswordChangedEmail(user.email, user.firstName);
|
||||
|
||||
await deletePasswordReset(
|
||||
redisKey
|
||||
);
|
||||
|
||||
deleteAllUserSessions(
|
||||
user.id
|
||||
);
|
||||
await deletePasswordReset(redisKey);
|
||||
|
||||
deleteAllUserSessions(user.id);
|
||||
|
||||
return res.status(200).send({
|
||||
success: true,
|
||||
message:
|
||||
"Password reset successfully. Please login again.",
|
||||
message: "Password reset successfully. Please login again.",
|
||||
});
|
||||
|
||||
|
||||
} catch (error) {
|
||||
|
||||
console.error(
|
||||
"RESET PASSWORD ERROR:",
|
||||
error
|
||||
);
|
||||
|
||||
console.error("RESET PASSWORD ERROR:", error);
|
||||
|
||||
return res.status(500).send({
|
||||
success: false,
|
||||
message:
|
||||
"Failed to reset password",
|
||||
message: "Failed to reset password",
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
|
||||
|
||||
// Logout: Clear the JWT cookie
|
||||
exports.logout = (req, res) => {
|
||||
res.clearCookie("access_token", {
|
||||
|
||||
@@ -30,6 +30,7 @@ const {
|
||||
sendVerificationEmail,
|
||||
deleteEmailVerification,
|
||||
} = require("../utils/emailVerification.util");
|
||||
const { getUserProfile } = require("../utils/users/userProfileDetails.util");
|
||||
const User = db.User;
|
||||
const Profile = db.Profile;
|
||||
|
||||
@@ -345,36 +346,81 @@ exports.getAllUsers = async (req, res) => {
|
||||
}
|
||||
};
|
||||
|
||||
// Get user details by ID
|
||||
exports.getUserById = async (req, res) => {
|
||||
try {
|
||||
const { id } = req.params;
|
||||
const user = await User.findOne({
|
||||
where: { id },
|
||||
attributes: { exclude: ["password"] },
|
||||
include: [{ model: Profile, as: "profile" }],
|
||||
});
|
||||
//get user profile details
|
||||
exports.userProfile = async (req, res) => {
|
||||
|
||||
if (!user) {
|
||||
try {
|
||||
const userId = req.user.id;
|
||||
|
||||
const profile =
|
||||
await getUserProfile(userId);
|
||||
|
||||
|
||||
if (!profile) {
|
||||
return res.status(404).send({
|
||||
success: false,
|
||||
message: "User not found",
|
||||
});
|
||||
}
|
||||
|
||||
res.status(200).send({
|
||||
|
||||
return res.status(200).send({
|
||||
success: true,
|
||||
data: user,
|
||||
message:
|
||||
"User profile retrieved successfully",
|
||||
|
||||
data: profile,
|
||||
});
|
||||
|
||||
|
||||
} catch (error) {
|
||||
res.status(500).send({
|
||||
|
||||
console.error(
|
||||
"GET USER PROFILE ERROR:",
|
||||
error
|
||||
);
|
||||
|
||||
|
||||
return res.status(500).send({
|
||||
success: false,
|
||||
message: "Failed to retrieve user",
|
||||
error: error.message,
|
||||
message:
|
||||
"Failed to retrieve user profile",
|
||||
});
|
||||
|
||||
}
|
||||
|
||||
};
|
||||
|
||||
// Get user details by ID
|
||||
// exports.getUserById = async (req, res) => {
|
||||
// try {
|
||||
// const { id } = req.params;
|
||||
// const user = await User.findOne({
|
||||
// where: { id },
|
||||
// attributes: { exclude: ["password"] },
|
||||
// include: [{ model: Profile, as: "profile" }],
|
||||
// });
|
||||
|
||||
// if (!user) {
|
||||
// return res.status(404).send({
|
||||
// success: false,
|
||||
// message: "User not found",
|
||||
// });
|
||||
// }
|
||||
|
||||
// res.status(200).send({
|
||||
// success: true,
|
||||
// data: user,
|
||||
// });
|
||||
// } catch (error) {
|
||||
// res.status(500).send({
|
||||
// success: false,
|
||||
// message: "Failed to retrieve user",
|
||||
// error: error.message,
|
||||
// });
|
||||
// }
|
||||
// };
|
||||
|
||||
// Update user details
|
||||
exports.updateUser = async (req, res) => {
|
||||
const transaction = await db.sequelize.transaction();
|
||||
|
||||
@@ -32,6 +32,12 @@ router.post(
|
||||
userController.verifyEmail
|
||||
);
|
||||
|
||||
router.get(
|
||||
"/profile",
|
||||
authenticate,
|
||||
userController.userProfile
|
||||
);
|
||||
|
||||
router.get(
|
||||
"/",
|
||||
authenticate,
|
||||
@@ -39,12 +45,12 @@ router.get(
|
||||
userController.getAllUsers
|
||||
);
|
||||
|
||||
router.get(
|
||||
"/:id",
|
||||
authenticate,
|
||||
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
||||
userController.getUserById
|
||||
);
|
||||
// router.get(
|
||||
// "/:id",
|
||||
// authenticate,
|
||||
// authorizedAccountType(["admin", "management", "team_head", "user"]),
|
||||
// userController.getUserById
|
||||
// );
|
||||
|
||||
router.patch(
|
||||
"/:id",
|
||||
|
||||
@@ -0,0 +1,56 @@
|
||||
// app/services/userProfile.service.js
|
||||
|
||||
const db = require("../../models");
|
||||
|
||||
const User = db.User;
|
||||
const Customer = db.Customer;
|
||||
const BusinessCustomer = db.BusinessCustomer;
|
||||
|
||||
|
||||
const getUserProfile = async (userId) => {
|
||||
|
||||
const user = await User.findByPk(userId, {
|
||||
attributes: {
|
||||
exclude: ["password"],
|
||||
},
|
||||
});
|
||||
|
||||
|
||||
if (!user) {
|
||||
return null;
|
||||
}
|
||||
|
||||
|
||||
let accountDetails = null;
|
||||
|
||||
if (user.accountType === "customer") {
|
||||
|
||||
accountDetails = await Customer.findOne({
|
||||
where: {
|
||||
user_id: user.id,
|
||||
},
|
||||
});
|
||||
|
||||
}
|
||||
|
||||
else if (user.accountType === "business_customer") {
|
||||
|
||||
accountDetails =
|
||||
await BusinessCustomer.findOne({
|
||||
where: {
|
||||
user_id: user.id,
|
||||
},
|
||||
});
|
||||
|
||||
}
|
||||
|
||||
return {
|
||||
user,
|
||||
accountDetails,
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
module.exports = {
|
||||
getUserProfile,
|
||||
};
|
||||
Reference in New Issue
Block a user