Auth #1
@@ -56,8 +56,8 @@ POST: http://localhost:3070/api/auth/login
|
||||
"email": "sathira@niolla.lk",
|
||||
"firstName": "Jhon",
|
||||
"lastName": "Doe",
|
||||
"role": "System Developer",
|
||||
"accountType": "admin"
|
||||
"accountType": "admin",
|
||||
"accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9......"
|
||||
}
|
||||
}
|
||||
```
|
||||
@@ -90,7 +90,6 @@ No Body
|
||||
"firstName": "Sathira",
|
||||
"lastName": "Sri Sathsara",
|
||||
"email": "sathira@niolla.lk",
|
||||
"role": "System Developer",
|
||||
"accountType": "admin",
|
||||
"iat": 1778865265,
|
||||
"exp": 1778868865,
|
||||
|
||||
@@ -18,7 +18,9 @@ emailVerifiedAt = null
|
||||
POST: http://localhost:3070/api/user
|
||||
```
|
||||
|
||||
**Request Body**
|
||||
**Request Body customer**
|
||||
|
||||
accontType = customer and bussiness_customer
|
||||
|
||||
```json
|
||||
{
|
||||
@@ -26,6 +28,10 @@ POST: http://localhost:3070/api/user
|
||||
"lastName": "Bimsara",
|
||||
"email": "ibimsara00@gmail.com",
|
||||
"password": "Hello@12346"
|
||||
"accountType": "customer",
|
||||
|
||||
"address": "Colombo, Sri Lanka",
|
||||
"phoneNumber": "0771234567"
|
||||
}
|
||||
```
|
||||
|
||||
@@ -45,21 +51,20 @@ POST: http://localhost:3070/api/user
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
After registration, the user receives an email containing a verification link.
|
||||
```
|
||||
|
||||
|
||||
|
||||
#### Verify Email
|
||||
|
||||
Verifies the customer's email using the raw verification token received by email.
|
||||
|
||||
The backend hashes the received token and compares the resulting hash with the `tokenHash` stored in the `email_verifications` table.
|
||||
|
||||
The token must:
|
||||
|
||||
```text
|
||||
Exist in the database
|
||||
Not have been used
|
||||
Not have expired
|
||||
store in redis and expire token
|
||||
```
|
||||
|
||||
**Endpoint**
|
||||
@@ -107,7 +112,44 @@ usedAt = <current date and time>
|
||||
|
||||
This prevents the same verification token from being successfully used again.
|
||||
|
||||
---
|
||||
#### Get user's details
|
||||
|
||||
**Endpoint**
|
||||
|
||||
```
|
||||
GET: http://localhost:3070/api/profile
|
||||
```
|
||||
|
||||
**Respond**
|
||||
|
||||
```json
|
||||
{
|
||||
"success": true,
|
||||
"message": "User profile retrieved successfully",
|
||||
"data": {
|
||||
"user": {
|
||||
"id": "usr_572gtlpi",
|
||||
"firstName": "Isuru",
|
||||
"lastName": "Bimsara",
|
||||
"email": "ibimsara00@gmail.com",
|
||||
"accountType": "customer",
|
||||
"accountStatus": "ACTIVE",
|
||||
"emailVerifiedAt": "2026-08-20T16:26:04.000Z",
|
||||
"passwordChangedAt": "2026-08-21T05:29:16.000Z",
|
||||
"createdAt": "2026-08-20T16:25:30.000Z",
|
||||
"updatedAt": "2026-08-21T05:29:16.000Z"
|
||||
},
|
||||
"accountDetails": {
|
||||
"customer_id": "cust_c8avqwbc",
|
||||
"user_id": "usr_572gtlpi",
|
||||
"address": "Colombo, Sri Lanka",
|
||||
"phoneNumber": "0771234567",
|
||||
"createdAt": "2026-08-20T16:25:31.000Z",
|
||||
"updatedAt": "2026-08-20T16:25:31.000Z"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
#### Get All Users
|
||||
|
||||
@@ -377,12 +377,57 @@ exports.resetPassword = async (req, res) => {
|
||||
|
||||
|
||||
// Logout: Clear the JWT cookie
|
||||
exports.logout = (req, res) => {
|
||||
exports.logout = async (req, res) => {
|
||||
try {
|
||||
// 1. Get refresh token from cookie
|
||||
const refreshToken = req.cookies?.refresh_token;
|
||||
|
||||
// 2. If refresh token exists, find its session
|
||||
if (refreshToken) {
|
||||
const session = validateRefreshSession(refreshToken);
|
||||
|
||||
// 3. Delete refresh session from server RAM
|
||||
if (session) {
|
||||
deleteRefreshSession(session.sessionId);
|
||||
|
||||
console.log(
|
||||
`Refresh session deleted: ${session.sessionId}`
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// 4. Clear access token cookie
|
||||
res.clearCookie("access_token", {
|
||||
httpOnly: true,
|
||||
secure: process.env.NODE_ENV === "production",
|
||||
sameSite: process.env.NODE_ENV === "production" ? "None" : "Lax",
|
||||
sameSite:
|
||||
process.env.NODE_ENV === "production"
|
||||
? "None"
|
||||
: "Lax",
|
||||
});
|
||||
|
||||
res.json({ success: true, message: "Logged out successfully" });
|
||||
// 5. Clear refresh token cookie
|
||||
res.clearCookie("refresh_token", {
|
||||
httpOnly: true,
|
||||
secure: process.env.NODE_ENV === "production",
|
||||
sameSite:
|
||||
process.env.NODE_ENV === "production"
|
||||
? "None"
|
||||
: "Lax",
|
||||
});
|
||||
|
||||
// 6. Send response
|
||||
return res.status(200).json({
|
||||
success: true,
|
||||
message: "Logged out successfully",
|
||||
});
|
||||
|
||||
} catch (error) {
|
||||
console.error("LOGOUT ERROR:", error);
|
||||
|
||||
return res.status(500).json({
|
||||
success: false,
|
||||
message: "Failed to logout",
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
@@ -13,7 +13,7 @@ const jwt = require("jsonwebtoken");
|
||||
require("dotenv").config();
|
||||
|
||||
const JWT_SECRET = process.env.JWT_SECRET || "your_jwt_secret_key";
|
||||
const JWT_EXPIRES_IN = process.env.JWT_EXPIRES_IN || "1d"; // token validity
|
||||
const JWT_EXPIRES_IN = process.env.JWT_EXPIRES_IN || "15m"; // token validity
|
||||
|
||||
const REFRESH_TOKEN_SECRET = process.env.REFRESH_TOKEN_SECRET || "your_refresh_token_secret_key";
|
||||
const REFRESH_TOKEN_DAYS = process.env.REFRESH_TOKEN_DAYS || "7d"; // refresh token validity
|
||||
|
||||
Reference in New Issue
Block a user