9d3d431416
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
32 lines
2.0 KiB
JavaScript
32 lines
2.0 KiB
JavaScript
const crypto = require("crypto");
|
|
const jwt = require("jsonwebtoken");
|
|
const { OAuth2Client } = require("google-auth-library");
|
|
|
|
let appleKeys;
|
|
let appleKeysAt = 0;
|
|
const verifyGoogleToken = async (idToken) => {
|
|
if (!process.env.GOOGLE_CLIENT_ID) throw Object.assign(new Error("Google authentication is unavailable"), { status: 503, code: "OAUTH_UNAVAILABLE" });
|
|
const ticket = await new OAuth2Client(process.env.GOOGLE_CLIENT_ID).verifyIdToken({ idToken, audience: process.env.GOOGLE_CLIENT_ID });
|
|
const payload = ticket.getPayload();
|
|
if (!payload?.sub || !payload.email || payload.email_verified !== true) throw new Error("Invalid Google identity token");
|
|
return { subject: payload.sub, email: payload.email.toLowerCase(), emailVerified: true, firstName: payload.given_name, lastName: payload.family_name };
|
|
};
|
|
|
|
const getAppleKeys = async () => {
|
|
if (appleKeys && Date.now() - appleKeysAt < 3600000) return appleKeys;
|
|
const response = await fetch("https://appleid.apple.com/auth/keys");
|
|
if (!response.ok) throw new Error("Apple key service unavailable");
|
|
appleKeys = (await response.json()).keys; appleKeysAt = Date.now(); return appleKeys;
|
|
};
|
|
const verifyAppleToken = async (idToken) => {
|
|
if (!process.env.APPLE_CLIENT_ID) throw Object.assign(new Error("Apple authentication is unavailable"), { status: 503, code: "OAUTH_UNAVAILABLE" });
|
|
const decoded = jwt.decode(idToken, { complete: true });
|
|
const key = (await getAppleKeys()).find((candidate) => candidate.kid === decoded?.header?.kid && candidate.alg === "RS256");
|
|
if (!key) throw new Error("Invalid Apple identity token");
|
|
const payload = jwt.verify(idToken, crypto.createPublicKey({ key, format: "jwk" }), { algorithms: ["RS256"], issuer: "https://appleid.apple.com", audience: process.env.APPLE_CLIENT_ID });
|
|
if (!payload.sub) throw new Error("Invalid Apple identity token");
|
|
return { subject: payload.sub, email: payload.email?.toLowerCase(), emailVerified: payload.email_verified === true || payload.email_verified === "true" };
|
|
};
|
|
|
|
module.exports = { verifyGoogleToken, verifyAppleToken };
|