9d3d431416
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
27 lines
814 B
JavaScript
27 lines
814 B
JavaScript
const jwt = require("jsonwebtoken");
|
|
|
|
const secret = () => {
|
|
if (!process.env.JWT_SECRET || process.env.JWT_SECRET.length < 32) throw new Error("JWT_SECRET is not configured securely");
|
|
return process.env.JWT_SECRET;
|
|
};
|
|
|
|
const generateToken = ({ userId, sessionId, tokenVersion }) => jwt.sign(
|
|
{ sid: sessionId, tokenVersion },
|
|
secret(),
|
|
{
|
|
algorithm: "HS256",
|
|
subject: userId,
|
|
issuer: process.env.JWT_ISSUER || "zumri-api",
|
|
audience: process.env.JWT_AUDIENCE || "zumri-clients",
|
|
expiresIn: process.env.ACCESS_TOKEN_TTL || "15m",
|
|
},
|
|
);
|
|
|
|
const verifyToken = (token) => jwt.verify(token, secret(), {
|
|
algorithms: ["HS256"],
|
|
issuer: process.env.JWT_ISSUER || "zumri-api",
|
|
audience: process.env.JWT_AUDIENCE || "zumri-clients",
|
|
});
|
|
|
|
module.exports = { generateToken, verifyToken };
|