Files
Sathira Sri Sathara 9d3d431416 feat: implement identity and security features
- Added account types and privileged account types constants.
- Created admin user controller for updating user security fields.
- Developed role assignment controller for managing user roles.
- Implemented validation middleware for request schemas.
- Defined user role and auth session models for database interactions.
- Created services for authentication, email notifications, and OTP handling.
- Developed OAuth service for Google and Apple authentication.
- Added JWT utility functions for token generation and verification.
- Implemented comprehensive tests for authentication, session management, and password policies.
- Created migration for updating user schema and adding new tables for auth sessions and user identities.
2026-09-03 13:56:18 +05:30

27 lines
814 B
JavaScript

const jwt = require("jsonwebtoken");
const secret = () => {
if (!process.env.JWT_SECRET || process.env.JWT_SECRET.length < 32) throw new Error("JWT_SECRET is not configured securely");
return process.env.JWT_SECRET;
};
const generateToken = ({ userId, sessionId, tokenVersion }) => jwt.sign(
{ sid: sessionId, tokenVersion },
secret(),
{
algorithm: "HS256",
subject: userId,
issuer: process.env.JWT_ISSUER || "zumri-api",
audience: process.env.JWT_AUDIENCE || "zumri-clients",
expiresIn: process.env.ACCESS_TOKEN_TTL || "15m",
},
);
const verifyToken = (token) => jwt.verify(token, secret(), {
algorithms: ["HS256"],
issuer: process.env.JWT_ISSUER || "zumri-api",
audience: process.env.JWT_AUDIENCE || "zumri-clients",
});
module.exports = { generateToken, verifyToken };