267e80e2ec
- Refactor server initialization to separate concerns and improve error handling. - Implement centralized environment validation using Zod. - Introduce database, Redis, and queue lifecycle management. - Add health check endpoints for liveness and readiness. - Enhance error handling middleware for better response structure. - Implement rate limiting for API endpoints. - Add request ID middleware for traceability. - Create Sequelize CLI configuration and baseline migration for schema management. - Establish CI workflow with Gitea for testing and syntax checks. - Document foundational changes and migration strategy in PHASE_0_FOUNDATION_STABILIZATION.md. - Add Docker Compose configuration for local development and testing. - Implement unit and integration tests for critical functionality.
52 lines
1.4 KiB
JavaScript
52 lines
1.4 KiB
JavaScript
/**
|
|
* Copyright (c) 2026 Niolla
|
|
* All rights reserved.
|
|
*
|
|
* This source code is proprietary and confidential.
|
|
* Unauthorized copying, modification, distribution, or use
|
|
* of this file, via any medium, is strictly prohibited.
|
|
*/
|
|
|
|
// app/utils/jwt.util.js
|
|
|
|
const jwt = require("jsonwebtoken");
|
|
require("dotenv").config();
|
|
|
|
const JWT_EXPIRES_IN = process.env.JWT_EXPIRES_IN || "15m"; // token validity
|
|
|
|
const REFRESH_TOKEN_DAYS = process.env.REFRESH_TOKEN_DAYS || "7d"; // refresh token validity
|
|
|
|
const getSecret = (name) => {
|
|
const value = process.env[name];
|
|
if (!value || value.length < 32) throw new Error(`${name} is not configured securely`);
|
|
return value;
|
|
};
|
|
|
|
/**
|
|
* Generate JWT token
|
|
* @param {Object} payload - usually { id, email, role }
|
|
* @returns string
|
|
*/
|
|
const generateToken = (payload) => {
|
|
return jwt.sign(payload, getSecret("JWT_SECRET"), { expiresIn: JWT_EXPIRES_IN });
|
|
};
|
|
|
|
/**
|
|
* Verify JWT token
|
|
* @param {string} token
|
|
* @returns payload or throws error
|
|
*/
|
|
const verifyToken = (token) => {
|
|
return jwt.verify(token, getSecret("JWT_SECRET"));
|
|
};
|
|
|
|
const generateRefreshToken = (payload) => {
|
|
return jwt.sign(payload, getSecret("REFRESH_TOKEN_SECRET"), { expiresIn: REFRESH_TOKEN_DAYS });
|
|
}
|
|
|
|
const verifyRefreshToken = (token) => {
|
|
return jwt.verify(token, getSecret("REFRESH_TOKEN_SECRET"));
|
|
}
|
|
|
|
module.exports = { generateToken, verifyToken, generateRefreshToken, verifyRefreshToken };
|