9d3d431416
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
73 lines
1.5 KiB
JavaScript
73 lines
1.5 KiB
JavaScript
/**
|
|
* Copyright (c) 2026 Niolla
|
|
* All rights reserved.
|
|
*
|
|
* This source code is proprietary and confidential.
|
|
* Unauthorized copying, modification, distribution, or use
|
|
* of this file, via any medium, is strictly prohibited.
|
|
*/
|
|
|
|
// app/routes/user.routes.js
|
|
|
|
const express = require("express");
|
|
const router = express.Router();
|
|
const userController = require("../controllers/user.controller");
|
|
const {
|
|
authenticate,
|
|
} = require("../middleware/auth.middleware");
|
|
|
|
const { authorizedAccountType, checkPermission } = require("../middleware/permission.middleware");
|
|
const PERMISSIONS = require("../constants/permissions");
|
|
|
|
router.get("/me", authenticate, userController.getCurrentUser);
|
|
router.patch("/me", authenticate, userController.updateCurrentUser);
|
|
|
|
|
|
router.post(
|
|
"/",
|
|
// authenticate,
|
|
// authorizedAccountType(["admin"]),
|
|
userController.createNewUser
|
|
);
|
|
|
|
router.post(
|
|
"/verify-email",
|
|
userController.verifyEmail
|
|
);
|
|
|
|
router.get(
|
|
"/profile",
|
|
authenticate,
|
|
userController.userProfile
|
|
);
|
|
|
|
router.get(
|
|
"/",
|
|
authenticate,
|
|
authorizedAccountType(["admin", "superadmin"]),
|
|
userController.getAllUsers
|
|
);
|
|
|
|
// router.get(
|
|
// "/:id",
|
|
// authenticate,
|
|
// authorizedAccountType(["admin", "management", "team_head", "user"]),
|
|
// userController.getUserById
|
|
// );
|
|
|
|
router.patch(
|
|
"/:id",
|
|
authenticate,
|
|
authorizedAccountType(["superadmin"]),
|
|
userController.updateUser
|
|
);
|
|
|
|
router.delete(
|
|
"/:id",
|
|
authenticate,
|
|
authorizedAccountType(["superadmin"]),
|
|
userController.deleteUser
|
|
);
|
|
|
|
module.exports = router;
|