Files
Zumri-Backend/app/routes/user.routes.js
T
Sathira Sri Sathara 9d3d431416 feat: implement identity and security features
- Added account types and privileged account types constants.
- Created admin user controller for updating user security fields.
- Developed role assignment controller for managing user roles.
- Implemented validation middleware for request schemas.
- Defined user role and auth session models for database interactions.
- Created services for authentication, email notifications, and OTP handling.
- Developed OAuth service for Google and Apple authentication.
- Added JWT utility functions for token generation and verification.
- Implemented comprehensive tests for authentication, session management, and password policies.
- Created migration for updating user schema and adding new tables for auth sessions and user identities.
2026-09-03 13:56:18 +05:30

73 lines
1.5 KiB
JavaScript

/**
* Copyright (c) 2026 Niolla
* All rights reserved.
*
* This source code is proprietary and confidential.
* Unauthorized copying, modification, distribution, or use
* of this file, via any medium, is strictly prohibited.
*/
// app/routes/user.routes.js
const express = require("express");
const router = express.Router();
const userController = require("../controllers/user.controller");
const {
authenticate,
} = require("../middleware/auth.middleware");
const { authorizedAccountType, checkPermission } = require("../middleware/permission.middleware");
const PERMISSIONS = require("../constants/permissions");
router.get("/me", authenticate, userController.getCurrentUser);
router.patch("/me", authenticate, userController.updateCurrentUser);
router.post(
"/",
// authenticate,
// authorizedAccountType(["admin"]),
userController.createNewUser
);
router.post(
"/verify-email",
userController.verifyEmail
);
router.get(
"/profile",
authenticate,
userController.userProfile
);
router.get(
"/",
authenticate,
authorizedAccountType(["admin", "superadmin"]),
userController.getAllUsers
);
// router.get(
// "/:id",
// authenticate,
// authorizedAccountType(["admin", "management", "team_head", "user"]),
// userController.getUserById
// );
router.patch(
"/:id",
authenticate,
authorizedAccountType(["superadmin"]),
userController.updateUser
);
router.delete(
"/:id",
authenticate,
authorizedAccountType(["superadmin"]),
userController.deleteUser
);
module.exports = router;