Files
parcer/server/src/routes/auth.ts

94 lines
3.5 KiB
TypeScript
Raw Normal View History

2024-09-24 17:39:50 +05:30
import { Router, Request, Response } from 'express';
2024-09-24 17:29:48 +05:30
import User from '../models/User';
2024-09-23 23:54:19 +05:30
import jwt from 'jsonwebtoken';
2024-09-25 18:52:03 +05:30
import { hashPassword, comparePassword } from '../utils/auth';
2024-09-23 23:57:12 +05:30
export const router = Router();
2024-09-23 23:54:19 +05:30
2024-09-24 17:39:50 +05:30
interface AuthenticatedRequest extends Request {
user?: { id: string };
}
2024-09-23 23:57:12 +05:30
router.post('/register', async (req, res) => {
2024-09-23 23:54:19 +05:30
try {
const { email, password } = req.body
if (!email) return res.status(400).send('Email is required')
if (!password || password.length < 6) return res.status(400).send('Password is required and must be at least 6 characters')
2024-09-24 17:29:48 +05:30
let userExist = await User.findOne({ where: { email } });
2024-09-23 23:54:19 +05:30
if (userExist) return res.status(400).send('User already exists')
2024-09-25 18:52:03 +05:30
const hashedPassword = await hashPassword(password)
2024-09-23 23:54:19 +05:30
2024-09-25 18:52:03 +05:30
const user = await User.create({ email, password: hashedPassword });
2024-09-24 17:29:48 +05:30
const token = jwt.sign({ id: user.id }, process.env.JWT_SECRET as string, { expiresIn: '1h' });
user.password = undefined as unknown as string
2024-09-23 23:54:19 +05:30
res.cookie('token', token, {
httpOnly: true
})
res.json(user)
2024-09-24 19:07:02 +05:30
} catch (error: any) {
2024-09-23 23:54:19 +05:30
res.status(500).send(`Could not register user - ${error.message}`)
}
2024-09-23 23:57:12 +05:30
})
2024-09-23 23:54:19 +05:30
2024-09-23 23:57:43 +05:30
router.post('/login', async (req, res) => {
2024-09-23 23:55:23 +05:30
try {
const { email, password } = req.body;
if (!email || !password) return res.status(400).send('Email and password are required')
if (password.length < 6) return res.status(400).send('Password must be at least 6 characters')
2024-09-25 19:53:45 +05:30
let user = await User.findOne({raw: true, where: { email } });
2024-09-25 18:52:03 +05:30
if (!user) return res.status(400).send('User does not exist');
const match = await comparePassword(password, user.password)
2024-09-23 23:55:23 +05:30
if (!match) return res.status(400).send('Invalid email or password')
2024-09-24 17:31:56 +05:30
const token = jwt.sign({ id: user?.id }, process.env.JWT_SECRET as string, { expiresIn: '1h' });
2024-09-23 23:55:23 +05:30
// return user and token to client, exclude hashed password
if (user) {
user.password = undefined as unknown as string;
}
2024-09-23 23:55:23 +05:30
res.cookie('token', token, {
httpOnly: true
})
res.json(user)
2024-09-24 19:07:02 +05:30
} catch (error: any) {
2024-09-23 23:55:23 +05:30
res.status(400).send(`Could not login user - ${error.message}`)
2024-09-25 19:53:45 +05:30
console.log(`Could not login user - ${error}`)
2024-09-23 23:55:23 +05:30
}
2024-09-23 23:57:43 +05:30
})
2024-09-23 23:55:41 +05:30
2024-09-23 23:58:14 +05:30
router.get('/logout', async (req, res) => {
2024-09-23 23:55:41 +05:30
try {
res.clearCookie('token')
return res.json({ message: 'Logout successful' })
2024-09-24 19:07:02 +05:30
} catch (error: any) {
2024-09-23 23:55:41 +05:30
res.status(500).send(`Could not logout user - ${error.message}`)
}
2024-09-23 23:58:14 +05:30
})
2024-09-23 23:55:53 +05:30
2024-09-24 17:39:50 +05:30
router.get('/current-user', async (req: AuthenticatedRequest, res) => {
2024-09-25 16:25:35 +05:30
console.log('Current user request received');
2024-09-23 23:55:53 +05:30
try {
2024-09-24 17:39:50 +05:30
if (!req.user) {
2024-09-25 16:25:35 +05:30
console.log('No user in request');
2024-09-25 16:16:49 +05:30
return res.status(401).json({ ok: false, error: 'Unauthorized' });
2024-09-24 17:39:50 +05:30
}
2024-09-25 16:25:35 +05:30
console.log('Fetching user with id:', req.user.id);
2024-09-24 17:33:51 +05:30
const user = await User.findByPk(req.user.id, {
2024-09-24 17:40:20 +05:30
attributes: { exclude: ['password'] },
});
2024-09-25 15:59:33 +05:30
if (!user) {
2024-09-25 16:25:35 +05:30
console.log('User not found in database');
2024-09-25 15:59:33 +05:30
return res.status(404).json({ ok: false, error: 'User not found' });
}
2024-09-25 16:25:35 +05:30
console.log('User found, sending response');
2024-09-25 16:16:49 +05:30
return res.status(200).json({ ok: true, user: user });
2024-09-24 19:07:02 +05:30
} catch (error: any) {
2024-09-25 16:25:35 +05:30
console.error('Error in current-user route:', error);
2024-09-25 16:16:49 +05:30
return res.status(500).json({ ok: false, error: `Could not fetch current user: ${error.message}` });
2024-09-23 23:55:53 +05:30
}
2024-09-24 00:01:32 +05:30
});