feat: add jwt auth guard and profile endpoint

This commit is contained in:
2026-02-28 08:14:04 +03:30
parent 8212ede785
commit 06f659101d
21 changed files with 371 additions and 31 deletions
+3
View File
@@ -2,6 +2,7 @@ import { Body, Controller, HttpCode, Post } from '@nestjs/common';
import { LoginDTO } from './dtos/login.dto';
import { AuthService } from './providers/auth.service';
import { VerifyOtpDTO } from './dtos/verify-otp.dto';
import { Public } from './decorators/public.decorator';
@Controller('users')
export class AuthController {
@@ -12,12 +13,14 @@ export class AuthController {
private readonly authService: AuthService,
) {}
@Public()
@Post('login')
@HttpCode(200)
public async logIn(@Body() loginDto: LoginDTO) {
return await this.authService.logIn(loginDto);
}
@Public()
@Post('verify-otp')
@HttpCode(200)
public async verifyOTP(@Body() verifyOtpDto: VerifyOtpDTO) {
+8
View File
@@ -9,6 +9,9 @@ import { ConfigService } from '@nestjs/config';
import { LoginProvider } from './providers/login.provider';
import { GenerateTokenProvider } from './providers/generate-token.provider';
import { VerifyOTPProvider } from './providers/verify-otp.provider';
import { JwtStrategy } from './strategies/jwt.strategy';
import { APP_GUARD } from '@nestjs/core';
import { GlobalAuthGuard } from './guards/global-auth.guard';
@Module({
imports: [
@@ -33,6 +36,11 @@ import { VerifyOTPProvider } from './providers/verify-otp.provider';
GenerateTokenProvider,
LoginProvider,
VerifyOTPProvider,
JwtStrategy,
{
provide: APP_GUARD,
useClass: GlobalAuthGuard,
},
],
})
export class AuthModule {}
+1
View File
@@ -0,0 +1 @@
export const IS_PUBLIC_KEY = 'isPublic';
@@ -0,0 +1,4 @@
import { SetMetadata } from '@nestjs/common';
import { IS_PUBLIC_KEY } from '../constants';
export const Public = () => SetMetadata(IS_PUBLIC_KEY, true);
@@ -0,0 +1,32 @@
import { IS_PUBLIC_KEY } from '../constants';
import { JwtAuthGuard } from './jwt-auth.guard';
import { ExecutionContext, Injectable } from '@nestjs/common';
import { Reflector } from '@nestjs/core';
import { Observable } from 'rxjs';
@Injectable()
export class GlobalAuthGuard extends JwtAuthGuard {
constructor(
/**
* Inject Reflector
*/
private readonly reflector: Reflector,
) {
super();
}
canActivate(
context: ExecutionContext,
): boolean | Promise<boolean> | Observable<boolean> {
const isPublic = this.reflector.getAllAndOverride<boolean>(IS_PUBLIC_KEY, [
context.getHandler(),
context.getClass(),
]);
if (isPublic) {
return true;
}
return super.canActivate(context);
}
}
@@ -0,0 +1,5 @@
import { Injectable } from '@nestjs/common';
import { AuthGuard } from '@nestjs/passport';
@Injectable()
export class JwtAuthGuard extends AuthGuard('jwt') {}
@@ -2,6 +2,5 @@ POST http://localhost:3000/users/login
Content-Type: application/json
{
"phone": "09126093033",
"password": "rad1.3.5"
"phone": "09121111111"
}
@@ -2,6 +2,6 @@ POST http://localhost:3000/users/verify-otp
Content-Type: application/json
{
"phone": "09126093033",
"otp": "57903"
"phone": "09121111111",
"otp": "83793"
}
@@ -0,0 +1,42 @@
import jwtConfig from '@/config/jwt.config';
import { Inject, Injectable, UnauthorizedException } from '@nestjs/common';
import type { ConfigType } from '@nestjs/config';
import { PassportStrategy } from '@nestjs/passport';
import { ExtractJwt, Strategy } from 'passport-jwt';
import { AccessTokenPayload } from '../interfaces/jwt.interface';
import { User } from '@/modules/users/user.entity';
import { UsersService } from '@/modules/users/providers/users.service';
@Injectable()
export class JwtStrategy extends PassportStrategy(Strategy) {
constructor(
/**
* Inject Jwt Config
*/
@Inject(jwtConfig.KEY)
private readonly jwtConfiguration: ConfigType<typeof jwtConfig>,
/**
* Inject Users Service
*/
private readonly usersService: UsersService,
) {
super({
jwtFromRequest: ExtractJwt.fromAuthHeaderAsBearerToken(),
ignoreExpiration: false,
secretOrKey: jwtConfiguration.access.secret || '*********',
issuer: jwtConfiguration.issuer,
audience: jwtConfiguration.audience,
});
}
async validate(payload: AccessTokenPayload): Promise<User> {
const user = await this.usersService.findOneByPhone(payload.phone);
if (!user) {
throw new UnauthorizedException();
}
return user;
}
}