feat: add otp and hashing modules
This commit is contained in:
@@ -2,9 +2,11 @@ import { Module } from '@nestjs/common';
|
||||
import { AuthController } from './auth.controller';
|
||||
import { AuthService } from './providers/auth.service';
|
||||
import { UsersModule } from '../users/users.module';
|
||||
import { OtpModule } from '../otp/otp.module';
|
||||
import { HashingModule } from '@/common/modules/hashing/hashing.module';
|
||||
|
||||
@Module({
|
||||
imports: [UsersModule],
|
||||
imports: [UsersModule, OtpModule, HashingModule],
|
||||
controllers: [AuthController],
|
||||
providers: [AuthService],
|
||||
})
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
import { UsersService } from '@/modules/users/providers/users.service';
|
||||
import { Injectable, UnauthorizedException } from '@nestjs/common';
|
||||
import { LoginDTO } from '../dtos/login.dto';
|
||||
import { OtpService } from '@/modules/otp/providers/otp.service';
|
||||
import { HashingProvider } from '@/common/modules/hashing/providers/hashing.provider';
|
||||
|
||||
@Injectable()
|
||||
export class AuthService {
|
||||
@@ -9,6 +11,16 @@ export class AuthService {
|
||||
* Inject Users Service
|
||||
*/
|
||||
private readonly usersService: UsersService,
|
||||
|
||||
/**
|
||||
* Inject OTP Service
|
||||
*/
|
||||
private readonly otpService: OtpService,
|
||||
|
||||
/**
|
||||
* Inject Hashing Provider
|
||||
*/
|
||||
private readonly hashingProvider: HashingProvider,
|
||||
) {}
|
||||
|
||||
public async logIn(loginDto: LoginDTO) {
|
||||
@@ -17,10 +29,13 @@ export class AuthService {
|
||||
|
||||
if (!user) {
|
||||
// TODO: Send OTP
|
||||
const otpCode = await this.otpService.createOTP(phone);
|
||||
|
||||
return {
|
||||
newUser: true,
|
||||
message: `Otp sent to ${phone}`,
|
||||
// Just for development
|
||||
code: otpCode,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -31,8 +46,12 @@ export class AuthService {
|
||||
};
|
||||
}
|
||||
|
||||
// TODO: Hash password and compare
|
||||
if (password === user.password) {
|
||||
const isPasswordCorrect = await this.hashingProvider.compare(
|
||||
password,
|
||||
user.password || '',
|
||||
);
|
||||
|
||||
if (isPasswordCorrect) {
|
||||
// TODO: Create JWT
|
||||
|
||||
return { access: 'ACCESS_TOKEN', refresh: 'REFRESH_TOKEN' };
|
||||
|
||||
@@ -33,13 +33,13 @@ export class OTP {
|
||||
|
||||
@Index()
|
||||
@Column({ type: 'timestamptz' })
|
||||
expiredAt: Date;
|
||||
expiresAt: Date;
|
||||
|
||||
@Column({ type: 'boolean', default: false })
|
||||
used: boolean;
|
||||
|
||||
@BeforeInsert()
|
||||
setExpiry() {
|
||||
this.expiredAt = new Date(Date.now() + 2 * 60 * 1000);
|
||||
this.expiresAt = new Date(Date.now() + 2 * 60 * 1000);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -6,5 +6,6 @@ import { OTP } from './otp.entity';
|
||||
@Module({
|
||||
imports: [TypeOrmModule.forFeature([OTP])],
|
||||
providers: [OtpService],
|
||||
exports: [OtpService],
|
||||
})
|
||||
export class OtpModule {}
|
||||
|
||||
@@ -1,7 +1,13 @@
|
||||
import { Injectable } from '@nestjs/common';
|
||||
import { Repository } from 'typeorm';
|
||||
import {
|
||||
HttpException,
|
||||
HttpStatus,
|
||||
Injectable,
|
||||
UnauthorizedException,
|
||||
} from '@nestjs/common';
|
||||
import { LessThan, Repository } from 'typeorm';
|
||||
import { OTP } from '../otp.entity';
|
||||
import { InjectRepository } from '@nestjs/typeorm';
|
||||
import { Cron } from '@nestjs/schedule';
|
||||
|
||||
@Injectable()
|
||||
export class OtpService {
|
||||
@@ -31,9 +37,52 @@ export class OtpService {
|
||||
});
|
||||
|
||||
if (lastOTP && Date.now() - lastOTP.createdAt.getTime() < 60_000) {
|
||||
// throw new TooMany();
|
||||
throw new HttpException(
|
||||
'Too many requests! Try again after 1 min.',
|
||||
HttpStatus.TOO_MANY_REQUESTS,
|
||||
);
|
||||
}
|
||||
|
||||
return '';
|
||||
const code = this.generateOTPCode();
|
||||
// TODO: Hash the code
|
||||
|
||||
const otp = this.otpRepository.create({ phone, code });
|
||||
|
||||
await this.otpRepository.save(otp);
|
||||
|
||||
return code;
|
||||
}
|
||||
|
||||
/**
|
||||
* Verify OTP
|
||||
*/
|
||||
public async verifyOTP(phone: string, code: string): Promise<OTP> {
|
||||
const otp = await this.otpRepository.findOne({
|
||||
where: { phone, used: false },
|
||||
order: { createdAt: 'DESC' },
|
||||
});
|
||||
|
||||
if (!otp) throw new UnauthorizedException('Invalid OTP');
|
||||
|
||||
if (otp.expiresAt < new Date()) {
|
||||
throw new UnauthorizedException('OTP expired');
|
||||
}
|
||||
|
||||
// TODO: Compared hashed otp
|
||||
if (otp.code !== code) {
|
||||
throw new UnauthorizedException('Invalid OTP');
|
||||
}
|
||||
|
||||
otp.used = true;
|
||||
await this.otpRepository.save(otp);
|
||||
|
||||
return otp;
|
||||
}
|
||||
|
||||
@Cron('0 */10 * * * *')
|
||||
public async cleanupExpired(): Promise<void> {
|
||||
await this.otpRepository.delete({
|
||||
expiresAt: LessThan(new Date()),
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2,6 +2,7 @@ import {
|
||||
Column,
|
||||
CreateDateColumn,
|
||||
Entity,
|
||||
Index,
|
||||
PrimaryGeneratedColumn,
|
||||
UpdateDateColumn,
|
||||
} from 'typeorm';
|
||||
@@ -25,6 +26,7 @@ export class User {
|
||||
})
|
||||
lastName?: string;
|
||||
|
||||
@Index({ unique: true })
|
||||
@Column({
|
||||
type: 'varchar',
|
||||
length: 11,
|
||||
@@ -37,6 +39,7 @@ export class User {
|
||||
type: 'varchar',
|
||||
length: 96,
|
||||
nullable: true,
|
||||
select: false,
|
||||
})
|
||||
password?: string;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user