feat: add refresh token and global exception filter
This commit is contained in:
@@ -1,15 +1,15 @@
|
||||
import {
|
||||
HttpException,
|
||||
HttpStatus,
|
||||
Injectable,
|
||||
RequestTimeoutException,
|
||||
UnauthorizedException,
|
||||
} from '@nestjs/common';
|
||||
import { LessThan, Repository } from 'typeorm';
|
||||
import { LessThan, MoreThanOrEqual, Repository } from 'typeorm';
|
||||
import { OTP } from '../otp.entity';
|
||||
import { InjectRepository } from '@nestjs/typeorm';
|
||||
import { Cron } from '@nestjs/schedule';
|
||||
import { HashingProvider } from '@/common/modules/hashing/providers/hashing.provider';
|
||||
import { AppException } from '@/common/exceptions/app.exception';
|
||||
|
||||
@Injectable()
|
||||
export class OtpService {
|
||||
@@ -44,9 +44,10 @@ export class OtpService {
|
||||
});
|
||||
|
||||
if (lastOTP && Date.now() - lastOTP.createdAt.getTime() < 60_000) {
|
||||
throw new HttpException(
|
||||
'Too many requests! Try again after 1 min.',
|
||||
throw new AppException(
|
||||
'common.errors.tooManyRequests',
|
||||
HttpStatus.TOO_MANY_REQUESTS,
|
||||
{ minutes: 1 },
|
||||
);
|
||||
}
|
||||
|
||||
@@ -68,26 +69,22 @@ export class OtpService {
|
||||
|
||||
try {
|
||||
otp = await this.otpRepository.findOne({
|
||||
where: { phone, used: false },
|
||||
where: { phone, used: false, expiresAt: MoreThanOrEqual(new Date()) },
|
||||
order: { createdAt: 'DESC' },
|
||||
});
|
||||
} catch (err) {
|
||||
throw new RequestTimeoutException(
|
||||
'Unable to process your request at the moment. Please try again later.',
|
||||
{ cause: err, description: 'Error connecting to the database' },
|
||||
);
|
||||
throw new RequestTimeoutException('common.errors.requestTimeout', {
|
||||
cause: err,
|
||||
description: 'Error connecting to the database',
|
||||
});
|
||||
}
|
||||
|
||||
if (!otp) throw new UnauthorizedException('Invalid OTP');
|
||||
|
||||
if (otp.expiresAt < new Date()) {
|
||||
throw new UnauthorizedException('OTP expired');
|
||||
}
|
||||
if (!otp) throw new UnauthorizedException('auth.errors.invalidOTP');
|
||||
|
||||
const isOTPCorrect = await this.hashingProvider.compare(code, otp.code);
|
||||
|
||||
if (!isOTPCorrect) {
|
||||
throw new UnauthorizedException('Invalid OTP');
|
||||
throw new UnauthorizedException('auth.errors.invalidOTP');
|
||||
}
|
||||
|
||||
otp.used = true;
|
||||
|
||||
Reference in New Issue
Block a user