From b9adbef7e82bd3f514bd79435984d36af7612ff2 Mon Sep 17 00:00:00 2001 From: radmehr Date: Tue, 24 Feb 2026 09:22:39 +0330 Subject: [PATCH] feat: hash otp code --- src/modules/auth/auth.controller.ts | 7 ++++++ src/modules/auth/providers/auth.service.ts | 2 ++ src/modules/otp/otp.module.ts | 3 ++- src/modules/otp/providers/otp.service.ts | 28 +++++++++++++++++----- 4 files changed, 33 insertions(+), 7 deletions(-) diff --git a/src/modules/auth/auth.controller.ts b/src/modules/auth/auth.controller.ts index f63c3b7..a3a4d29 100644 --- a/src/modules/auth/auth.controller.ts +++ b/src/modules/auth/auth.controller.ts @@ -1,6 +1,7 @@ import { Body, Controller, HttpCode, Post } from '@nestjs/common'; import { LoginDTO } from './dtos/login.dto'; import { AuthService } from './providers/auth.service'; +import { VerifyOtpDTO } from './dtos/verify-otp.dto'; @Controller('users') export class AuthController { @@ -16,4 +17,10 @@ export class AuthController { public async logIn(@Body() loginDto: LoginDTO) { return await this.authService.logIn(loginDto); } + + @Post('verify-otp') + @HttpCode(200) + public verifyOTP(@Body() verifyOtpDto: VerifyOtpDTO) { + return verifyOtpDto; + } } diff --git a/src/modules/auth/providers/auth.service.ts b/src/modules/auth/providers/auth.service.ts index 24e3b6f..831bd29 100644 --- a/src/modules/auth/providers/auth.service.ts +++ b/src/modules/auth/providers/auth.service.ts @@ -14,4 +14,6 @@ export class AuthService { public async logIn(loginDto: LoginDTO) { return await this.loginProvider.logIn(loginDto); } + + // public async verifyOTP(verifyOtpDto: VerifyOtpDTO) {} } diff --git a/src/modules/otp/otp.module.ts b/src/modules/otp/otp.module.ts index 3755898..42c162b 100644 --- a/src/modules/otp/otp.module.ts +++ b/src/modules/otp/otp.module.ts @@ -2,9 +2,10 @@ import { Module } from '@nestjs/common'; import { OtpService } from './providers/otp.service'; import { TypeOrmModule } from '@nestjs/typeorm'; import { OTP } from './otp.entity'; +import { HashingModule } from '@/common/modules/hashing/hashing.module'; @Module({ - imports: [TypeOrmModule.forFeature([OTP])], + imports: [TypeOrmModule.forFeature([OTP]), HashingModule], providers: [OtpService], exports: [OtpService], }) diff --git a/src/modules/otp/providers/otp.service.ts b/src/modules/otp/providers/otp.service.ts index 6f51684..2885f9d 100644 --- a/src/modules/otp/providers/otp.service.ts +++ b/src/modules/otp/providers/otp.service.ts @@ -2,12 +2,14 @@ import { HttpException, HttpStatus, Injectable, + RequestTimeoutException, UnauthorizedException, } from '@nestjs/common'; import { LessThan, Repository } from 'typeorm'; import { OTP } from '../otp.entity'; import { InjectRepository } from '@nestjs/typeorm'; import { Cron } from '@nestjs/schedule'; +import { HashingProvider } from '@/common/modules/hashing/providers/hashing.provider'; @Injectable() export class OtpService { @@ -17,6 +19,11 @@ export class OtpService { */ @InjectRepository(OTP) private readonly otpRepository: Repository, + + /** + * Inject Hashing Provider + */ + private readonly hashingProvider: HashingProvider, ) {} /** @@ -44,9 +51,9 @@ export class OtpService { } const code = this.generateOTPCode(); - // TODO: Hash the code + const hashedCode = await this.hashingProvider.hash(code); - const otp = this.otpRepository.create({ phone, code }); + const otp = this.otpRepository.create({ phone, code: hashedCode }); await this.otpRepository.save(otp); @@ -57,10 +64,19 @@ export class OtpService { * Verify OTP */ public async verifyOTP(phone: string, code: string): Promise { - const otp = await this.otpRepository.findOne({ - where: { phone, used: false }, - order: { createdAt: 'DESC' }, - }); + let otp: OTP | null = null; + + try { + otp = await this.otpRepository.findOne({ + where: { phone, used: false }, + order: { createdAt: 'DESC' }, + }); + } catch (err) { + throw new RequestTimeoutException( + 'Unable to process your request at the moment. Please try again later.', + { cause: err, description: 'Error connecting to the database' }, + ); + } if (!otp) throw new UnauthorizedException('Invalid OTP');