feat: hash otp code

This commit is contained in:
2026-02-24 09:22:39 +03:30
parent 63b4567166
commit b9adbef7e8
4 changed files with 33 additions and 7 deletions
+7
View File
@@ -1,6 +1,7 @@
import { Body, Controller, HttpCode, Post } from '@nestjs/common'; import { Body, Controller, HttpCode, Post } from '@nestjs/common';
import { LoginDTO } from './dtos/login.dto'; import { LoginDTO } from './dtos/login.dto';
import { AuthService } from './providers/auth.service'; import { AuthService } from './providers/auth.service';
import { VerifyOtpDTO } from './dtos/verify-otp.dto';
@Controller('users') @Controller('users')
export class AuthController { export class AuthController {
@@ -16,4 +17,10 @@ export class AuthController {
public async logIn(@Body() loginDto: LoginDTO) { public async logIn(@Body() loginDto: LoginDTO) {
return await this.authService.logIn(loginDto); return await this.authService.logIn(loginDto);
} }
@Post('verify-otp')
@HttpCode(200)
public verifyOTP(@Body() verifyOtpDto: VerifyOtpDTO) {
return verifyOtpDto;
}
} }
@@ -14,4 +14,6 @@ export class AuthService {
public async logIn(loginDto: LoginDTO) { public async logIn(loginDto: LoginDTO) {
return await this.loginProvider.logIn(loginDto); return await this.loginProvider.logIn(loginDto);
} }
// public async verifyOTP(verifyOtpDto: VerifyOtpDTO) {}
} }
+2 -1
View File
@@ -2,9 +2,10 @@ import { Module } from '@nestjs/common';
import { OtpService } from './providers/otp.service'; import { OtpService } from './providers/otp.service';
import { TypeOrmModule } from '@nestjs/typeorm'; import { TypeOrmModule } from '@nestjs/typeorm';
import { OTP } from './otp.entity'; import { OTP } from './otp.entity';
import { HashingModule } from '@/common/modules/hashing/hashing.module';
@Module({ @Module({
imports: [TypeOrmModule.forFeature([OTP])], imports: [TypeOrmModule.forFeature([OTP]), HashingModule],
providers: [OtpService], providers: [OtpService],
exports: [OtpService], exports: [OtpService],
}) })
+22 -6
View File
@@ -2,12 +2,14 @@ import {
HttpException, HttpException,
HttpStatus, HttpStatus,
Injectable, Injectable,
RequestTimeoutException,
UnauthorizedException, UnauthorizedException,
} from '@nestjs/common'; } from '@nestjs/common';
import { LessThan, Repository } from 'typeorm'; import { LessThan, Repository } from 'typeorm';
import { OTP } from '../otp.entity'; import { OTP } from '../otp.entity';
import { InjectRepository } from '@nestjs/typeorm'; import { InjectRepository } from '@nestjs/typeorm';
import { Cron } from '@nestjs/schedule'; import { Cron } from '@nestjs/schedule';
import { HashingProvider } from '@/common/modules/hashing/providers/hashing.provider';
@Injectable() @Injectable()
export class OtpService { export class OtpService {
@@ -17,6 +19,11 @@ export class OtpService {
*/ */
@InjectRepository(OTP) @InjectRepository(OTP)
private readonly otpRepository: Repository<OTP>, private readonly otpRepository: Repository<OTP>,
/**
* Inject Hashing Provider
*/
private readonly hashingProvider: HashingProvider,
) {} ) {}
/** /**
@@ -44,9 +51,9 @@ export class OtpService {
} }
const code = this.generateOTPCode(); const code = this.generateOTPCode();
// TODO: Hash the code const hashedCode = await this.hashingProvider.hash(code);
const otp = this.otpRepository.create({ phone, code }); const otp = this.otpRepository.create({ phone, code: hashedCode });
await this.otpRepository.save(otp); await this.otpRepository.save(otp);
@@ -57,10 +64,19 @@ export class OtpService {
* Verify OTP * Verify OTP
*/ */
public async verifyOTP(phone: string, code: string): Promise<OTP> { public async verifyOTP(phone: string, code: string): Promise<OTP> {
const otp = await this.otpRepository.findOne({ let otp: OTP | null = null;
where: { phone, used: false },
order: { createdAt: 'DESC' }, try {
}); otp = await this.otpRepository.findOne({
where: { phone, used: false },
order: { createdAt: 'DESC' },
});
} catch (err) {
throw new RequestTimeoutException(
'Unable to process your request at the moment. Please try again later.',
{ cause: err, description: 'Error connecting to the database' },
);
}
if (!otp) throw new UnauthorizedException('Invalid OTP'); if (!otp) throw new UnauthorizedException('Invalid OTP');