Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions authorization/controllers/authorization.controller.js
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,17 @@ const uuid = require('uuid');

exports.login = (req, res) => {
try {
let refreshId = req.body.userId + jwtSecret;
let salt = crypto.randomBytes(16).toString('base64');
let hash = crypto.createHmac('sha512', salt).update(refreshId).digest("base64");
req.body.refreshKey = salt;
let token = jwt.sign(req.body, jwtSecret);
let hash = crypto.createHmac('sha512', salt).update(req.body.userId + jwtSecret).digest("base64");
let b = Buffer.from(hash);
let refresh_token = b.toString('base64');
let refresh_token = salt + '.' + b.toString('base64');
let token = jwt.sign({
userId: req.body.userId,
email: req.body.email,
permissionLevel: req.body.permissionLevel,
provider: req.body.provider,
name: req.body.name,
}, jwtSecret, {expiresIn: 36000});
res.status(201).send({accessToken: token, refreshToken: refresh_token});
} catch (err) {
res.status(500).send({errors: err});
Expand All @@ -20,8 +24,13 @@ exports.login = (req, res) => {

exports.refresh_token = (req, res) => {
try {
req.body = req.jwt;
let token = jwt.sign(req.body, jwtSecret);
let token = jwt.sign({
userId: req.jwt.userId,
email: req.jwt.email,
permissionLevel: req.jwt.permissionLevel,
provider: req.jwt.provider,
name: req.jwt.name,
}, jwtSecret, {expiresIn: 36000});
res.status(201).send({id: token});
} catch (err) {
res.status(500).send({errors: err});
Expand Down
9 changes: 8 additions & 1 deletion common/config/env.config.js
Original file line number Diff line number Diff line change
@@ -1,8 +1,15 @@
const jwtSecret = process.env.JWT_SECRET;
if (!jwtSecret) {
console.error('FATAL: JWT_SECRET environment variable is not set.');
console.error('Generate one with: node -e "console.log(require(\'crypto\').randomBytes(32).toString(\'base64\'))"');
process.exit(1);
}

module.exports = {
"port": 3600,
"appEndpoint": "http://localhost:3600",
"apiEndpoint": "http://localhost:3600",
"jwt_secret": "myS33!!creeeT",
"jwt_secret": jwtSecret,
"jwt_expiration_in_seconds": 36000,
"environment": "dev",
"permissionLevels": {
Expand Down
12 changes: 8 additions & 4 deletions common/middlewares/auth.validation.middleware.js
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,14 @@ exports.verifyRefreshBodyField = (req, res, next) => {
};

exports.validRefreshNeeded = (req, res, next) => {
let b = Buffer.from(req.body.refresh_token, 'base64');
let refresh_token = b.toString();
let hash = crypto.createHmac('sha512', req.jwt.refreshKey).update(req.jwt.userId + secret).digest("base64");
if (hash === refresh_token) {
let parts = req.body.refresh_token.split('.');
if (parts.length !== 2) {
return res.status(400).send({error: 'Invalid refresh token'});
}
let salt = parts[0];
let expectedHash = Buffer.from(parts[1], 'base64').toString();
let hash = crypto.createHmac('sha512', salt).update(req.jwt.userId + secret).digest("base64");
if (hash === expectedHash) {
req.body = req.jwt;
return next();
} else {
Expand Down
2 changes: 1 addition & 1 deletion index.js
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ const AuthorizationRouter = require('./authorization/routes.config');
const UsersRouter = require('./users/routes.config');

app.use(function (req, res, next) {
res.header('Access-Control-Allow-Origin', '*');
res.header('Access-Control-Allow-Origin', req.headers.origin || 'http://localhost:3000');
res.header('Access-Control-Allow-Credentials', 'true');
res.header('Access-Control-Allow-Methods', 'GET,HEAD,PUT,PATCH,POST,DELETE');
res.header('Access-Control-Expose-Headers', 'Content-Length');
Expand Down
16 changes: 12 additions & 4 deletions users/controllers/users.controller.js
Original file line number Diff line number Diff line change
Expand Up @@ -34,13 +34,21 @@ exports.getById = (req, res) => {
});
};
exports.patchById = (req, res) => {
if (req.body.password) {
const allowedFields = ['firstName', 'lastName', 'email', 'password'];
const patchData = {};
Object.keys(req.body).forEach(key => {
if (allowedFields.includes(key)) {
patchData[key] = req.body[key];
}
});

if (patchData.password) {
let salt = crypto.randomBytes(16).toString('base64');
let hash = crypto.createHmac('sha512', salt).update(req.body.password).digest("base64");
req.body.password = salt + "$" + hash;
let hash = crypto.createHmac('sha512', salt).update(patchData.password).digest("base64");
patchData.password = salt + "$" + hash;
}

UserModel.patchUser(req.params.userId, req.body)
UserModel.patchUser(req.params.userId, patchData)
.then((result) => {
res.status(204).send({});
});
Expand Down