re-implemented JWT auth

This commit is contained in:
lnn0q 2025-04-18 14:47:42 +03:00
parent c190d368de
commit b47b0f3752
18 changed files with 390 additions and 174 deletions

View file

@ -3,6 +3,7 @@ import { prisma } from '@app/server/prisma/client';
import { MutationLoginArgs, Session } from '@generated/types';
import bcrypt from 'bcrypt';
import jwt from 'jsonwebtoken';
import { config } from '@app/server/main';
export async function LoginResolver(
_: any,
@ -19,16 +20,11 @@ export async function LoginResolver(
const match = await bcrypt.compare(input.password, user.password);
if (!match) throw new Error(error);
const accessTokenSecret = process.env.ACCESS_TOKEN_SECRET;
const refreshTokenSecret = process.env.REFRESH_TOKEN_SECRET;
if (accessTokenSecret == null || refreshTokenSecret == null) throw new Error('No secrets found');
const accessToken = jwt.sign({ userId: user.id }, accessTokenSecret, {
expiresIn: '30s'
const accessToken = jwt.sign({ userId: user.id }, config.accessToken.secret, {
expiresIn: config.accessToken.expiresIn
});
const refreshToken = jwt.sign({ userId: user.id }, refreshTokenSecret, {
expiresIn: '1d'
const refreshToken = jwt.sign({ userId: user.id }, config.refreshToken.secret, {
expiresIn: config.refreshToken.expiresIn
});
await prisma.user.update({
@ -40,17 +36,10 @@ export async function LoginResolver(
httpOnly: true,
sameSite: 'none',
secure: true,
maxAge: 24 * 60 * 60 * 1000
maxAge: config.refreshToken.maxAge
});
return {
accessToken
// refreshToken: {
// token: refreshToken,
// httpOnly: true,
// secure: true,
// maxAge: 24 * 60 * 60 * 1000,
// sameSite: 'None'
// }
};
}

View file

@ -0,0 +1,32 @@
import { IdentityContext } from '@app/server/identity';
import { prisma } from '@app/server/prisma/client';
export async function LogoutResolver(
_: any,
__: any,
{ req, res, identity }: IdentityContext
): Promise<void> {
const cookie: { jwt?: string | null } = req.cookies;
if (cookie == null || cookie.jwt == null) return;
const refreshToken = cookie.jwt;
const user = await prisma.user.findUnique({
where: { refreshToken },
select: { id: true }
});
if (user == null) {
res.clearCookie('jwt', { httpOnly: true });
return;
}
await prisma.user.update({
where: {
id: user.id
},
data: { refreshToken: null }
});
res.clearCookie('jwt', { httpOnly: true });
}

View file

@ -1,36 +0,0 @@
import { IdentityContext } from '@app/server/identity';
import { prisma } from '@app/server/prisma/client';
import { Session } from '@generated/types';
import jwt from 'jsonwebtoken';
export async function RefreshTokenResolver(
_: any,
{ req, res, identity }: IdentityContext
): Promise<Session> {
const accessTokenSecret = process.env.ACCESS_TOKEN_SECRET;
const refreshTokenSecret = process.env.REFRESH_TOKEN_SECRET;
if (accessTokenSecret == null || refreshTokenSecret == null) throw new Error('No secrets found.');
const cookie: { jwt?: string | null } = req.cookies;
if (cookie == null || cookie.jwt == null) throw new Error('Unauthorized.');
const refreshToken = cookie.jwt;
const user = await prisma.user.findUniqueOrThrow({
where: { refreshToken },
select: { id: true }
});
const decoded = jwt.verify(refreshToken, accessTokenSecret) as {
userId: string;
iat: number;
exp: number;
};
if (user.id !== decoded.userId) throw new Error('Invalid token.');
const accessToken = jwt.sign({ userId: user.id }, accessTokenSecret, {
expiresIn: '30s'
});
return { accessToken };
}

View file

@ -6,7 +6,7 @@ import bcrypt from 'bcrypt';
export async function SignUpResolver(
_: any,
{ input }: MutationSignUpArgs,
{ identity }: IdentityContext
{ req, res, identity }: IdentityContext
): Promise<void> {
const existingUsername = await prisma.user.findUnique({
where: { username: input.username },

View file

@ -17,8 +17,9 @@ export const books = [
export async function BooksManyResolver(
_: any,
__: any,
{ identity }: IdentityContext
{ req, res, identity }: IdentityContext
): Promise<Book[]> {
if (identity == null) throw new Error('Unauthorized');
return books;
}