fixed 'added 'refreshToken', converted to 'httpOnly', added SSL
fixed 'gql-types' generator
This commit is contained in:
parent
d179b8c7c8
commit
c190d368de
20 changed files with 314 additions and 179 deletions
|
|
@ -7,7 +7,7 @@ import jwt from 'jsonwebtoken';
|
|||
export async function LoginResolver(
|
||||
_: any,
|
||||
{ input }: MutationLoginArgs,
|
||||
{ identity }: IdentityContext
|
||||
{ req, res, identity }: IdentityContext
|
||||
): Promise<Session> {
|
||||
const error = 'Invalid password or email';
|
||||
|
||||
|
|
@ -36,14 +36,21 @@ export async function LoginResolver(
|
|||
data: { refreshToken }
|
||||
});
|
||||
|
||||
res.cookie('jwt', refreshToken, {
|
||||
httpOnly: true,
|
||||
sameSite: 'none',
|
||||
secure: true,
|
||||
maxAge: 24 * 60 * 60 * 1000
|
||||
});
|
||||
|
||||
return {
|
||||
accessToken,
|
||||
refreshToken: {
|
||||
token: refreshToken,
|
||||
httpOnly: true,
|
||||
secure: true,
|
||||
maxAge: 24 * 60 * 60 * 1000,
|
||||
sameSite: 'None'
|
||||
}
|
||||
accessToken
|
||||
// refreshToken: {
|
||||
// token: refreshToken,
|
||||
// httpOnly: true,
|
||||
// secure: true,
|
||||
// maxAge: 24 * 60 * 60 * 1000,
|
||||
// sameSite: 'None'
|
||||
// }
|
||||
};
|
||||
}
|
||||
|
|
|
|||
0
app/server/graphql/resolvers/auth/logout.ts
Normal file
0
app/server/graphql/resolvers/auth/logout.ts
Normal file
36
app/server/graphql/resolvers/auth/refreshToken.ts
Normal file
36
app/server/graphql/resolvers/auth/refreshToken.ts
Normal file
|
|
@ -0,0 +1,36 @@
|
|||
import { IdentityContext } from '@app/server/identity';
|
||||
import { prisma } from '@app/server/prisma/client';
|
||||
import { Session } from '@generated/types';
|
||||
import jwt from 'jsonwebtoken';
|
||||
|
||||
export async function RefreshTokenResolver(
|
||||
_: any,
|
||||
{ req, res, identity }: IdentityContext
|
||||
): Promise<Session> {
|
||||
const accessTokenSecret = process.env.ACCESS_TOKEN_SECRET;
|
||||
const refreshTokenSecret = process.env.REFRESH_TOKEN_SECRET;
|
||||
if (accessTokenSecret == null || refreshTokenSecret == null) throw new Error('No secrets found.');
|
||||
|
||||
const cookie: { jwt?: string | null } = req.cookies;
|
||||
if (cookie == null || cookie.jwt == null) throw new Error('Unauthorized.');
|
||||
|
||||
const refreshToken = cookie.jwt;
|
||||
|
||||
const user = await prisma.user.findUniqueOrThrow({
|
||||
where: { refreshToken },
|
||||
select: { id: true }
|
||||
});
|
||||
|
||||
const decoded = jwt.verify(refreshToken, accessTokenSecret) as {
|
||||
userId: string;
|
||||
iat: number;
|
||||
exp: number;
|
||||
};
|
||||
|
||||
if (user.id !== decoded.userId) throw new Error('Invalid token.');
|
||||
const accessToken = jwt.sign({ userId: user.id }, accessTokenSecret, {
|
||||
expiresIn: '30s'
|
||||
});
|
||||
|
||||
return { accessToken };
|
||||
}
|
||||
|
|
@ -1,11 +1,11 @@
|
|||
import { IdentityContext } from '@app/server/identity';
|
||||
import { prisma, uuid } from '@app/server/prisma/client';
|
||||
import { MutationRegisterArgs } from '@generated/types';
|
||||
import { MutationSignUpArgs } from '@generated/types';
|
||||
import bcrypt from 'bcrypt';
|
||||
|
||||
export async function SignUpResolver(
|
||||
_: any,
|
||||
{ input }: MutationRegisterArgs,
|
||||
{ input }: MutationSignUpArgs,
|
||||
{ identity }: IdentityContext
|
||||
): Promise<void> {
|
||||
const existingUsername = await prisma.user.findUnique({
|
||||
|
|
|
|||
|
|
@ -19,6 +19,6 @@ export async function BooksManyResolver(
|
|||
__: any,
|
||||
{ identity }: IdentityContext
|
||||
): Promise<Book[]> {
|
||||
if (identity == null) throw Error('Unauthorized');
|
||||
if (identity == null) throw new Error('Unauthorized');
|
||||
return books;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -7,7 +7,7 @@ type Query {
|
|||
|
||||
type Mutation {
|
||||
login(input: LoginInput!): Session!
|
||||
signUp(input: RegisterInput!): Void
|
||||
signUp(input: SignUpInput!): Void
|
||||
}
|
||||
|
||||
input LoginInput {
|
||||
|
|
@ -15,7 +15,7 @@ input LoginInput {
|
|||
password: String!
|
||||
}
|
||||
|
||||
input RegisterInput {
|
||||
input SignUpInput {
|
||||
email: String!
|
||||
username: String!
|
||||
password: String!
|
||||
|
|
@ -23,7 +23,6 @@ input RegisterInput {
|
|||
|
||||
type Session {
|
||||
accessToken: String!
|
||||
refreshToken: RefreshToken!
|
||||
}
|
||||
|
||||
type RefreshToken {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue