added jwt service. Currently it has some bugs and it is not very functional.
Also restructured the project a bit - created a service folder for the database script and the token script.
This commit is contained in:
28
backend/services/tokenService.js
Normal file
28
backend/services/tokenService.js
Normal file
@@ -0,0 +1,28 @@
|
||||
import cookieParser from "cookie-parser";
|
||||
import bodyParser from "body-parser";
|
||||
import { SignJWT, jwtVerify } from "jose";
|
||||
import env from "dotenv";
|
||||
env.config();
|
||||
const secret = new TextEncoder().encode(process.env.SECRET_KEY);
|
||||
|
||||
export async function generateToken(payload) {
|
||||
return await new SignJWT(payload)
|
||||
.setProtectedHeader({ alg: "HS256" })
|
||||
.setIssuedAt()
|
||||
.setExpirationTime("2h") // Token valid for 2 hours
|
||||
.sign(secret);
|
||||
}
|
||||
|
||||
export async function authenticate(req, res, next) {
|
||||
const token = req.cookies.token;
|
||||
|
||||
if (!token) return res.status(401).send("No token provided");
|
||||
|
||||
try {
|
||||
const { payload } = await jwtVerify(token, secret);
|
||||
req.user = payload;
|
||||
next();
|
||||
} catch (e) {
|
||||
return res.status(403).send("Invalid or expired token");
|
||||
}
|
||||
}
|
Reference in New Issue
Block a user