Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions Utils/Auth.js
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,12 @@ const verifyToken = (req, res, next) => {
if (token === '') {
return res.sendStatus(401);
}
req.token = token;
return next();
try {
req.authUser = jwt.verify(token, process.env.JWT_SECRET);
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't really understand. Isn't this already in the development branch?

return next();
} catch (error) {
return res.sendStatus(401);
}
};

const passwordHash = (password) => {
Expand Down
8 changes: 0 additions & 8 deletions Utils/Auth.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -87,12 +87,4 @@ describe('Auth Utility File', () => {
await verifyToken(req, res, () => {});
expect(res.status).toEqual(401);
});

it('verifyToken', async () => {
const token = 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9';
const req = { headers: { authorization: `Bearer ${token}` } };
const res = mockResponse();
await verifyToken(req, res, () => {});
expect(req.token).toEqual(token);
});
});
45 changes: 8 additions & 37 deletions routes/index.js
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
const express = require('express');
const jwt = require('jsonwebtoken');
const mongoose = require('mongoose');
const { verifyToken } = require('../Utils/Auth');
const Families = require('../Models/Families');
Expand All @@ -17,13 +16,7 @@ router.get('/heartbeat', (req, res) => {
});

router.post('/backup', verifyToken, (req, res) => {
let decoded;
try {
decoded = jwt.verify(req.token, process.env.JWT_SECRET);
} catch (err) {
return res.sendStatus(401);
}
const { username } = decoded;
const { username } = req.authUser;
const { transactions } = req.body;
if (!transactions) {
return res.status(400).json({ code: 400, message: 'No transactions found' });
Expand All @@ -47,13 +40,7 @@ router.post('/backup', verifyToken, (req, res) => {
});

router.get('/backup', verifyToken, (req, res) => {
let decoded;
try {
decoded = jwt.verify(req.token, process.env.JWT_SECRET);
} catch (err) {
return res.sendStatus(401);
}
const { username } = decoded;
const { username } = req.authUser;

Users.findOne({ username }, (err, found) => {
if (err) {
Expand All @@ -66,8 +53,6 @@ router.get('/backup', verifyToken, (req, res) => {
});

router.post('/family', verifyToken, async (req, res) => {
const decoded = jwt.verify(req.token, process.env.JWT_SECRET);

const { members } = req.body;
if (!members) {
return res.status(400).json({
Expand Down Expand Up @@ -98,7 +83,7 @@ router.post('/family', verifyToken, async (req, res) => {
}

const newFamily = new Families({
creator: decoded.id,
creator: req.authUser.id,
members: filteredMembers.map((user) => user.id),
});

Expand All @@ -122,13 +107,6 @@ router.post('/family', verifyToken, async (req, res) => {
});

router.post('/family-transactions', verifyToken, async (req, res) => {
let decoded;
try {
decoded = jwt.verify(req.token, process.env.JWT_SECRET);
} catch (err) {
return res.status(401).json({ code: 401, message: 'Unauthorized' });
}

const {
amount, labelName, date, type,
} = req.body;
Expand All @@ -141,8 +119,8 @@ router.post('/family-transactions', verifyToken, async (req, res) => {
}

const family = await Families.findOne({
$or: [{ members: decoded.id },
{ creator: decoded.id }],
$or: [{ members: req.authUser.id },
{ creator: req.authUser.id }],
});

if (!family) {
Expand All @@ -153,7 +131,7 @@ router.post('/family-transactions', verifyToken, async (req, res) => {
}

family.transactions.push(new Transactions({
creator: decoded.id, amount, labelName, date, type,
creator: req.authUser.id, amount, labelName, date, type,
}));

family.save((err) => {
Expand All @@ -170,16 +148,9 @@ router.post('/family-transactions', verifyToken, async (req, res) => {
});

router.get('/family-transactions', verifyToken, async (req, res) => {
let decoded;
try {
decoded = jwt.verify(req.token, process.env.JWT_SECRET);
} catch (err) {
return res.status(401).json({ code: 401, message: 'Unauthorized' });
}

const family = await Families.findOne({
$or: [{ members: decoded.id },
{ creator: decoded.id }],
$or: [{ members: req.authUser.id },
{ creator: req.authUser.id }],
});

if (!family) {
Expand Down
2 changes: 1 addition & 1 deletion routes/route.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -138,7 +138,7 @@ describe('Users Route', () => {
const res = await request(app)
.get('/users')
.set('Authorization', expiredToken);
expect(res.statusCode).toEqual(500);
expect(res.statusCode).toEqual(401);
});

it('get user list without contain', async () => {
Expand Down
2 changes: 0 additions & 2 deletions routes/users.js
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
const express = require('express');
const jwt = require('jsonwebtoken');
const bcrypt = require('bcrypt');
const Users = require('../Models/Users');
const {
Expand All @@ -10,7 +9,6 @@ const mailer = require('../Utils/Mailer');
const router = express.Router();

router.get('/users', verifyToken, (req, res) => {
jwt.verify(req.token, process.env.JWT_SECRET);
const { contain } = req.query;

Users.find((err, userList) => {
Expand Down