diff --git a/src/app/api/auth/route.ts b/src/app/api/auth/route.ts index 901ae3d..c7b86c4 100644 --- a/src/app/api/auth/route.ts +++ b/src/app/api/auth/route.ts @@ -1,73 +1,44 @@ import { NextRequest, NextResponse } from "next/server"; -import { - StatusCodes, -} from 'http-status-codes'; -import { narrow } from "@/types/typeUtils"; import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth"; -import { initDb } from "../db"; - -type Intents = 'server' | 'client'; - -const narrowIntents = (intents?: string | null) => narrow(intents, 'client', 'server') as Intents; +import { StatusCodes } from "http-status-codes"; export async function GET(req: NextRequest) { const url = new URL(req.url); const token = url.searchParams.get('token'); - const intents = narrowIntents(url.searchParams.get('intents')); if (!token) - return NextResponse.json({ message: "token parameter required" }); + return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.BAD_REQUEST }); - switch (intents) { - case "server": - { - const auth = SERVER_AUTH_TOKENS[token]; - - if (!auth) - return NextResponse.json({ message: "Invalid token" }); + const auth = SERVER_AUTH_TOKENS[token]; - const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1'); + if (!auth) + return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND }); - if (auth.server_ip !== ip) { - return NextResponse.json({ message: "Invalid address" }); - } - - delete SERVER_AUTH_TOKENS[token]; + const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1'); - return NextResponse.json({ message: "ok", ...auth }); - } - case "client": - { - const auth = CLIENT_AUTH_TOKENS[token]; - if (!auth) - return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND }); - return NextResponse.json({ message: "ok", auth }); - } + if (auth.server_ip !== ip) { + return NextResponse.json({ message: "Invalid address" }, { status: StatusCodes.UNAUTHORIZED }); } + + delete SERVER_AUTH_TOKENS[token]; + + return NextResponse.json({ message: "ok", ...auth }); } export async function POST(req: NextRequest) { - let { intents, server_ip } = await req.json(); - - intents = String(intents).split('/'); + let { server_ip, session_token } = await req.json(); const token = crypto.randomUUID(); - const user_id = 12; + const user_id = CLIENT_AUTH_TOKENS[session_token]; - switch (narrowIntents(intents[0])) { - case 'server': - SERVER_AUTH_TOKENS[token] = { - user_id, - server_ip: String(server_ip), - }; - return NextResponse.json({ message: "ok", token }); - case 'client': - CLIENT_AUTH_TOKENS[token] = user_id; - return NextResponse.json({ message: "ok", token }); - default: - return NextResponse.json({ message: 'Invalid intentions' }, { status: StatusCodes.BAD_REQUEST }); - } + if (!user_id) + return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND }); + + SERVER_AUTH_TOKENS[token] = { + user_id, + server_ip: String(server_ip), + }; + + return NextResponse.json({ message: "ok", token }); } - -initDb(); \ No newline at end of file diff --git a/src/app/api/user/route.ts b/src/app/api/user/route.ts index 2ad60b6..219739b 100644 --- a/src/app/api/user/route.ts +++ b/src/app/api/user/route.ts @@ -1,20 +1,8 @@ import { NextRequest, NextResponse } from "next/server"; -import pool from "../db"; +import pool, { initDb } from "../db"; import { StatusCodes } from "http-status-codes"; import { CLIENT_AUTH_TOKENS } from "../auth/auth"; -/* -Input: - { - "name": "", - "password": "" - } -Output: - { - "message": "ok", - "token": "", - } -*/ export async function POST(req: NextRequest) { let { name, username, email, password } = await req.json(); @@ -40,7 +28,7 @@ export async function POST(req: NextRequest) { const result = await pool.query("INSERT INTO users (username, email, password_hash) VALUES ($1, $2, $3) RETURNING id;", [username, email, password]); const token = crypto.randomUUID(); - CLIENT_AUTH_TOKENS[token] = result.rows[0].id; + CLIENT_AUTH_TOKENS[token] = parseInt(result.rows[0].id); return NextResponse.json({ message: "ok", token, user_id: result.rows[0].id }); } @@ -55,3 +43,5 @@ export async function DELETE(req: NextRequest) { return NextResponse.json({ message: "ok" }); } + +initDb(); \ No newline at end of file diff --git a/src/test/auth.js b/src/test/auth.js index 431fb5d..dac9e4e 100644 --- a/src/test/auth.js +++ b/src/test/auth.js @@ -1,8 +1,12 @@ import axios from "axios"; +import { getUser } from "./user.js"; + +const session_token = await getUser(); const res = (await axios.post('http://localhost:3000/api/auth', { intents: 'server', - server_ip: '127.0.0.1' + server_ip: '127.0.0.1', + session_token, })).data; const token = res.token; diff --git a/src/test/user.js b/src/test/user.js index 2bdf13f..4e506e9 100644 --- a/src/test/user.js +++ b/src/test/user.js @@ -1,12 +1,16 @@ import axios from "axios"; -console.log((await axios.delete("http://localhost:3000/api/user", { - data: { username: "leo" }, -})).data); +export async function getUser() { + console.log((await axios.delete("http://localhost:3000/api/user", { + data: { username: "leo" }, + })).data); -console.log((await axios.post('http://localhost:3000/api/user', { - username: 'leo', - name: 'Leo', - email: '', - password: 'Idk123', -})).data); + return ((await axios.post('http://localhost:3000/api/user', { + username: 'leo', + name: 'Leo', + email: '', + password: 'Idk123', + })).data).token; +} + +// await getUser(); \ No newline at end of file