Simple actual auth
This commit is contained in:
@@ -4,6 +4,7 @@ import {
|
||||
} from 'http-status-codes';
|
||||
import { narrow } from "@/types/typeUtils";
|
||||
import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth";
|
||||
import { initDb } from "../db";
|
||||
|
||||
type Intents = 'server' | 'client';
|
||||
|
||||
@@ -57,7 +58,7 @@ export async function POST(req: NextRequest) {
|
||||
switch (narrowIntents(intents[0])) {
|
||||
case 'server':
|
||||
SERVER_AUTH_TOKENS[token] = {
|
||||
user_id, // placeholder
|
||||
user_id,
|
||||
server_ip: String(server_ip),
|
||||
};
|
||||
return NextResponse.json({ message: "ok", token });
|
||||
@@ -67,4 +68,6 @@ export async function POST(req: NextRequest) {
|
||||
default:
|
||||
return NextResponse.json({ message: 'Invalid intentions' }, { status: StatusCodes.BAD_REQUEST });
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
initDb();
|
||||
@@ -0,0 +1,32 @@
|
||||
import { Pool } from "pg";
|
||||
|
||||
const pool = new Pool({
|
||||
user: "klestiselimaj",
|
||||
host: "localhost",
|
||||
database: "postgres",
|
||||
password: "",
|
||||
port: 5432,
|
||||
});
|
||||
|
||||
const createUsersTableQuery = `
|
||||
CREATE TABLE IF NOT EXISTS users (
|
||||
id BIGSERIAL PRIMARY KEY,
|
||||
username VARCHAR(32) UNIQUE NOT NULL,
|
||||
email VARCHAR(255) UNIQUE NOT NULL,
|
||||
password_hash TEXT NOT NULL,
|
||||
created_at TIMESTAMP DEFAULT NOW() NOT NULL,
|
||||
updated_at TIMESTAMP DEFAULT NOW() NOT NULL
|
||||
);
|
||||
`;
|
||||
|
||||
export async function initDb() {
|
||||
try {
|
||||
await pool.query(createUsersTableQuery);
|
||||
console.log("Users table is ready");
|
||||
} catch (err) {
|
||||
console.error("Error creating users table:", err);
|
||||
throw err;
|
||||
}
|
||||
}
|
||||
|
||||
export default pool;
|
||||
@@ -0,0 +1,57 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import pool from "../db";
|
||||
import { StatusCodes } from "http-status-codes";
|
||||
import { CLIENT_AUTH_TOKENS } from "../auth/auth";
|
||||
|
||||
/*
|
||||
Input:
|
||||
{
|
||||
"name": "<Bob Smith>",
|
||||
"password": "<bobsmith21>"
|
||||
}
|
||||
Output:
|
||||
{
|
||||
"message": "ok",
|
||||
"token": "<crypto-uuid>",
|
||||
}
|
||||
*/
|
||||
export async function POST(req: NextRequest) {
|
||||
let { name, username, email, password } = await req.json();
|
||||
|
||||
const user_ = await pool.query(
|
||||
"SELECT id, username, email FROM users WHERE username = $1;",
|
||||
[username]
|
||||
);
|
||||
|
||||
if (user_.rows.length > 0) {
|
||||
return NextResponse.json({ message: "Username already used" }, { status: StatusCodes.CONFLICT });
|
||||
}
|
||||
|
||||
const user_email = await pool.query(
|
||||
"SELECT id, username, email FROM users WHERE email = $1;",
|
||||
[email]
|
||||
);
|
||||
|
||||
if (user_email.rows.length > 0) {
|
||||
return NextResponse.json({ message: "Email already used" }, { status: StatusCodes.CONFLICT });
|
||||
}
|
||||
|
||||
// TODO: Hash the password
|
||||
const result = await pool.query("INSERT INTO users (username, email, password_hash) VALUES ($1, $2, $3) RETURNING id;", [username, email, password]);
|
||||
const token = crypto.randomUUID();
|
||||
|
||||
CLIENT_AUTH_TOKENS[token] = result.rows[0].id;
|
||||
|
||||
return NextResponse.json({ message: "ok", token, user_id: result.rows[0].id });
|
||||
}
|
||||
|
||||
export async function DELETE(req: NextRequest) {
|
||||
let { username } = await req.json();
|
||||
|
||||
await pool.query(
|
||||
"DELETE FROM users WHERE username = $1;",
|
||||
[username]
|
||||
);
|
||||
|
||||
return NextResponse.json({ message: "ok" });
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
import axios from "axios";
|
||||
|
||||
console.log((await axios.delete("http://localhost:3000/api/user", {
|
||||
data: { username: "leo" },
|
||||
})).data);
|
||||
|
||||
console.log((await axios.post('http://localhost:3000/api/user', {
|
||||
username: 'leo',
|
||||
name: 'Leo',
|
||||
email: '',
|
||||
password: 'Idk123',
|
||||
})).data);
|
||||
Reference in New Issue
Block a user