Simple actual auth

This commit is contained in:
2025-09-23 23:15:44 +02:00
parent 32291f19b5
commit e00a589ae6
6 changed files with 270 additions and 3 deletions
+5 -2
View File
@@ -4,6 +4,7 @@ import {
} from 'http-status-codes';
import { narrow } from "@/types/typeUtils";
import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth";
import { initDb } from "../db";
type Intents = 'server' | 'client';
@@ -57,7 +58,7 @@ export async function POST(req: NextRequest) {
switch (narrowIntents(intents[0])) {
case 'server':
SERVER_AUTH_TOKENS[token] = {
user_id, // placeholder
user_id,
server_ip: String(server_ip),
};
return NextResponse.json({ message: "ok", token });
@@ -67,4 +68,6 @@ export async function POST(req: NextRequest) {
default:
return NextResponse.json({ message: 'Invalid intentions' }, { status: StatusCodes.BAD_REQUEST });
}
}
}
initDb();
+32
View File
@@ -0,0 +1,32 @@
import { Pool } from "pg";
const pool = new Pool({
user: "klestiselimaj",
host: "localhost",
database: "postgres",
password: "",
port: 5432,
});
const createUsersTableQuery = `
CREATE TABLE IF NOT EXISTS users (
id BIGSERIAL PRIMARY KEY,
username VARCHAR(32) UNIQUE NOT NULL,
email VARCHAR(255) UNIQUE NOT NULL,
password_hash TEXT NOT NULL,
created_at TIMESTAMP DEFAULT NOW() NOT NULL,
updated_at TIMESTAMP DEFAULT NOW() NOT NULL
);
`;
export async function initDb() {
try {
await pool.query(createUsersTableQuery);
console.log("Users table is ready");
} catch (err) {
console.error("Error creating users table:", err);
throw err;
}
}
export default pool;
+57
View File
@@ -0,0 +1,57 @@
import { NextRequest, NextResponse } from "next/server";
import pool from "../db";
import { StatusCodes } from "http-status-codes";
import { CLIENT_AUTH_TOKENS } from "../auth/auth";
/*
Input:
{
"name": "<Bob Smith>",
"password": "<bobsmith21>"
}
Output:
{
"message": "ok",
"token": "<crypto-uuid>",
}
*/
export async function POST(req: NextRequest) {
let { name, username, email, password } = await req.json();
const user_ = await pool.query(
"SELECT id, username, email FROM users WHERE username = $1;",
[username]
);
if (user_.rows.length > 0) {
return NextResponse.json({ message: "Username already used" }, { status: StatusCodes.CONFLICT });
}
const user_email = await pool.query(
"SELECT id, username, email FROM users WHERE email = $1;",
[email]
);
if (user_email.rows.length > 0) {
return NextResponse.json({ message: "Email already used" }, { status: StatusCodes.CONFLICT });
}
// TODO: Hash the password
const result = await pool.query("INSERT INTO users (username, email, password_hash) VALUES ($1, $2, $3) RETURNING id;", [username, email, password]);
const token = crypto.randomUUID();
CLIENT_AUTH_TOKENS[token] = result.rows[0].id;
return NextResponse.json({ message: "ok", token, user_id: result.rows[0].id });
}
export async function DELETE(req: NextRequest) {
let { username } = await req.json();
await pool.query(
"DELETE FROM users WHERE username = $1;",
[username]
);
return NextResponse.json({ message: "ok" });
}