From 32341b002bc6762b715ac1a5fd60735934a52801 Mon Sep 17 00:00:00 2001 From: Kallesh B S Date: Fri, 26 Sep 2025 12:33:43 +0530 Subject: [PATCH] auth fix --- src/auth/auth.service.ts | 22 +++++++++---------- src/guards/roles.guard.ts | 2 +- src/main.ts | 7 +++++- .../manage-clients.controller.ts | 2 +- 4 files changed, 19 insertions(+), 14 deletions(-) diff --git a/src/auth/auth.service.ts b/src/auth/auth.service.ts index 1a40a60..b0f7b14 100644 --- a/src/auth/auth.service.ts +++ b/src/auth/auth.service.ts @@ -305,22 +305,22 @@ export class AuthService { // throw new BadRequestException("Invalid username or password") // } - if (access_token && refresh_token && userSession.length > 0) { + // if (access_token && refresh_token && userSession.length > 0) { - const getSub: any = jwt.decode(refresh_token, { complete: true }) + // const getSub: any = jwt.decode(refresh_token, { complete: true }) - const user: any = await this.getUserDetailsById(getSub?.payload.sub) + // const user: any = await this.getUserDetailsById(getSub?.payload.sub) - if (user.email !== username) { - throw new UnauthorizedException("Authentication failed") - } + // if (user.email !== username) { + // throw new UnauthorizedException("Authentication failed") + // } - let tokens = await this.getTokenFromRefreshToken(req); - const decoded = jwt.decode(access_token, { complete: true }); - const email: any = (decoded && typeof decoded === 'object') ? (decoded as any).payload?.email : undefined; - return { ...tokens, email, ApplicationName: ROLE } + // let tokens = await this.getTokenFromRefreshToken(req); + // const decoded = jwt.decode(access_token, { complete: true }); + // const email: any = (decoded && typeof decoded === 'object') ? (decoded as any).payload?.email : undefined; + // return { ...tokens, email, ApplicationName: ROLE } - } + // } const response = await axios.post(this.TOKEN_URL, params, { headers: { 'Content-Type': 'application/x-www-form-urlencoded' }, diff --git a/src/guards/roles.guard.ts b/src/guards/roles.guard.ts index cd86e12..83ed376 100644 --- a/src/guards/roles.guard.ts +++ b/src/guards/roles.guard.ts @@ -37,7 +37,7 @@ export class RolesGuard implements CanActivate { try { const decoded: any = jwt.decode(token); - const roles: string[] = decoded?.resource_access?.['carnet-app']?.roles || []; + const roles: string[] = decoded?.resource_access?.[process.env.CLIENT_ID || '']?.roles || []; const hasRole = requiredRoles.some(role => roles.includes(role)); if (!hasRole) { diff --git a/src/main.ts b/src/main.ts index a152e6b..73722a6 100644 --- a/src/main.ts +++ b/src/main.ts @@ -20,7 +20,12 @@ async function bootstrap() { 'http://localhost:5173', 'https://policy.alphaomegainfosys.com', 'https://sp.alphaomegainfosys.com', - 'https://client.alphaomegainfosys.com' + 'https://policy-2.alphaomegainfosys.com', + 'https://client-2.alphaomegainfosys.com', + 'https://sp-2.alphaomegainfosys.com', + 'https://policy-1.alphaomegainfosys.com', + 'https://client-1.alphaomegainfosys.com', + 'https://sp-1.alphaomegainfosys.com', ], methods: 'GET,HEAD,PUT,PATCH,POST,DELETE', preflightContinue: false, diff --git a/src/pg/manage-clients/manage-clients.controller.ts b/src/pg/manage-clients/manage-clients.controller.ts index 7442ec0..1c146ab 100644 --- a/src/pg/manage-clients/manage-clients.controller.ts +++ b/src/pg/manage-clients/manage-clients.controller.ts @@ -57,7 +57,7 @@ export class ManageClientsController { } @Post('CreateClientLocations') - @Roles('pca', 'psa') + @Roles('pca', 'psa', 'pua') CreateClientLocation(@Body() body: CreateClientLocationsDTO) { return this.manageClientsService.CreateClientLocation(body); }