auth fix
This commit is contained in:
parent
b27fee6ece
commit
67173f3a6c
@ -305,22 +305,22 @@ export class AuthService {
|
|||||||
// throw new BadRequestException("Invalid username or password")
|
// throw new BadRequestException("Invalid username or password")
|
||||||
// }
|
// }
|
||||||
|
|
||||||
if (access_token && refresh_token && userSession.length > 0) {
|
// if (access_token && refresh_token && userSession.length > 0) {
|
||||||
|
|
||||||
const getSub: any = jwt.decode(refresh_token, { complete: true })
|
// const getSub: any = jwt.decode(refresh_token, { complete: true })
|
||||||
|
|
||||||
const user: any = await this.getUserDetailsById(getSub?.payload.sub)
|
// const user: any = await this.getUserDetailsById(getSub?.payload.sub)
|
||||||
|
|
||||||
if (user.email !== username) {
|
// if (user.email !== username) {
|
||||||
throw new UnauthorizedException("Authentication failed")
|
// throw new UnauthorizedException("Authentication failed")
|
||||||
}
|
// }
|
||||||
|
|
||||||
let tokens = await this.getTokenFromRefreshToken(req);
|
// let tokens = await this.getTokenFromRefreshToken(req);
|
||||||
const decoded = jwt.decode(access_token, { complete: true });
|
// const decoded = jwt.decode(access_token, { complete: true });
|
||||||
const email: any = (decoded && typeof decoded === 'object') ? (decoded as any).payload?.email : undefined;
|
// const email: any = (decoded && typeof decoded === 'object') ? (decoded as any).payload?.email : undefined;
|
||||||
return { ...tokens, email, ApplicationName: ROLE }
|
// return { ...tokens, email, ApplicationName: ROLE }
|
||||||
|
|
||||||
}
|
// }
|
||||||
|
|
||||||
const response = await axios.post(this.TOKEN_URL, params, {
|
const response = await axios.post(this.TOKEN_URL, params, {
|
||||||
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
|
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
|
||||||
@ -845,6 +845,26 @@ export class AuthService {
|
|||||||
async getMailTemplate(body: SendMailDTO, token: string, source: string, appDomain: string): Promise<MailTemplateDTO | null> {
|
async getMailTemplate(body: SendMailDTO, token: string, source: string, appDomain: string): Promise<MailTemplateDTO | null> {
|
||||||
|
|
||||||
switch (body.P_MAIL_TYPE) {
|
switch (body.P_MAIL_TYPE) {
|
||||||
|
case MailTypeDTO.REGISTER_USCIB:
|
||||||
|
return {
|
||||||
|
to: body.P_TO,
|
||||||
|
subject: `🔐 Register Your Account`,
|
||||||
|
templateName: 'a',
|
||||||
|
variables: {
|
||||||
|
to: body.P_TO,
|
||||||
|
url: `https://${appDomain.toLowerCase() === "policy" ? "policy" : appDomain.toLowerCase() === "policy-1" ? "policy-1" : appDomain.toLowerCase() === "policy-2" ? "policy-2" : ""}.alphaomegainfosys.com/register`
|
||||||
|
}
|
||||||
|
}
|
||||||
|
case MailTypeDTO.REGISTER_SP:
|
||||||
|
return {
|
||||||
|
to: body.P_TO,
|
||||||
|
subject: `🔐 Register Your Account`,
|
||||||
|
templateName: 'a',
|
||||||
|
variables: {
|
||||||
|
to: body.P_TO,
|
||||||
|
url: `https://${appDomain.toLowerCase() === "sp" ? "sp" : appDomain.toLowerCase() === "sp-1" ? "sp-1" : appDomain.toLowerCase() === "sp-2" ? "sp-2" : ""}.alphaomegainfosys.com/register`
|
||||||
|
}
|
||||||
|
}
|
||||||
case MailTypeDTO.REGISTER_CLIENT:
|
case MailTypeDTO.REGISTER_CLIENT:
|
||||||
return {
|
return {
|
||||||
to: body.P_TO,
|
to: body.P_TO,
|
||||||
|
|||||||
@ -37,7 +37,7 @@ export class RolesGuard implements CanActivate {
|
|||||||
try {
|
try {
|
||||||
const decoded: any = jwt.decode(token);
|
const decoded: any = jwt.decode(token);
|
||||||
|
|
||||||
const roles: string[] = decoded?.resource_access?.['carnet-app']?.roles || [];
|
const roles: string[] = decoded?.resource_access?.[process.env.CLIENT_ID || '']?.roles || [];
|
||||||
const hasRole = requiredRoles.some(role => roles.includes(role));
|
const hasRole = requiredRoles.some(role => roles.includes(role));
|
||||||
|
|
||||||
if (!hasRole) {
|
if (!hasRole) {
|
||||||
|
|||||||
@ -20,7 +20,12 @@ async function bootstrap() {
|
|||||||
'http://localhost:5173',
|
'http://localhost:5173',
|
||||||
'https://policy.alphaomegainfosys.com',
|
'https://policy.alphaomegainfosys.com',
|
||||||
'https://sp.alphaomegainfosys.com',
|
'https://sp.alphaomegainfosys.com',
|
||||||
'https://client.alphaomegainfosys.com'
|
'https://policy-2.alphaomegainfosys.com',
|
||||||
|
'https://client-2.alphaomegainfosys.com',
|
||||||
|
'https://sp-2.alphaomegainfosys.com',
|
||||||
|
'https://policy-1.alphaomegainfosys.com',
|
||||||
|
'https://client-1.alphaomegainfosys.com',
|
||||||
|
'https://sp-1.alphaomegainfosys.com',
|
||||||
],
|
],
|
||||||
methods: 'GET,HEAD,PUT,PATCH,POST,DELETE',
|
methods: 'GET,HEAD,PUT,PATCH,POST,DELETE',
|
||||||
preflightContinue: false,
|
preflightContinue: false,
|
||||||
|
|||||||
@ -436,7 +436,7 @@ export class ManageClientsService {
|
|||||||
const pgArrayLiteral = `{${addressLiterals.join(',')}}`;
|
const pgArrayLiteral = `{${addressLiterals.join(',')}}`;
|
||||||
|
|
||||||
const callProcQuery = `
|
const callProcQuery = `
|
||||||
CALL "CARNETSYS".managepreparer_pkg_updateclientlocations($1, $2, $3::"CARNETSYS".addresstable[], $4, $5)
|
CALL "CARNETSYS".managepreparer_pkg_createclientlocation($1, $2, $3::"CARNETSYS".addresstable[], $4, $5)
|
||||||
`;
|
`;
|
||||||
await client.query(callProcQuery,
|
await client.query(callProcQuery,
|
||||||
[
|
[
|
||||||
@ -515,7 +515,7 @@ export class ManageClientsService {
|
|||||||
await client.query('BEGIN');
|
await client.query('BEGIN');
|
||||||
|
|
||||||
const callProcQuery = `
|
const callProcQuery = `
|
||||||
CALL "CARNETSYS".managepreparer_pkg_getpreparerlocbyclientid($1, $2, $3)
|
CALL "CARNETSYS".managepreparer_pkg_GetPreparerByClientid($1, $2, $3)
|
||||||
`;
|
`;
|
||||||
await client.query(callProcQuery, [body.P_SPID, body.P_CLIENTID, cursorName]);
|
await client.query(callProcQuery, [body.P_SPID, body.P_CLIENTID, cursorName]);
|
||||||
|
|
||||||
|
|||||||
@ -41,8 +41,8 @@ export class UserMaintenanceController {
|
|||||||
|
|
||||||
@Post('CreateUSCIBLogins')
|
@Post('CreateUSCIBLogins')
|
||||||
@Roles('pua')
|
@Roles('pua')
|
||||||
async CreateUSCIBLogins(@Body() body: CreateUSCIBLoginsDTO) {
|
async CreateUSCIBLogins(@Body() body: CreateUSCIBLoginsDTO, @Req() req: Request) {
|
||||||
return await this.userMaintenanceService.CreateUSCIBLogins(body);
|
return await this.userMaintenanceService.CreateUSCIBLogins(body, req);
|
||||||
}
|
}
|
||||||
|
|
||||||
// SP LOGINS
|
// SP LOGINS
|
||||||
|
|||||||
@ -162,7 +162,7 @@ export class UserMaintenanceService {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async CreateUSCIBLogins(body: CreateUSCIBLoginsDTO) {
|
async CreateUSCIBLogins(body: CreateUSCIBLoginsDTO, req: Request) {
|
||||||
|
|
||||||
let client: PoolClient | null = null;
|
let client: PoolClient | null = null;
|
||||||
|
|
||||||
@ -194,6 +194,20 @@ export class UserMaintenanceService {
|
|||||||
|
|
||||||
checkPgUserDefinedErrors(fetchResult);
|
checkPgUserDefinedErrors(fetchResult);
|
||||||
|
|
||||||
|
let appDomain;
|
||||||
|
if (req.headers.origin) {
|
||||||
|
appDomain = extractSubdomain(req.headers.origin)
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
appDomain = ""
|
||||||
|
}
|
||||||
|
|
||||||
|
const mailRes = await this.authService.sendMail({ P_TO: body.P_USERID, P_MAIL_TYPE: MailTypeDTO.REGISTER_USCIB }, appDomain)
|
||||||
|
|
||||||
|
if (mailRes.statusCode !== 200) {
|
||||||
|
throw new InternalServerException();
|
||||||
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
statusCode: 201,
|
statusCode: 201,
|
||||||
message: ResponseStatus.created,
|
message: ResponseStatus.created,
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user