diff --git a/app/Controllers/Http/Api/v1/AuthController.ts b/app/Controllers/Http/Api/v1/AuthController.ts index bbab909..830a65e 100644 --- a/app/Controllers/Http/Api/v1/AuthController.ts +++ b/app/Controllers/Http/Api/v1/AuthController.ts @@ -28,7 +28,7 @@ export default class AuthController extends BaseController { public async login(ctx: HttpContextContract) { const payload = await ctx.request.validate(AuthValidator); - const result = await this.authService.login(payload.login, payload.password, ctx.auth); + const result = await this.authService.login(payload.login, payload.password, ctx); if (!result.success && result.error) { throw new Exception(result.message, result.status, result.error.code); @@ -43,7 +43,7 @@ export default class AuthController extends BaseController { */ public async logout(ctx: HttpContextContract) { - const result = await this.authService.logout(ctx.auth); + const result = await this.authService.logout(ctx); if (!result.success && result.error) { throw new Exception(result.message, result.status, result.error.code); diff --git a/app/Middleware/Auth.ts b/app/Middleware/Auth.ts index 76f00a8..14f7874 100644 --- a/app/Middleware/Auth.ts +++ b/app/Middleware/Auth.ts @@ -52,13 +52,21 @@ export default class AuthMiddleware { ); } - public async handle({ auth }: HttpContextContract, next: () => Promise, customGuards: (keyof GuardsList)[]) { + public async handle(ctx: HttpContextContract, next: () => Promise, customGuards: (keyof GuardsList)[]) { + /** + * Verify token from cookie and set the authorization header + */ + const token = ctx.request.cookie('token'); + if (token) { + ctx.request.headers().authorization = `Bearer ${token}`; + } + /** * Uses the user defined guards or the default guard mentioned in * the config file */ - const guards = customGuards.length ? customGuards : [auth.name]; - await this.authenticate(auth, guards); + const guards = customGuards.length ? customGuards : [ctx.auth.name]; + await this.authenticate(ctx.auth, guards); await next(); } } diff --git a/app/Services/AuthService.ts b/app/Services/AuthService.ts index 19d505b..57ec251 100644 --- a/app/Services/AuthService.ts +++ b/app/Services/AuthService.ts @@ -1,11 +1,11 @@ import { inject, Ioc } from '@adonisjs/core/build/standalone'; +import { HttpContextContract } from '@ioc:Adonis/Core/HttpContext'; import Hash from '@ioc:Adonis/Core/Hash'; import Logger from '@ioc:Adonis/Core/Logger'; /** * Interfaces */ -import { AuthContract } from '@ioc:Adonis/Addons/Auth'; import IResponse from 'App/Datatypes/Interfaces/IResponse'; /** @@ -33,10 +33,10 @@ export default class AuthService { * * @param login Login * @param password Password - * @param auth AuthContact + * @param ctx Http context * @returns Token data */ - public async login(login: string, password: string, auth: AuthContract): Promise { + public async login(login: string, password: string, ctx: HttpContextContract): Promise { const user = await this.userRepository.getByColumn('login', login); if (!user) { @@ -69,11 +69,13 @@ export default class AuthService { /** * Create new token */ - const token = await auth.use(this.authGuard).generate(user, { + const token = await ctx.auth.use(this.authGuard).generate(user, { expiresIn: '1d', userRoles: user.roles.map(role => role.slug), }); + ctx.response.cookie('token', token.token); + Logger.info(`A token for user with id: "${token.user.id}" was successfully generated.`); return { @@ -87,11 +89,12 @@ export default class AuthService { /** * Logout user * - * @param auth AuthContract + * @param ctx Http context * @returns Logout message */ - public async logout(auth: AuthContract): Promise { - await auth.use(this.authGuard).revoke(); + public async logout(ctx: HttpContextContract): Promise { + ctx.response.clearCookie('token'); + await ctx.auth.use(this.authGuard).revoke(); return { success: true,