change password method in user controller

This commit is contained in:
Sergey Yarkov 2021-07-25 17:49:14 +03:00
parent fe6d4a3593
commit 49d6fe40ae
5 changed files with 73 additions and 6 deletions

View File

@ -24,7 +24,7 @@ export default class AuthController {
const user = await this.user.query().preload('roles').where('login', login).firstOrFail();
if (!(await Hash.verify(user.password, password))) {
throw new Exception('Invalid credentials.', 401, 'E_INVALID_CREDENTIALS');
throw new Exception('Invalid credentials.', 403, 'E_INVALID_CREDENTIALS');
}
const token = await auth.use(this.guard).generate(user, {

View File

@ -1,10 +1,17 @@
import { AuthenticationException } from '@adonisjs/auth/build/standalone';
import { Exception } from '@adonisjs/core/build/standalone';
import { HttpContextContract } from '@ioc:Adonis/Core/HttpContext';
import Hash from '@ioc:Adonis/Core/Hash';
import Logger from '@ioc:Adonis/Core/Logger';
/* Models */
import Contact from 'App/Models/Contact';
import Role from 'App/Models/Role';
import User from 'App/Models/User';
/* Validators */
import AddRoleToUserValidator from 'App/Validators/AddRoleToUserValidator';
import ChangePasswordValidator from 'App/Validators/ChangePasswordValidator';
import CreateUserValidator from 'App/Validators/CreateUserValidator';
import DelRoleFromUserValidator from 'App/Validators/DelRoleFromUserValidator';
import UpdateUserValidator from 'App/Validators/UpdateUserValidator';
@ -187,6 +194,50 @@ export default class UsersController {
});
}
/**
* Change password of authenticated user
* PATCH /users/me/password
*/
public async changePassword({ request, response, auth }: HttpContextContract) {
await request.validate(ChangePasswordValidator);
const userId = auth.use('api').token?.userId;
if (userId) {
const user = await this.user.findOrFail(userId);
const oldPassword: string = request.input('oldPassword');
const newPassword: string = request.input('newPassword');
if (oldPassword === newPassword) {
throw new Exception('The new password is the same as the old one.', 400, 'E_PASSWORD_VALUES');
}
/**
* Verify old password
*/
if (!(await Hash.verify(user.password, oldPassword))) {
throw new Exception('Invalid credentials.', 403, 'E_INVALID_CREDENTIALS');
}
/**
* Update user password
*/
user.password = newPassword;
await user.save();
Logger.info(`Password of user with id: "${user.id}" was updated.`);
return response.ok({
message: 'The password was successfully changed to the new value.',
});
}
/**
* Unauthorized user
*/
throw new AuthenticationException('Unauthorized access', 'E_UNAUTHORIZED_ACCESS', 'api');
}
/**
* Finds roles by input value and throw error if role does not exist.
*

View File

@ -0,0 +1,13 @@
import { schema, rules } from '@ioc:Adonis/Core/Validator';
import { HttpContextContract } from '@ioc:Adonis/Core/HttpContext';
export default class ChangePasswordValidator {
constructor(protected ctx: HttpContextContract) {}
public schema = schema.create({
oldPassword: schema.string(),
newPassword: schema.string({}, [rules.minLength(6), rules.maxLength(128)]),
});
public messages = {};
}

View File

@ -26,12 +26,9 @@ export default class CreateUserValidator {
public schema = schema.create({
first_name: schema.string(),
last_name: schema.string(),
login: schema.string({}, [
rules.maxLength(128),
rules.unique({ table: 'users', column: 'login' }),
]),
login: schema.string({}, [rules.maxLength(128), rules.unique({ table: 'users', column: 'login' })]),
email: schema.string({}, [rules.email(), rules.unique({ table: 'contacts', column: 'email' })]),
password: schema.string(),
password: schema.string({}, [rules.minLength(6), rules.maxLength(128)]),
});
/**

View File

@ -40,6 +40,12 @@ Route.group(() => {
Route.post('users/:id/attach-roles', 'UsersController.attachRoles').middleware('role:admin').as('attachUserRole');
Route.delete('users/:id/detach-roles', 'UsersController.detachRoles').middleware('role:admin').as('detachUserRole');
Route.get('users/me', 'UsersController.showMe').middleware('role:admin,teacher,student').as('showMe');
Route.patch('users/me/password', 'UsersController.changePassword')
.middleware('role:admin,teacher,student')
.as('changePassword');
Route.patch('users/me/contacts', 'UsersController.updateContacts')
.middleware('role:admin,teacher,student')
.as('updateContacts');
}).middleware('auth');
})
.prefix('/api/v1')