Cantilever-Labs/controllers/auth.js

558 lines
43 KiB
JavaScript
Raw Normal View History

2021-05-09 04:31:53 -07:00
const bcrypt = require("bcryptjs");
const User = require("../models/User");
const Student = require("../models/Student");
const jwt = require("jsonwebtoken");
2021-04-01 06:38:27 -07:00
const JWT_secret = "Cantileverlabs";
const messagebird = require("messagebird")("llVKD53ve6QRpbCKOHzWBADaS", null, [
"ENABLE_CONVERSATIONSAPI_WHATSAPP_SANDBOX",
]);
2021-05-12 03:44:03 -07:00
const nodemailer = require("nodemailer");
const smtpTransport = require("nodemailer-smtp-transport");
2021-05-26 03:05:16 -07:00
// const { OAuth2Client } = require("google-auth-library");
// const client = new OAuth2Client(
// "7810129519-dr5l4l1i7a7bh07sbvl49gd80coenphj.apps.googleusercontent.com"
// );
// -------------------------------------------- mail transporter -----------------------------------------
var transport = nodemailer.createTransport(
smtpTransport({
2021-05-19 00:04:12 -07:00
host: `${process.env.HOST}`, //`${process.env.HOST}`
port: 465,
auth: {
2021-05-19 00:04:12 -07:00
user: `${process.env.EMAIL}`, //`${process.env.EMAIL}`
pass: `${process.env.PASS}`, //`${process.env.PASS}`
},
})
);
// -------------------------------------------- mail transporter -----------------------------------------
2021-03-26 06:29:27 -07:00
2021-05-09 04:31:53 -07:00
module.exports.Protected = async (req, res, next) => {
res.send("Hello User");
};
module.exports.postSignup = async (req, res, next) => {
try {
//we need firstName , lastName , email , password as input
let firstName = req.body.firstName || " ";
let lastName = req.body.lastName || " ";
2021-05-17 02:06:05 -07:00
const { sending_company_email, email, password, subject } = req.body;
2021-05-09 04:31:53 -07:00
let user = await User.findOne({ email: email });
if (user) {
res.json({
message: "User already exist",
type: "error",
});
} else {
const email_otp = Math.floor(100000 + Math.random() * 900000);
console.log("otp", email_otp);
2021-05-09 04:31:53 -07:00
const hashedPass = await bcrypt.hash(password, 12);
user = new User({
firstName: firstName,
lastName: lastName,
email: email,
password: hashedPass,
isAdmin: false,
2021-05-28 00:46:05 -07:00
email_otp,
2021-05-09 04:31:53 -07:00
});
user = await user.save();
await Student.deleteOne({ user: user._id });
let student = new Student({
user: user._id,
});
student = await student.save();
user.student = student._id;
await user.save();
2021-05-28 00:46:05 -07:00
const message = {
from: `${sending_company_email}`, // Sender address
to: `${email}`, // List of recipients
subject: `${subject}`, // Subject line
html: `
<!doctype html>
<html lang="en-US">
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type" />
<title>Verify Email Template</title>
<meta name="description" content="Reset Password Email Template.">
<style type="text/css">
a:hover {text-decoration: underline !important;}
</style>
</head>
<body marginheight="0" topmargin="0" marginwidth="0" style="margin: 0px; background-color: #f2f3f8;" leftmargin="0">
<!--100% body table-->
<table cellspacing="0" border="0" cellpadding="0" width="100%" bgcolor="#f2f3f8"
style="@import url(https://fonts.googleapis.com/css?family=Rubik:300,400,500,700|Open+Sans:300,400,600,700); font-family: 'Open Sans', sans-serif;">
<tr>
<td>
<table style="background-color: #f2f3f8; max-width:670px; margin:0 auto;" width="100%" border="0"
align="center" cellpadding="0" cellspacing="0">
<tr>
<td style="height:80px;">&nbsp;</td>
</tr>
<tr>
<td style="text-align:center;">
</td>
</tr>
<tr>
<td style="height:20px;">&nbsp;</td>
</tr>
<tr>
<td>
<table width="95%" border="0" align="center" cellpadding="0" cellspacing="0"
style="max-width:670px;background:#fff; border-radius:3px; text-align:center;-webkit-box-shadow:0 6px 18px 0 rgba(0,0,0,.06);-moz-box-shadow:0 6px 18px 0 rgba(0,0,0,.06);box-shadow:0 6px 18px 0 rgba(0,0,0,.06);">
<tr>
<td style="height:40px;">&nbsp;</td>
</tr>
<tr>
<td style="padding:0 35px;">
<a href="https://cantileverlabs.com" title="logo" target="_blank">
<img width="80" height="80"
src="https://media-exp1.licdn.com/dms/image/C510BAQEgcV3sgE1PIA/company-logo_200_200/0/1552289011007?e=2159024400&v=beta&t=FO8loLVwC5qoHmYkk-gR-mv7vC36LPG17yZkxOFl6Go" style="margin:40px" title="logo" alt="logo">
</a> <h1 style="color:#1e1e2d; font-weight:500; margin:0;font-size:32px;font-family:'Rubik',sans-serif;">Your OTP to verify
the Email.</h1>
<span
style="display:inline-block; vertical-align:middle; margin:29px 0 26px; border-bottom:1px solid #cecece; width:100px;"></span>
<p style="color:#455056; font-size:15px;line-height:24px; margin:0;">
<br><strong>OTP: ${email_otp} </strong><br>Please Navigate to Website to Verify OTP.
</p>
<p style="color:#455056; margin:"30px";font-size:15px;line-height:24px; margin:0;">
Facing any issue? Write us at
<p style="color:#455056; font-size:15px;line-height:24px; margin:0;"><a href="mailto:info@cantileverlabs.com">info@cantileverlabs.com</a></P>
<img width="300" height="80"
src="
title="logo" alt="logo">
<p style="color:#455056; font-size:15px;line-height:24px; margin:0;">
<a href="https://www.cantileverlabs.com/policies#privacy" style="text-decoration:none;border-right:1px solid;padding-right:10px">Privacy Policy</a>
<a href="https://www.cantileverlabs.com/policies#privacy" style="text-decoration:none ; border-right:1px solid;padding-right:10px;margin-left:5px">Terms Of Use</a>
<a href="mailto:infi@cantileverlabs.com" style="text-decoration:none ;margin-left:5px">Contact Us</a>
</p>
</p>
</td>
</tr>
<tr>
<td style="height:40px;">&nbsp;</td>
</tr>
</table>
</td>
<tr>
<td style="height:20px;">&nbsp;</td>
</tr>
<tr>
<td style="text-align:center;">
<div class="reset-logo2-J ">
<img src="./images/Icon material-copyright.png" alt="">
<span class="light-copyright-J">copyright <span class="bold-copyright-J">2018 Cantilever Labs</span></span>
</div>
</td>
</tr>
<tr>
<td style="height:80px;">&nbsp;</td>
</tr>
</table>
</td>
</tr>
</table>
<!--/100% body table-->
</body>
</html>`, // design html for email message.
};
transport.sendMail(message, function (err, info) {
if (err) {
console.log(err);
} else {
console.log(info);
}
});
2021-05-09 04:31:53 -07:00
res.json({
2021-05-28 00:46:05 -07:00
message: "Email with 6 Digit OTP has been sent.",
2021-05-09 04:31:53 -07:00
type: "success",
});
2021-03-26 06:29:27 -07:00
}
2021-05-09 04:31:53 -07:00
} catch (err) {
console.log(err);
}
};
2021-03-26 06:29:27 -07:00
module.exports.verfiyemail = async (req, res, next) => {
const { email, otp } = req.body;
try {
let user = await User.findOne({ email: email });
if (user) {
const isMatched = await (user.email_otp == otp ? true : false);
if (isMatched) {
if (!user.isVerified) {
user.isVerified = true;
await user.save();
res.json({
message: "User Verified, Please Login",
});
} else {
res.json({
message: "User Already Verified, Please Login",
});
}
} else {
res.json({
message: "OTP Doesn't Matched!",
type: "error",
});
}
} else {
res.json({
message: "No user with this email exists",
type: "error",
});
}
} catch {
(err) => {
console.log(err);
};
}
};
2021-05-09 04:31:53 -07:00
module.exports.postSignin = async (req, res, next) => {
try {
//we need email and password as input
2021-05-29 02:12:02 -07:00
let { email, password, isGoogle } = req.body;
2021-05-29 05:36:18 -07:00
console.log("req.body", req.body);
let user = await User.findOne({ email });
2021-05-29 02:12:02 -07:00
if (isGoogle) {
2021-05-31 00:43:31 -07:00
if (user) {
user.isVerified = true;
user = await user.save();
const isMatched = await bcrypt.compare(password, user.password);
if (isMatched) {
const token = jwt.sign({ _id: user._id }, JWT_secret);
res.json({
token: token,
});
} else {
res.json({
message: "email and password doesn't match",
type: "error",
});
return;
}
2021-05-29 02:12:02 -07:00
} else {
res.json({
2021-05-31 00:43:31 -07:00
message: "User Doesn't Exists",
2021-05-29 02:12:02 -07:00
type: "error",
});
return;
}
} else {
if (user) {
if (user.isVerified) {
const isMatched = await bcrypt.compare(password, user.password);
if (isMatched) {
const token = jwt.sign({ _id: user._id }, JWT_secret);
res.json({
token: token,
});
} else {
res.json({
message: "email and password doesn't match",
type: "error",
});
return;
}
2021-05-28 00:46:05 -07:00
} else {
2021-05-29 02:12:02 -07:00
res.status(403).json({
message: "User Not Verified!",
2021-05-28 00:46:05 -07:00
type: "error",
});
return;
}
2021-05-09 04:31:53 -07:00
} else {
2021-05-29 02:12:02 -07:00
res.status(201).json({
message: "No user with this email exists",
2021-05-09 04:31:53 -07:00
type: "error",
});
2021-05-28 00:46:05 -07:00
return;
2021-05-09 04:31:53 -07:00
}
}
} catch (err) {
console.log(err);
}
};
2021-05-26 03:05:16 -07:00
// Gmail Login Starts.
// -----------------------------------------------------------------------------------------------
//1026548376782-5p5tjck8ffhan9l1ajhv6orr87dfkrrf.apps.googleusercontent.com
// module.exports.googleSignIn = async (req, res, next) => {
// const { tokenId } = req.params;
// console.log("TokenId from frontend", tokenId);
// client
// .verifyIdToken({
// idToken: tokenId,
// audience:
// "7810129519-dr5l4l1i7a7bh07sbvl49gd80coenphj.apps.googleusercontent.com",
// })
// .then((response) => {
// console.log(response.payload);
// });
// };
2021-03-26 06:29:27 -07:00
2021-05-12 04:00:38 -07:00
// Phone verification Starts.
// -----------------------------------------------------------------------------------------------
2021-05-29 05:36:18 -07:00
module.exports.sendOTP = (req, res, next) => {
2021-05-09 04:31:53 -07:00
//uNNYosMopvvCW9RTR1tRWJmYC test
//llVKD53ve6QRpbCKOHzWBADaS live
2021-05-29 05:36:18 -07:00
const { phoneNumber } = req.body;
2021-05-09 04:31:53 -07:00
try {
2021-05-29 05:36:18 -07:00
if (!phoneNumber) {
res.status(422).json({ message: "Please Add All Required Fields" });
2021-05-29 02:12:02 -07:00
return;
2021-05-29 05:36:18 -07:00
} else {
messagebird.verify.create(
phoneNumber,
{
template: "Your verification code is %token",
},
function (err, response) {
if (err) {
console.log(err);
res.status(422).json({ message: err.errors[0].description });
} else {
console.log(response);
res.json({ id: response.id });
}
}
);
2021-03-26 06:29:27 -07:00
}
2021-05-09 04:31:53 -07:00
} catch (err) {
console.log(err);
}
};
module.exports.getOTP = (req, res, next) => {
try {
2021-05-12 04:00:38 -07:00
const { id, otp } = req.body;
messagebird.verify.verify(id, otp, function (err, response) {
2021-05-09 04:31:53 -07:00
if (err) {
console.log({ error: err.errors[0].description, id: id });
res.json({ error: err.errors[0].description, id: id });
} else {
console.log(response);
res.json({ message: "Code Verified" });
}
});
} catch (err) {
console.log(err);
}
};
2021-05-12 04:00:38 -07:00
// Phone verification End.
// -----------------------------------------------------------------------------------------------
// -----------------------------------------------------------------------------------------------
// Forgot password Starts
2021-05-12 04:00:38 -07:00
2021-05-11 07:25:34 -07:00
module.exports.forgotpassword = async (req, res, next) => {
const { email, link, sending_company_email, subject } = req.body;
2021-05-12 04:00:38 -07:00
//link = https://cantileverlabs.herokuapp.com/resetpassword/:id/:token
2021-05-12 02:16:11 -07:00
try {
await User.findOne({ email }).then((user) => {
if (!user) {
2021-05-11 07:25:34 -07:00
res.status(404).json({ error: "User not found with this Email" });
return;
} else {
const payload = {
2021-05-12 02:16:11 -07:00
email: user.email,
_id: user._id,
2021-05-11 07:25:34 -07:00
};
2021-05-12 02:16:11 -07:00
const secret = JWT_secret + user.password;
2021-05-11 07:25:34 -07:00
const token = jwt.sign(payload, secret, { expiresIn: "10m" });
2021-05-12 02:16:11 -07:00
User.findByIdAndUpdate(user._id, {
$set: { passwordResetToken: token },
})
.then((data) => {
const reset_link = `${link}/${user._id}/${token}`;
2021-05-12 03:44:03 -07:00
const message = {
from: `${sending_company_email}`, // Sender address
to: `${user.email}`, // List of recipients
subject: `${subject}`, // Subject line
2021-05-16 22:45:42 -07:00
html: `
<!doctype html>
<html lang="en-US">
2021-05-16 22:45:42 -07:00
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type" />
<title>Reset Password Email Template</title>
<meta name="description" content="Reset Password Email Template.">
<style type="text/css">
a:hover {text-decoration: underline !important;}
</style>
2021-05-16 22:45:42 -07:00
</head>
2021-05-16 22:45:42 -07:00
<body marginheight="0" topmargin="0" marginwidth="0" style="margin: 0px; background-color: #f2f3f8;" leftmargin="0">
<!--100% body table-->
<table cellspacing="0" border="0" cellpadding="0" width="100%" bgcolor="#f2f3f8"
style="@import url(https://fonts.googleapis.com/css?family=Rubik:300,400,500,700|Open+Sans:300,400,600,700); font-family: 'Open Sans', sans-serif;">
<tr>
<td>
<table style="background-color: #f2f3f8; max-width:670px; margin:0 auto;" width="100%" border="0"
align="center" cellpadding="0" cellspacing="0">
<tr>
<td style="height:80px;">&nbsp;</td>
</tr>
<tr>
<td style="text-align:center;">
2021-05-17 02:41:13 -07:00
2021-05-16 22:45:42 -07:00
</td>
</tr>
<tr>
<td style="height:20px;">&nbsp;</td>
</tr>
<tr>
<td>
<table width="95%" border="0" align="center" cellpadding="0" cellspacing="0"
style="max-width:670px;background:#fff; border-radius:3px; text-align:center;-webkit-box-shadow:0 6px 18px 0 rgba(0,0,0,.06);-moz-box-shadow:0 6px 18px 0 rgba(0,0,0,.06);box-shadow:0 6px 18px 0 rgba(0,0,0,.06);">
<tr>
<td style="height:40px;">&nbsp;</td>
</tr>
<tr>
<td style="padding:0 35px;">
2021-05-17 02:41:13 -07:00
<a href="https://cantileverlabs.com" title="logo" target="_blank">
<img width="80" height="80"
src="https://media-exp1.licdn.com/dms/image/C510BAQEgcV3sgE1PIA/company-logo_200_200/0/1552289011007?e=2159024400&v=beta&t=FO8loLVwC5qoHmYkk-gR-mv7vC36LPG17yZkxOFl6Go" style="margin:40px" title="logo" alt="logo">
</a> <h1 style="color:#1e1e2d; font-weight:500; margin:0;font-size:32px;font-family:'Rubik',sans-serif;">You have
2021-05-16 22:45:42 -07:00
requested to reset your password</h1>
<span
style="display:inline-block; vertical-align:middle; margin:29px 0 26px; border-bottom:1px solid #cecece; width:100px;"></span>
<p style="color:#455056; font-size:15px;line-height:24px; margin:0;">
We cannot simply send you your old password. A unique link to reset your
password has been generated for you. To reset your password, click the
following link and follow the instructions.
</p>
<a href=${reset_link}
2021-05-17 02:41:13 -07:00
style="background:#ffc600;text-decoration:none !important; font-weight:500; margin-top:35px; color:#111;text-transform:uppercase; font-size:14px;padding:10px 24px;display:inline-block;border-radius:50px;">Reset
2021-05-16 22:45:42 -07:00
Password</a>
2021-05-17 02:41:13 -07:00
<p style="color:#455056; margin:"30px";font-size:15px;line-height:24px; margin:0;">
Facing any issue? Write us at
<p style="color:#455056; font-size:15px;line-height:24px; margin:0;"><a href="mailto:info@cantileverlabs.com">info@cantileverlabs.com</a></P>
<img width="300" height="80"
2021-05-18 23:52:26 -07:00
src="
title="logo" alt="logo">
2021-05-19 00:00:55 -07:00
2021-05-17 02:41:13 -07:00
<p style="color:#455056; font-size:15px;line-height:24px; margin:0;">
<a href="https://www.cantileverlabs.com/policies#privacy" style="text-decoration:none;border-right:1px solid;padding-right:10px">Privacy Policy</a>
<a href="https://www.cantileverlabs.com/policies#privacy" style="text-decoration:none ; border-right:1px solid;padding-right:10px;margin-left:5px">Terms Of Use</a>
<a href="mailto:infi@cantileverlabs.com" style="text-decoration:none ;margin-left:5px">Contact Us</a>
</p>
</p>
2021-05-16 22:45:42 -07:00
</td>
</tr>
<tr>
<td style="height:40px;">&nbsp;</td>
</tr>
</table>
</td>
<tr>
<td style="height:20px;">&nbsp;</td>
</tr>
<tr>
<td style="text-align:center;">
<div class="reset-logo2-J ">
<img src="./images/Icon material-copyright.png" alt="">
<span class="light-copyright-J">copyright <span class="bold-copyright-J">2018 Cantilever Labs</span></span>
</div>
</td>
</tr>
2021-05-17 02:41:13 -07:00
2021-05-16 22:45:42 -07:00
<tr>
<td style="height:80px;">&nbsp;</td>
</tr>
</table>
</td>
</tr>
</table>
<!--/100% body table-->
</body>
</html>
`, // design html for email message.
2021-05-12 03:44:03 -07:00
};
transport.sendMail(message, function (err, info) {
if (err) {
console.log(err);
} else {
console.log(info);
}
});
2021-05-12 02:16:11 -07:00
res.status(200).json({
message: "Link is Active for 10 mins",
2021-05-12 02:16:11 -07:00
reset_link,
});
})
.catch((err) => {
console.log(err);
});
2021-05-11 07:25:34 -07:00
}
});
2021-05-12 02:16:11 -07:00
} catch {
(error) => {
console.log("Error from forgot pass", error);
};
}
2021-05-11 07:25:34 -07:00
};
module.exports.resetpassword = async (req, res, next) => {
const { _id, token } = req.params;
const { password } = req.body;
2021-05-12 02:16:11 -07:00
try {
let user = await User.findById({ _id });
if (!user) {
res.json({ error: "User not Found or WrongId" });
return;
} else {
const secret = JWT_secret + user.password;
const user_token = user.passwordResetToken;
2021-05-11 07:25:34 -07:00
const payload = jwt.verify(token, secret);
2021-05-12 02:16:11 -07:00
const hashedPass = await bcrypt.hash(password, 12);
2021-05-11 07:25:34 -07:00
if (token == user_token) {
2021-05-12 02:16:11 -07:00
user.password = hashedPass;
await user
.save()
.then((ok) => {
2021-05-18 23:52:26 -07:00
res.header("Access-Control-Allow-Origin", "*");
res.header("Access-Control-Allow-Headers", "*");
2021-05-11 07:25:34 -07:00
res.json({ message: "Password Updated!" });
})
.catch((err) => {
2021-05-12 02:16:11 -07:00
console.log("Error in save", err);
2021-05-11 07:25:34 -07:00
});
} else {
2021-05-12 02:16:11 -07:00
res.status(422).json({ error: "Either Token not found or Expired!" });
return;
2021-05-11 07:25:34 -07:00
}
}
2021-05-12 02:16:11 -07:00
} catch {
(err) => {
console.log("error from try catch resetpass", err);
};
}
2021-05-11 07:25:34 -07:00
};
2021-04-01 06:38:27 -07:00
// Forgot password Ends
2021-05-19 00:02:30 -07:00
2021-05-12 04:48:25 -07:00
// Email verification Ends
2021-05-19 00:02:30 -07:00
2021-05-12 04:00:38 -07:00
// -----------------------------------------------------------------------------------------------
2021-05-09 04:31:53 -07:00
module.exports.checkProtected = (req, res, next) => {
console.log(req.user);
res.json({
message: "Protected",
user: req.user,
});
};