* --init * -- * replace old structure with new DI * fix type * -- * moving stuff around * moving stuff around again * minor clean up * -- * resolve conflict * clea up * old schema clean up * further clean up * removing unwanted merged responsibilities * -- * improve DI and SOLID * some type fixes * --1 * clean up --cont * fix DI in facade for test * more fix * fix * checking * o.o * fix import * fix failing test --2 * fix failing test --3 * fix failing test --4 * normalization use * introduce facade container injection * uniform async telemetry spans * further improvements * replace prismock with repo mocks * ensure we don't pass prisma outside of repo * fix import * remove try catch from repo calls * async await fixes * using deps pattern * more clean up and fixes * more clean up * address feedback --1 * separation of concern * clean up * test clean up * feedback --2 * remove extra fetch * remove await * migrate _post test from prismock * fix type * -- * fix tokens path * rename AuditRepo * test --1 * update _post to integration test * fix test * fix test * test fix maybe? * -- * feedback * feedback * fixes * more feedback * NIT * use sentry and logger imports as planned * assertion in test * add missing test case * add tests for controllers and services * NITs * fix domain normalisation
48 lines
1.1 KiB
TypeScript
48 lines
1.1 KiB
TypeScript
import type { PrismaApiKeyRepository } from "../repository/PrismaApiKeyRepository";
|
|
|
|
type Deps = {
|
|
apiKeyRepo: PrismaApiKeyRepository;
|
|
};
|
|
|
|
interface VerifyKeyResult {
|
|
valid: boolean;
|
|
error?: string;
|
|
userId?: number;
|
|
user?: {
|
|
role: string;
|
|
locked: boolean;
|
|
email: string;
|
|
};
|
|
}
|
|
|
|
export class ApiKeyService {
|
|
constructor(private readonly deps: Deps) {}
|
|
|
|
async verifyKeyByHashedKey(hashedKey: string): Promise<VerifyKeyResult> {
|
|
const apiKey = await this.deps.apiKeyRepo.findByHashedKey(hashedKey);
|
|
|
|
if (!apiKey) {
|
|
return { valid: false, error: "Your API key is not valid." };
|
|
}
|
|
|
|
if (apiKey.expiresAt && this.isExpired(apiKey.expiresAt)) {
|
|
return { valid: false, error: "This API key is expired." };
|
|
}
|
|
|
|
if (!apiKey.userId || !apiKey.user) {
|
|
return { valid: false, error: "No user found for this API key." };
|
|
}
|
|
|
|
return {
|
|
valid: true,
|
|
userId: apiKey.userId,
|
|
user: apiKey.user,
|
|
};
|
|
}
|
|
|
|
private isExpired(expiresAt: Date): boolean {
|
|
const now = new Date();
|
|
return now.setHours(0, 0, 0, 0) > expiresAt.setHours(0, 0, 0, 0);
|
|
}
|
|
}
|