39 lines
1.5 KiB
TypeScript
39 lines
1.5 KiB
TypeScript
import type { NextFunction, Request, Response } from 'express'
|
|||
|
|
import jwt, { type JwtPayload } from 'jsonwebtoken'
|
||
|
|
|
||
|
|
export type OsintClaims = JwtPayload & { role?: string; isAdmin?: boolean }
|
||
|
|
|
||
|
|
declare global {
|
||
|
|
namespace Express {
|
||
|
|
interface Request { authClaims?: OsintClaims }
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
export function authenticateJwt(req: Request, _res: Response, next: NextFunction) {
|
||
|
|
const authorization = req.headers.authorization
|
||
|
|
const token = req.cookies?.auth_token || (authorization?.startsWith('Bearer ') ? authorization.slice(7) : undefined)
|
||
|
|
const secret = process.env.JWT_SECRET
|
||
|
|
if (token && secret) {
|
||
|
|
try {
|
||
|
|
const decoded = jwt.verify(token, secret)
|
||
|
|
if (typeof decoded !== 'string') req.authClaims = decoded as OsintClaims
|
||
|
|
} catch { /* An absent, expired, or invalid cookie is an anonymous session. */ }
|
||
|
|
}
|
||
|
|
next()
|
||
|
|
}
|
||
|
|
|
||
|
|
export function hasAdminClaim(req: Request) {
|
||
|
|
return req.authClaims?.role === 'admin' || req.authClaims?.isAdmin === true
|
||
|
|
}
|
||
|
|
|
||
|
|
export function requireAdmin(req: Request, res: Response, next: NextFunction) {
|
||
|
|
if (!hasAdminClaim(req)) return res.status(403).json({ error: 'Administrator claim required' })
|
||
|
|
next()
|
||
|
|
}
|
||
|
|
|
||
|
|
export function createDevelopmentAdminToken() {
|
||
|
|
if (process.env.NODE_ENV === 'production') throw new Error('Development sessions are disabled in production')
|
||
|
|
if (!process.env.JWT_SECRET) throw new Error('JWT_SECRET is required')
|
||
|
|
return jwt.sign({ sub: 'osint-local-admin', role: 'admin', isAdmin: true }, process.env.JWT_SECRET, { expiresIn: '7d' })
|
||
|
|
}
|