UNPKG

@bitloops/bl-boilerplate-infra-nest-auth-passport

Version:
71 lines (70 loc) 3 kB
var __decorate = (this && this.__decorate) || function (decorators, target, key, desc) { var c = arguments.length, r = c < 3 ? target : desc === null ? desc = Object.getOwnPropertyDescriptor(target, key) : desc, d; if (typeof Reflect === "object" && typeof Reflect.decorate === "function") r = Reflect.decorate(decorators, target, key, desc); else for (var i = decorators.length - 1; i >= 0; i--) if (d = decorators[i]) r = (c < 3 ? d(r) : c > 3 ? d(target, key, r) : d(target, key)) || r; return c > 3 && r && Object.defineProperty(target, key, r), r; }; var __metadata = (this && this.__metadata) || function (k, v) { if (typeof Reflect === "object" && typeof Reflect.metadata === "function") return Reflect.metadata(k, v); }; var __param = (this && this.__param) || function (paramIndex, decorator) { return function (target, key) { decorator(target, key, paramIndex); } }; import { Injectable, Inject } from '@nestjs/common'; import { RpcException } from '@nestjs/microservices'; import * as jwt from 'jsonwebtoken'; import { JWTSecret } from '../constants'; let JwtGrpcAuthGuard = class JwtGrpcAuthGuard { jwtSecret; constructor(jwtSecret) { this.jwtSecret = jwtSecret; } canActivate(context) { const call = context.switchToRpc().getContext(); const metadata = call.internalRepr; const bearerToken = metadata.get('authorization')?.[0].replace('Bearer ', ''); if (!bearerToken) { throw new RpcException({ code: 3, message: 'Missing required JWT token', }); } try { const secret = this.jwtSecret; const payload = jwt.verify(bearerToken, secret); // if the token is an object and has the property exp, then it's a valid token if (payload === undefined) { throw new RpcException({ code: 3, message: 'JWT token is missing', }); } if (payload === undefined || typeof payload !== 'object' || !payload.hasOwnProperty('exp')) { throw new RpcException({ code: 3, message: 'JWT token is invalid', }); } const decoded = payload; // check if the token is expired if (decoded.exp && decoded.exp < Date.now() / 1000) { throw new RpcException({ code: 16, message: 'JWT token has expired', }); } call.decodedToken = decoded; call.jwt = bearerToken; return true; } catch (error) { throw new RpcException({ code: 3, message: 'Invalid JWT token' }); } } }; JwtGrpcAuthGuard = __decorate([ Injectable(), __param(0, Inject(JWTSecret)), __metadata("design:paramtypes", [String]) ], JwtGrpcAuthGuard); export { JwtGrpcAuthGuard };