@nestjs/jwt
Version:
Nest - modern, fast, powerful node.js web framework (@jwt)
120 lines (119 loc) • 5.81 kB
JavaScript
var __decorate = (this && this.__decorate) || function (decorators, target, key, desc) {
var c = arguments.length, r = c < 3 ? target : desc === null ? desc = Object.getOwnPropertyDescriptor(target, key) : desc, d;
if (typeof Reflect === "object" && typeof Reflect.decorate === "function") r = Reflect.decorate(decorators, target, key, desc);
else for (var i = decorators.length - 1; i >= 0; i--) if (d = decorators[i]) r = (c < 3 ? d(r) : c > 3 ? d(target, key, r) : d(target, key)) || r;
return c > 3 && r && Object.defineProperty(target, key, r), r;
};
var __metadata = (this && this.__metadata) || function (k, v) {
if (typeof Reflect === "object" && typeof Reflect.metadata === "function") return Reflect.metadata(k, v);
};
var __param = (this && this.__param) || function (paramIndex, decorator) {
return function (target, key) { decorator(target, key, paramIndex); }
};
import { Inject, Injectable, Logger, Optional } from '@nestjs/common';
import jsonwebtoken from 'jsonwebtoken';
import { JwtSecretRequestType } from './interfaces/index.js';
import { JWT_MODULE_OPTIONS } from './jwt.constants.js';
import { WrongSecretProviderError } from './jwt.errors.js';
let JwtService = class JwtService {
constructor(options = {}) {
this.options = options;
this.logger = new Logger('JwtService');
}
sign(payload, options) {
const signOptions = this.mergeJwtOptions({ ...options }, 'signOptions');
const secret = this.getSecretKey(payload, options, 'privateKey', JwtSecretRequestType.SIGN);
if (secret instanceof Promise) {
secret.catch(() => { });
this.logger.warn('For async version of "secretOrKeyProvider", please use "signAsync".');
throw new WrongSecretProviderError();
}
const allowedSignOptKeys = ['secret', 'privateKey'];
const signOptKeys = Object.keys(signOptions);
if (typeof payload === 'string' &&
signOptKeys.some((k) => !allowedSignOptKeys.includes(k))) {
throw new Error('Payload as string is not allowed with the following sign options: ' +
signOptKeys.join(', '));
}
return jsonwebtoken.sign(payload, secret, signOptions);
}
signAsync(payload, options) {
const signOptions = this.mergeJwtOptions({ ...options }, 'signOptions');
const secret = this.getSecretKey(payload, options, 'privateKey', JwtSecretRequestType.SIGN);
const allowedSignOptKeys = ['secret', 'privateKey'];
const signOptKeys = Object.keys(signOptions);
if (typeof payload === 'string' &&
signOptKeys.some((k) => !allowedSignOptKeys.includes(k))) {
throw new Error('Payload as string is not allowed with the following sign options: ' +
signOptKeys.join(', '));
}
return new Promise((resolve, reject) => Promise.resolve()
.then(() => secret)
.then((scrt) => {
jsonwebtoken.sign(payload, scrt, signOptions, (err, encoded) => err ? reject(err) : resolve(encoded));
}));
}
verify(token, options) {
const verifyOptions = this.mergeJwtOptions({ ...options }, 'verifyOptions');
const secret = this.getSecretKey(token, options, 'publicKey', JwtSecretRequestType.VERIFY);
if (secret instanceof Promise) {
secret.catch(() => { });
this.logger.warn('For async version of "secretOrKeyProvider", please use "verifyAsync".');
throw new WrongSecretProviderError();
}
return jsonwebtoken.verify(token, secret, verifyOptions);
}
verifyAsync(token, options) {
const verifyOptions = this.mergeJwtOptions({ ...options }, 'verifyOptions');
const secret = this.getSecretKey(token, options, 'publicKey', JwtSecretRequestType.VERIFY);
return new Promise((resolve, reject) => Promise.resolve()
.then(() => secret)
.then((scrt) => {
jsonwebtoken.verify(token, scrt, verifyOptions, (err, decoded) => (err ? reject(err) : resolve(decoded)));
})
.catch(reject));
}
decode(token, options) {
return jsonwebtoken.decode(token, options);
}
mergeJwtOptions(options, key) {
delete options.secret;
if (key === 'signOptions') {
delete options.privateKey;
}
else {
delete options.publicKey;
}
return options
? { ...(this.options[key] || {}), ...options }
: this.options[key];
}
overrideSecretFromOptions(secret) {
if (this.options.secretOrPrivateKey) {
this.logger.warn(`"secretOrPrivateKey" has been deprecated, please use the new explicit "secret" or use "secretOrKeyProvider" or "privateKey"/"publicKey" exclusively.`);
secret = this.options.secretOrPrivateKey;
}
return secret;
}
getSecretKey(token, options, key, secretRequestType) {
const secret = this.options.secretOrKeyProvider
? this.options.secretOrKeyProvider(secretRequestType, token, options)
: options?.secret ||
this.options.secret ||
(key === 'privateKey'
? options?.privateKey || this.options.privateKey
: options?.publicKey ||
this.options.publicKey) ||
this.options[key];
return secret instanceof Promise
? secret.then((sec) => this.overrideSecretFromOptions(sec))
: this.overrideSecretFromOptions(secret);
}
};
JwtService = __decorate([
Injectable(),
__param(0, Optional()),
__param(0, Inject(JWT_MODULE_OPTIONS)),
__metadata("design:paramtypes", [Object])
], JwtService);
export { JwtService };