diff options
Diffstat (limited to 'backend/src')
| -rw-r--r-- | backend/src/index.js | 23 | ||||
| -rw-r--r-- | backend/src/resolvers/Mutation.js | 24 | ||||
| -rw-r--r-- | backend/src/resolvers/Query.js | 3 | ||||
| -rw-r--r-- | backend/src/schema.graphql | 1 |
4 files changed, 38 insertions, 13 deletions
diff --git a/backend/src/index.js b/backend/src/index.js index 04d13cc..6978225 100644 --- a/backend/src/index.js +++ b/backend/src/index.js @@ -3,14 +3,16 @@ require('dotenv').config({ path: 'variables.env' }); /* eslint-enable */ const jwt = require('jsonwebtoken'); const createServer = require('./createServer'); +const cookieParser = require('cookie-parser'); const server = createServer(); +server.express.use(cookieParser()); + // 1. Check JWT server.express.use((req, res, next) => { - const Authorization = req.get('Authorization'); - if (Authorization) { - const token = Authorization.replace('Bearer ', ''); + const { token } = req.cookies; + if (token) { const { userId } = jwt.verify(token, process.env.APP_SECRET); req.userId = userId; } @@ -30,6 +32,15 @@ server.express.use(async (req, res, next) => { next(); }); -server.start({ port: 4444 }, deets => { - console.log(`Server is running on http://localhost:${deets.port}`); -}); +server.start( + { + cors: { + credentials: true, + origin: process.env.FRONTEND_URL, + }, + port: 4444, + }, + deets => { + console.log(`Server is running on http://localhost:${deets.port}`); + } +); diff --git a/backend/src/resolvers/Mutation.js b/backend/src/resolvers/Mutation.js index 268b348..153833d 100644 --- a/backend/src/resolvers/Mutation.js +++ b/backend/src/resolvers/Mutation.js @@ -22,10 +22,18 @@ const mutations = { info ); - return { - token: jwt.sign({ userId: user.id }, process.env.APP_SECRET), - user, - }; + const token = jwt.sign({ userId: user.id }, process.env.APP_SECRET); + ctx.response.cookie('token', token, { + maxAge: 1000 * 60 * 60 * 24 * 365, + httpOnly: true, + }); + return { user }; + }, + + async signout(parent, args, ctx, info) { + ctx.response.clearCookie('token'); + // TODO: What do we return here? + return { id: 'abc123' }; }, async signin(parent, { email, password }, ctx, info) { @@ -38,8 +46,14 @@ const mutations = { if (!valid) { throw new Error('Invalid password'); } + // set the cookie + const token = jwt.sign({ userId: user.id }, process.env.APP_SECRET); + ctx.response.cookie('token', token, { + maxAge: 1000 * 60 * 60 * 24 * 365, + httpOnly: true, + }); return { - token: jwt.sign({ userId: user.id }, process.env.APP_SECRET), + token, user, }; }, diff --git a/backend/src/resolvers/Query.js b/backend/src/resolvers/Query.js index 276f7fa..b1e0c5b 100644 --- a/backend/src/resolvers/Query.js +++ b/backend/src/resolvers/Query.js @@ -36,8 +36,7 @@ const Query = { }, me(parent, args, ctx, info) { - const Authorization = ctx.request.get('Authorization'); - if (!Authorization || Authorization === 'null') { + if (!ctx.request.userId) { return null; // don't error out, just return nothing } diff --git a/backend/src/schema.graphql b/backend/src/schema.graphql index 5c77d56..14d4797 100644 --- a/backend/src/schema.graphql +++ b/backend/src/schema.graphql @@ -18,6 +18,7 @@ type Mutation { removeFromCart(id: ID!): CartItem createOrder(token: String!): Order! updateUser(name: String): User + signout: User updatePermissions(permissions: [Permission], userId: ID!): User } |
