feat: complete multi-user RBAC integration, login system, and fix backend API crashing
This commit is contained in:
1 parent
4aa12511e8
commit
72ded25e4d
31 files changed
+954
-411
No files matched your search
+21
-2
@@ -3,17 +3,36 @@ const path = require('path');
|
||||
require('dotenv').config({ path: path.join(__dirname, '..', '.env.local') });
|
||||
const express = require('express');
|
||||
const cors = require('cors');
|
||||
const cookieParser = require('cookie-parser');
|
||||
const jwt = require('jsonwebtoken');
|
||||
|
||||
const app = express();
|
||||
const PORT = process.env.BACKEND_PORT || 3001;
|
||||
|
||||
// ── Middleware ────────────────────────────────────────────────────────────────
|
||||
app.use(cors());
|
||||
app.use(cors({ origin: true, credentials: true }));
|
||||
app.use(express.json());
|
||||
app.use(cookieParser());
|
||||
|
||||
// ── API Routes ────────────────────────────────────────────────────────────────
|
||||
const authRoutes = require('./routes/auth');
|
||||
app.use('/api/auth', authRoutes);
|
||||
|
||||
// Auth Middleware for Dashboard
|
||||
const JWT_SECRET = process.env.JWT_SECRET || 'super-secret-backone-key';
|
||||
function requireAuth(req, res, next) {
|
||||
const token = req.cookies?.token;
|
||||
if (!token) return res.status(401).json({ error: 'Unauthorized' });
|
||||
try {
|
||||
req.user = jwt.verify(token, JWT_SECRET);
|
||||
next();
|
||||
} catch (err) {
|
||||
res.status(401).json({ error: 'Invalid token' });
|
||||
}
|
||||
}
|
||||
|
||||
const dashboardRoutes = require('./routes/dashboard');
|
||||
app.use('/api/dashboard', dashboardRoutes);
|
||||
app.use('/api/dashboard', requireAuth, dashboardRoutes);
|
||||
|
||||
// ── Health Check ──────────────────────────────────────────────────────────────
|
||||
app.get('/api/health', (req, res) => {
|
||||
|
||||
Reference in new issue
Block a user