import { Injectable, BadRequestException } from '@nestjs/common'; import { RequestOtpDto } from '../dto/request-otp.dto'; import { CacheService } from '../../util/cache.service'; import { SmsService } from '../../notification/services/sms.service'; import { UserService } from '../../user/providers/user.service'; import { randomInt } from 'crypto'; import { TokensService } from './tokens.service'; import { RestRepository } from 'src/modules/restaurants/repositories/rest.repository'; import { AuthMessage, RestMessage } from 'src/common/enums/message.enum'; import { AdminRepository } from 'src/modules/admin/repositories/admin.repository'; import { AdminLoginTransformer } from '../transformers/admin-login.transformer'; import { UserLoginTransformer } from '../transformers/user-login.transformer'; import { ConfigService } from '@nestjs/config'; import { normalizePhone } from '../../util/phone.util'; @Injectable() export class AuthService { readonly ADMIN_PERMISSIONS_KEY = 'admin-perms'; private OTP_EXPIRATION_TIME: number; constructor( private readonly cacheService: CacheService, private readonly smsService: SmsService, private readonly userService: UserService, private readonly tokensService: TokensService, private readonly restRepository: RestRepository, private readonly adminRepository: AdminRepository, private readonly configService: ConfigService, ) { this.OTP_EXPIRATION_TIME = this.configService.get('OTP_EXPIRATION_TIME') ?? 240; } private userOtpKey(restaurantSlug: string, phone: string) { return `otp:${restaurantSlug}:${phone}`; } private adminOtpKey(restaurantSlug: string, phone: string) { return `otp-admin:${restaurantSlug}:${phone}`; } async requestOtp(dto: RequestOtpDto, isAdmin: boolean) { const { phone, slug } = dto; const normalizedPhone = normalizePhone(phone); const code = this.generateOtpCode(); const key = isAdmin ? this.adminOtpKey(slug, normalizedPhone) : this.userOtpKey(slug, normalizedPhone); await this.cacheService.set(key, code, this.OTP_EXPIRATION_TIME); await this.smsService.sendotp(normalizedPhone, code); return { code: null }; } async verifyOtp(phone: string, slug: string, code: string) { const normalizedPhone = normalizePhone(phone); const key = this.userOtpKey(slug, normalizedPhone); const cachedCode = await this.cacheService.get(key); if (!cachedCode) throw new BadRequestException('OTP expired or not found'); if (cachedCode !== code) throw new BadRequestException('Invalid OTP'); await this.cacheService.del(key); const user = await this.userService.findOrCreateByPhone(normalizedPhone); const rest = await this.restRepository.findOne({ slug }); if (!rest) { throw new BadRequestException(RestMessage.NOT_FOUND); } const tokens = await this.tokensService.generateAccessAndRefreshToken(user.id, rest.id, false, slug); const userResponse = UserLoginTransformer.transform(user, rest); return { tokens, user: userResponse }; } async verifyOtpAdmin(phone: string, slug: string, code: string) { const normalizedPhone = normalizePhone(phone); const key = this.adminOtpKey(slug, normalizedPhone); const cachedCode = await this.cacheService.get(key); if (!cachedCode) throw new BadRequestException('OTP expired or not found'); if (cachedCode !== code) throw new BadRequestException('Invalid OTP'); await this.cacheService.del(key); const admin = await this.adminRepository.findByPhoneAndRestaurantSlug(normalizedPhone, slug); if (!admin) { throw new BadRequestException(AuthMessage.ADMIN_NOT_FOUND); } const rest = await this.restRepository.findOne({ slug }); if (!rest) { throw new BadRequestException(RestMessage.NOT_FOUND); } const tokens = await this.tokensService.generateAccessAndRefreshToken(admin.id, rest.id, true, slug); const adminResponse = await AdminLoginTransformer.transform(admin, rest); return { tokens, admin: adminResponse }; } /** * to use for login directly from DSC */ async loginAdminForDsc(phone: string, slug: string) { const normalizedPhone = normalizePhone(phone); const admin = await this.adminRepository.findByPhoneAndRestaurantSlug(normalizedPhone, slug); if (!admin) { throw new BadRequestException(AuthMessage.ADMIN_NOT_FOUND); } const rest = await this.restRepository.findOne({ slug }); if (!rest) { throw new BadRequestException(RestMessage.NOT_FOUND); } const tokens = await this.tokensService.generateAccessAndRefreshToken(admin.id, rest.id, true, slug); const adminResponse = await AdminLoginTransformer.transform(admin, rest); return { tokens, admin: adminResponse }; } private generateOtpCode(): string { const code = randomInt(10000, 100000); return code.toString(); } refreshToken(oldRefreshToken: string) { return this.tokensService.refreshToken(oldRefreshToken); } }