-
Notifications
You must be signed in to change notification settings - Fork 736
/
Copy pathhandler_login.go
74 lines (64 loc) · 1.83 KB
/
handler_login.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
package main
import (
"encoding/json"
"net/http"
"time"
"github.com/imhasandl/learn-file-storage-s3-golang-starter/internal/auth"
"github.com/imhasandl/learn-file-storage-s3-golang-starter/internal/database"
)
func (cfg *apiConfig) handlerLogin(w http.ResponseWriter, r *http.Request) {
type parameters struct {
Password string `json:"password"`
Email string `json:"email"`
}
type response struct {
database.User
Token string `json:"token"`
RefreshToken string `json:"refresh_token"`
}
decoder := json.NewDecoder(r.Body)
params := parameters{}
err := decoder.Decode(¶ms)
if err != nil {
respondWithError(w, http.StatusInternalServerError, "Couldn't decode parameters", err)
return
}
user, err := cfg.db.GetUserByEmail(params.Email)
if err != nil {
respondWithError(w, http.StatusUnauthorized, "Incorrect email or password", err)
return
}
err = auth.CheckPasswordHash(params.Password, user.Password)
if err != nil {
respondWithError(w, http.StatusUnauthorized, "Incorrect email or password", err)
return
}
accessToken, err := auth.MakeJWT(
user.ID,
cfg.jwtSecret,
time.Hour*24*30,
)
if err != nil {
respondWithError(w, http.StatusInternalServerError, "Couldn't create access JWT", err)
return
}
refreshToken, err := auth.MakeRefreshToken()
if err != nil {
respondWithError(w, http.StatusInternalServerError, "Couldn't create refresh token", err)
return
}
_, err = cfg.db.CreateRefreshToken(database.CreateRefreshTokenParams{
UserID: user.ID,
Token: refreshToken,
ExpiresAt: time.Now().UTC().Add(time.Hour * 24 * 60),
})
if err != nil {
respondWithError(w, http.StatusInternalServerError, "Couldn't save refresh token", err)
return
}
respondWithJSON(w, http.StatusOK, response{
User: user,
Token: accessToken,
RefreshToken: refreshToken,
})
}