auth.controller.js 5.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211
  1. const { validation } = require('../../middleware/validation')
  2. const response = require('../../utils/responseHandler')
  3. const userModel = require('../../model/user.model')
  4. const { roleDataProduction, PTB_DIKTI, PTB_ADMIN, TEMPLATE_OTP, PTB_READ } = require('../../utils/constanta')
  5. const convertRole = require('../../utils/convertRole')
  6. const jwt = require('jsonwebtoken')
  7. const moment = require('moment')
  8. const logModel = require('../../model/log.model')
  9. const auth = require('../../middleware/verifyToken')
  10. const generateOTP = require('../../utils/otp')
  11. const role = require('../../middleware/role')
  12. const pddiktiService = require('../../services/v2/pddikti.service')
  13. exports.login = [
  14. validation((req) => req.body, {
  15. username: { type: 'string', empty: false },
  16. password: { type: 'string', empty: false }
  17. }),
  18. async (req, res) => {
  19. const { username, password } = req.body
  20. let userResponse
  21. try {
  22. userResponse = await pddiktiService.login(req.body)
  23. if (userResponse.code === 400) {
  24. return response.error(res, {
  25. code: 401,
  26. message: userResponse.message
  27. })
  28. }
  29. } catch (e) {
  30. return response.error(res, {
  31. code: 500,
  32. message: e.message
  33. })
  34. }
  35. let role = userResponse.peran.find((e) => roleDataProduction.includes(e.peran.id))
  36. if (!role) {
  37. return response.error(res, {
  38. code: 401,
  39. message: 'Anda tidak memiliki akses ke aplikasi ini'
  40. })
  41. }
  42. role.peran.id = convertRole(role?.peran?.id)
  43. let user = await userModel.findOne({ user_id: userResponse.id })
  44. if (!user) {
  45. await userModel.create({
  46. user_id: userResponse.id,
  47. nama: userResponse.nama,
  48. lembaga: role.organisasi,
  49. email: userResponse.username,
  50. no_hp: userResponse.no_hp,
  51. alamat: userResponse.alamat,
  52. role: role.peran,
  53. role_asal: role.peran,
  54. isPublic: false,
  55. isPrivate: false
  56. })
  57. } else {
  58. await userModel.findOneAndUpdate({ user_id: userResponse.id }, {
  59. lembaga: role.organisasi,
  60. role: {
  61. id: username.toLowerCase() === 'rizqevo@outlook.com' ? PTB_READ : role.peran.id,
  62. nama: username.toLowerCase() === 'rizqevo@outlook.com' ? 'Auditor PTB' : role.peran.nama,
  63. menu: role.peran.menu
  64. },
  65. role_asal: {
  66. id: role.peran.id,
  67. nama: role.peran.nama,
  68. menu: role.peran.menu
  69. }
  70. })
  71. }
  72. user = await userModel.findOne({ user_id: userResponse.id })
  73. const accessToken = jwt.sign({ _id: user._id }, process.env.SRU51, {
  74. expiresIn: '1d'
  75. })
  76. res.cookie('sidali-cookie', accessToken, {
  77. httpOnly: true,
  78. expires: moment().add(1, 'day').toDate()
  79. })
  80. return response.success(res, {
  81. message: 'Berhasil Login',
  82. data: {
  83. token: `Bearer ${accessToken}`,
  84. user
  85. }
  86. })
  87. }
  88. ]
  89. exports.loginToPT = [
  90. auth,
  91. role([PTB_DIKTI, PTB_ADMIN]),
  92. validation((req) => req.body, {
  93. lembaga_id: 'string',
  94. password: 'string'
  95. }),
  96. async (req, res) => {
  97. let user = req.user
  98. const { lembaga_id, password } = req.body
  99. let dataLembaga
  100. try {
  101. const userResponse = await pddiktiService.login({ username: user.email, password })
  102. if (userResponse.code && userResponse.code !== 200) {
  103. return response.error(res, {
  104. code: 401,
  105. message: userResponse.message
  106. })
  107. }
  108. dataLembaga = await pddiktiService.getPT(lembaga_id)
  109. } catch (e) {
  110. return response.error(res, {
  111. code: e.response.status,
  112. message: e.message
  113. })
  114. }
  115. await userModel.updateOne({
  116. _id: user._id
  117. }, {
  118. lembaga: {
  119. id: dataLembaga[0].id,
  120. nama: dataLembaga[0].nama
  121. },
  122. role: {
  123. id: 2022,
  124. nama: 'PTB PT'
  125. }
  126. })
  127. user = await userModel.findOne({ _id: user._id })
  128. await logModel.create({
  129. user: user._id,
  130. aktivitas: `${user.nama} berhasil masuk ke PT ${dataLembaga[0].nama}`
  131. })
  132. const accessToken = jwt.sign({ _id: user._id }, process.env.SRU51, {
  133. expiresIn: '1d'
  134. })
  135. const data = {
  136. token: `Bearer ${accessToken}`,
  137. user
  138. }
  139. res.cookie('sidali-cookie', accessToken, {
  140. httpOnly: true,
  141. expires: moment().add(1, 'day').toDate()
  142. })
  143. response.success(res, {
  144. message: 'Berhasil Login',
  145. data
  146. })
  147. }
  148. ]
  149. exports.logout = [
  150. auth,
  151. (req, res) => {
  152. res.clearCookie('sidali-cookie')
  153. response.success(res, {
  154. message: 'Berhasil Logout'
  155. })
  156. }
  157. ]
  158. exports.sendOTP = [
  159. auth,
  160. validation((req) => req.body, { no_hp: 'string' }),
  161. async (req, res) => {
  162. const user = req.user
  163. let no_hp = req.body.no_hp
  164. no_hp = req.body.no_hp.substring(0, 1) === '0' ? '62' + no_hp.substring(1) : no_hp
  165. const generatedOtp = generateOTP(4)
  166. res.cookie('sidali-otp', jwt.sign({ no_hp, otp: generatedOtp }, process.env.SRU51, {
  167. expiresIn: '5m'
  168. }), {
  169. httpOnly: true,
  170. secure: true,
  171. expires: moment().add(5, 'minutes').toDate()
  172. })
  173. try {
  174. const waResult = await pddiktiService.whatsapp(
  175. TEMPLATE_OTP,
  176. [{ name: user.nama, number: no_hp }],
  177. [{ key: 1, value: 'otp', value_text: generatedOtp }],
  178. [{ type: 'url', value: generatedOtp }]
  179. )
  180. if ([200, 201].includes(waResult.status)) {
  181. return response.error(res, {
  182. code: waResult[0].error.code,
  183. error: waResult[0].error.messages
  184. })
  185. }
  186. } catch (e) {
  187. return response.error(res, {
  188. code: 500,
  189. message: e.message
  190. })
  191. }
  192. return response.success(res, {
  193. message: 'Berhasil mengirimkan OTP'
  194. })
  195. }
  196. ]