auth.controller.js 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211
  1. const { validation } = require('../../middleware/validation')
  2. const response = require('../../utils/responseHandler')
  3. const userModel = require('../../model/user.model')
  4. const { roleDataProduction, TEMPLATE_VERIFIKASI, PTB_DIKTI, PTB_ADMIN } = require('../../utils/constanta')
  5. const convertRole = require('../../utils/convertRole')
  6. const jwt = require('jsonwebtoken')
  7. const moment = require('moment')
  8. const logModel = require('../../model/log.model')
  9. const auth = require('../../middleware/verifyToken')
  10. const generateOTP = require('../../utils/otp')
  11. const { genSaltSync, compareSync, hashSync } = require('bcrypt')
  12. const role = require('../../middleware/role')
  13. const pddiktiService = require('../../services/v2/pddikti.service')
  14. exports.login = [
  15. validation((req) => req.body, {
  16. username: { type: 'string', empty: false },
  17. password: { type: 'string', empty: false }
  18. }),
  19. async (req, res) => {
  20. const { username, password } = req.body
  21. let userResponse
  22. try {
  23. userResponse = await pddiktiService.login(req.body)
  24. if (userResponse.code === 400) {
  25. return response.error(res, {
  26. code: 401,
  27. message: userResponse.message
  28. })
  29. }
  30. } catch (e) {
  31. return response.error(res, {
  32. code: 500,
  33. message: e.message
  34. })
  35. }
  36. let role = userResponse.peran.find((e) => roleDataProduction.includes(e.peran.id))
  37. if (!role) {
  38. return response.error(res, {
  39. code: 401,
  40. message: 'Anda tidak memiliki akses ke aplikasi ini'
  41. })
  42. }
  43. role.peran.id = convertRole(role?.peran?.id)
  44. let user = await userModel.findOne({ user_id: userResponse.id })
  45. if (!user) {
  46. await userModel.create({
  47. user_id: userResponse.id,
  48. nama: userResponse.nama,
  49. lembaga: role.organisasi,
  50. email: userResponse.username,
  51. no_hp: userResponse.no_hp,
  52. alamat: userResponse.alamat,
  53. role: role.peran,
  54. role_asal: role.peran,
  55. isPublic: false,
  56. isPrivate: false
  57. })
  58. } else {
  59. await userModel.findOneAndUpdate({ user_id: userResponse.id }, {
  60. lembaga: role.organisasi,
  61. role: {
  62. id: username.toLowerCase() === 'rizqevo@outlook.com' ? 2020 : username.toLowerCase() === 'sugiyanto@gmail.com' ? 2024 : role.peran.id,
  63. nama: username.toLowerCase() === 'rizqevo@outlook.com' ? 'PTB Dikti' : username.toLowerCase() === 'sugiyanto@gmail.com' ? 'ReadOnly' : role.peran.nama,
  64. menu: role.peran.menu
  65. },
  66. role_asal: {
  67. id: role.peran.id,
  68. nama: role.peran.nama,
  69. menu: role.peran.menu
  70. }
  71. })
  72. }
  73. user = await userModel.findOne({ user_id: userResponse.id })
  74. const accessToken = jwt.sign({ _id: user._id }, process.env.SRU51, {
  75. expiresIn: '1d'
  76. })
  77. res.cookie('sidali-cookie', accessToken, {
  78. httpOnly: true,
  79. expires: moment().add(1, 'day').toDate()
  80. })
  81. return response.success(res, {
  82. message: 'Berhasil Login',
  83. data: {
  84. token: `Bearer ${accessToken}`,
  85. user
  86. }
  87. })
  88. }
  89. ]
  90. exports.loginToPT = [
  91. auth,
  92. role([PTB_DIKTI, PTB_ADMIN]),
  93. validation((req) => req.body, {
  94. lembaga_id: 'string',
  95. password: 'string'
  96. }),
  97. async (req, res) => {
  98. let user = req.user
  99. const { lembaga_id, password } = req.body
  100. let dataLembaga
  101. try {
  102. const userResponse = await pddiktiService.login({ username: user.email, password })
  103. if (userResponse.code && userResponse.code !== 200) {
  104. return response.error(res, {
  105. code: 401,
  106. message: userResponse.message
  107. })
  108. }
  109. dataLembaga = await pddiktiService.getPT(lembaga_id)
  110. } catch (e) {
  111. return response.error(res, {
  112. code: e.response.status,
  113. message: e.message
  114. })
  115. }
  116. await userModel.updateOne({
  117. _id: user._id
  118. }, {
  119. lembaga: {
  120. id: dataLembaga[0].id,
  121. nama: dataLembaga[0].nama
  122. },
  123. role: {
  124. id: 2022,
  125. nama: 'PTB PT'
  126. }
  127. })
  128. user = await userModel.findOne({ _id: user._id })
  129. await logModel.create({
  130. user: user._id,
  131. aktivitas: `${user.nama} berhasil masuk ke PT ${dataLembaga[0].nama}`
  132. })
  133. const accessToken = jwt.sign({ _id: user._id }, process.env.SRU51, {
  134. expiresIn: '1d'
  135. })
  136. const data = {
  137. token: `Bearer ${accessToken}`,
  138. user
  139. }
  140. res.cookie('sidali-cookie', accessToken, {
  141. httpOnly: true,
  142. expires: moment().add(1, 'day').toDate()
  143. })
  144. response.success(res, {
  145. message: 'Berhasil Login',
  146. data
  147. })
  148. }
  149. ]
  150. exports.logout = [
  151. auth,
  152. (req, res) => {
  153. res.clearCookie('sidali-cookie')
  154. response.success(res, {
  155. message: 'Berhasil Logout'
  156. })
  157. }
  158. ]
  159. exports.sendOTP = [
  160. auth,
  161. validation((req) => req.body, { no_hp: 'string' }),
  162. async (req, res) => {
  163. const user = req.user
  164. let no_hp = req.body.no_hp
  165. no_hp = req.body.no_hp.substring(0, 1) === '0' ? '62' + no_hp.substring(1) : no_hp
  166. const generatedOtp = generateOTP(4)
  167. res.cookie('sidali-otp', jwt.sign({ no_hp, otp: generatedOtp }, process.env.SRU51, {
  168. expiresIn: '5m'
  169. }), {
  170. httpOnly: true,
  171. secure: true,
  172. expires: moment().add(5, 'minutes').toDate()
  173. })
  174. try {
  175. const waResult = await pddiktiService.whatsapp(TEMPLATE_VERIFIKASI, [{ name: user.nama, number: no_hp }], [
  176. { key: '1', value: 'pt', value_text: user.lembaga.nama },
  177. { key: '3', value: 'no_verifikasi', value_text: generatedOtp },
  178. { key: '2', value: 'no_laporan', value_text: '-' }
  179. ])
  180. if ([200, 201].includes(waResult.status)) {
  181. return response.error(res, {
  182. code: waResult[0].error.code,
  183. error: waResult[0].error.messages
  184. })
  185. }
  186. } catch (e) {
  187. return response.error(res, {
  188. code: 500,
  189. message: e.message
  190. })
  191. }
  192. return response.success(res, {
  193. message: 'Berhasil mengirimkan OTP',
  194. })
  195. }
  196. ]