Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions .env.example

This file was deleted.

42 changes: 42 additions & 0 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 3 additions & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,10 @@
},
"dependencies": {
"bcrypt": "^5.1.1",
"cors": "^2.8.5",
"dotenv": "^16.4.5",
"express": "^4.21.1",
"express-rate-limit": "^8.2.1",
"express-validator": "^7.2.1",
"jsonwebtoken": "^9.0.2",
"pg": "^8.13.1",
Expand All @@ -29,4 +31,4 @@
"prettier": "^3.3.3",
"supertest": "^7.1.1"
}
}
}
4 changes: 3 additions & 1 deletion src/app.js
Original file line number Diff line number Diff line change
Expand Up @@ -3,10 +3,12 @@ const app = express();
const authRoutes = require('./routes/authRoutes');
const taskRoutes = require('./routes/taskRoutes');
const errorHandler = require('./middleware/errorHandler');
const cors = require('cors');

app.use(express.json());
app.use(cors());
app.use('/api/auth', authRoutes);
app.use('/api/tasks', taskRoutes);
app.use(errorHandler);

module.exports = app;
module.exports = app;
17 changes: 11 additions & 6 deletions src/controllers/authController.js
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,22 @@ const authService = require('../services/authService');
exports.register = async (req, res, next) => {
try {
const errors = validationResult(req);
if (!errors.isEmpty()) return res.status(400).json({ errors: errors.array() });
const { username, password } = req.body;
const user = await authService.register(username, password);
if (!errors.isEmpty())
return res.status(400).json({ errors: errors.array() });
const { username, password, role } = req.body;
const user = await authService.register(username, password, role);
res.status(201).json({ message: 'User created', user });
} catch (err) { next(err); }
} catch (err) {
next(err);
}
};

exports.login = async (req, res, next) => {
try {
const { username, password } = req.body;
const token = await authService.login(username, password);
res.json({ token });
} catch (err) { next(err); }
};
} catch (err) {
next(err);
}
};
86 changes: 76 additions & 10 deletions src/controllers/taskController.js
Original file line number Diff line number Diff line change
Expand Up @@ -3,37 +3,103 @@ const { Task } = require('../models');

exports.getTasks = async (req, res, next) => {
try {
const tasks = await Task.findAll({ where: { userId: req.user.id } });
res.json(tasks);
} catch (err) { next(err); }
let { page = 1, limit = 10, status = 'pending', userId } = req.query;

page = parseInt(page);
limit = parseInt(limit);
const offset = (page - 1) * limit;

const where = {};

if (req.user.role === 'admin') {
if (userId) where.userId = userId;
} else {
where.userId = req.user.id;
}

if (status) where.status = status;

const [tasks, total] = await Promise.all([
Task.findAll({
where,
limit,
offset,
order: [['createdAt', 'DESC']],
attributes: [
'id',
'title',
'description',
'status',
'userId',
'createdAt',
],
}),
Task.count({ where }),
]);

res.status(200).json({
page,
limit,
totalPages: Math.ceil(total / limit),
totalTasks: total,
tasks,
});
} catch (err) {
next(err);
}
};

exports.createTask = async (req, res, next) => {
try {
const errors = validationResult(req);
if (!errors.isEmpty()) return res.status(400).json({ errors: errors.array() });
if (!errors.isEmpty())
return res.status(400).json({ errors: errors.array() });
const { title, description } = req.body;
const task = await Task.create({ title, description, userId: req.user.id });
res.status(201).json(task);
} catch (err) { next(err); }
} catch (err) {
next(err);
}
};

exports.updateTask = async (req, res, next) => {
try {
const task = await Task.findByPk(req.params.id);
if (!task) return res.status(404).json({ message: 'Task not found' });
if (task.userId !== req.user.id) return res.status(403).json({ message: 'Forbidden' });
if (task.userId !== req.user.id)
return res.status(403).json({ message: 'Forbidden' });
await task.update(req.body);
res.json(task);
} catch (err) { next(err); }
} catch (err) {
next(err);
}
};

exports.deleteTask = async (req, res, next) => {
try {
const task = await Task.findByPk(req.params.id);
if (!task) return res.status(404).json({ message: 'Task not found' });
if (task.userId !== req.user.id) return res.status(403).json({ message: 'Forbidden' });
if (task.userId !== req.user.id)
return res.status(403).json({ message: 'Forbidden' });
await task.destroy();
res.json({ message: 'Task deleted' });
} catch (err) { next(err); }
};
} catch (err) {
next(err);
}
};

exports.SoftDelete = async (req, res) => {
const task = await Task.findOne({
where: { id: req.params.id, userId: req.user.id },
});

if (!task) {
return res.status(404).json({ error: 'Task not found' });
}

task.status = 'deleted';
task.deletedAt = new Date();
await task.save();

res.json({ message: 'Task Deleted', task });
};
11 changes: 11 additions & 0 deletions src/middleware/rateLimit.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
const rateLimit = require('express-rate-limit');

exports.loginLimiter = rateLimit({
windowMs: 10 * 60 * 1000,
max: 5,
message: {
error: 'Too many login attempts. Please try again in 10 minutes.',
},
standardHeaders: true,
legacyHeaders: false,
});
8 changes: 6 additions & 2 deletions src/models/task.js
Original file line number Diff line number Diff line change
Expand Up @@ -6,12 +6,16 @@ const Task = sequelize.define('Task', {
title: { type: DataTypes.STRING, allowNull: false },
description: { type: DataTypes.TEXT },
status: {
type: DataTypes.ENUM('pending', 'in-progress', 'done'),
type: DataTypes.ENUM('pending', 'in-progress', 'done', 'deleted'),
defaultValue: 'pending',
},
deletedAt: {
type: DataTypes.DATE,
allowNull: true,
},
});

Task.belongsTo(User, { foreignKey: 'userId', onDelete: 'CASCADE' });
User.hasMany(Task, { foreignKey: 'userId' });

module.exports = Task;
module.exports = Task;
7 changes: 6 additions & 1 deletion src/models/user.js
Original file line number Diff line number Diff line change
Expand Up @@ -5,10 +5,15 @@ const bcrypt = require('bcrypt');
const User = sequelize.define('User', {
username: { type: DataTypes.STRING, allowNull: false, unique: true },
password: { type: DataTypes.STRING, allowNull: false },
role: {
type: DataTypes.ENUM('user', 'admin'),
allowNull: false,
defaultValue: 'user',
},
});

User.beforeCreate(async (user) => {
user.password = await bcrypt.hash(user.password, 10);
});

module.exports = User;
module.exports = User;
11 changes: 8 additions & 3 deletions src/routes/authRoutes.js
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,12 @@ const express = require('express');
const { body } = require('express-validator');
const router = express.Router();
const authController = require('../controllers/authController');
const { loginLimiter } = require('../middleware/rateLimit');

router.post('/register', [body('username').notEmpty(), body('password').isLength({ min: 5 })], authController.register);
router.post('/login', authController.login);
module.exports = router;
router.post(
'/register',
[body('username').notEmpty(), body('password').isLength({ min: 5 })],
authController.register
);
router.post('/login', loginLimiter, authController.login);
module.exports = router;
3 changes: 2 additions & 1 deletion src/routes/taskRoutes.js
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,5 @@ router.get('/', taskController.getTasks);
router.post('/', [body('title').notEmpty()], taskController.createTask);
router.put('/:id', taskController.updateTask);
router.delete('/:id', taskController.deleteTask);
module.exports = router;
router.delete('/softdelete/:id', taskController.SoftDelete);
module.exports = router;
15 changes: 10 additions & 5 deletions src/services/authService.js
Original file line number Diff line number Diff line change
Expand Up @@ -2,21 +2,26 @@ const jwt = require('jsonwebtoken');
const bcrypt = require('bcrypt');
const { User } = require('../models');

exports.register = async (username, password) => {
exports.register = async (username, password, role = 'user') => {
const existing = await User.findOne({ where: { username } });
if (existing) throw new Error('Username already exists');
return await User.create({ username, password });
const newUser = await User.create({ username, password, role });
const { password: _, ...safeUser } = newUser.toJSON();
return safeUser;
};

exports.login = async (username, password) => {
const user = await User.findOne({ where: { username } });
if (!user) throw new Error('User not found');

const valid = await bcrypt.compare(password, user.password);
if (!valid) throw new Error('Invalid credentials');

const token = jwt.sign(
{ id: user.id, username: user.username },
{ id: user.id, username: user.username, role: user.role },
process.env.JWT_SECRET,
{ expiresIn: '1h' }
);
return token;
};

return { token, role: user.role };
};