Add Google OAuth authentication infrastructure
- Add passport, passport-google-oauth20, jsonwebtoken, cookie-parser, uuid deps - Create config/auth.js with JWT, cookie, and OAuth configuration - Create models/user.js with MongoDB user model and indexes - Create middleware/passport.js with Google OAuth strategy - Create middleware/auth.js with requireAuth middleware and sliding window refresh - Create routes/auth.js with OAuth flow endpoints - Update server.js to integrate auth, protect all data endpoints (except /health) - Configure CORS for cookie-based authentication
This commit is contained in:
24
config/auth.js
Normal file
24
config/auth.js
Normal file
@ -0,0 +1,24 @@
|
||||
// Google OAuth and JWT configuration
|
||||
module.exports = {
|
||||
google: {
|
||||
clientID: process.env.GOOGLE_CLIENT_ID,
|
||||
clientSecret: process.env.GOOGLE_CLIENT_SECRET,
|
||||
callbackURL: process.env.GOOGLE_CALLBACK_URL,
|
||||
scope: ['profile', 'email']
|
||||
},
|
||||
jwt: {
|
||||
secret: process.env.JWT_SECRET,
|
||||
expiresIn: '7d',
|
||||
refreshThreshold: 24 * 60 * 60 // Refresh if token is older than 1 day (in seconds)
|
||||
},
|
||||
cookie: {
|
||||
name: 'auth_token',
|
||||
options: {
|
||||
httpOnly: true,
|
||||
secure: process.env.NODE_ENV === 'production',
|
||||
sameSite: 'lax',
|
||||
maxAge: 7 * 24 * 60 * 60 * 1000, // 7 days
|
||||
domain: process.env.NODE_ENV === 'production' ? '.maverickapplications.com' : undefined
|
||||
}
|
||||
}
|
||||
};
|
||||
Reference in New Issue
Block a user