fix: Use the correct defaults for the invite token expiry (#10344)

This commit is contained in:
Stevche Radevski
2024-11-28 12:06:32 +01:00
committed by GitHub
parent aced04e182
commit f7279f1b96
3 changed files with 45 additions and 8 deletions
@@ -156,6 +156,37 @@ medusaIntegrationTestRunner({
expect(e.response.data.message).toEqual("Unauthorized") expect(e.response.data.message).toEqual("Unauthorized")
}) })
}) })
it("should fail to accept with an expired token", async () => {
jest.useFakeTimers()
const signup = await api.post("/auth/user/emailpass/register", {
email: "test@medusa-commerce.com",
password: "secret_password",
})
// Advance time by 25 hours
jest.advanceTimersByTime(25 * 60 * 60 * 1000)
await api
.post(
`/admin/invites/accept?token=${invite.token}`,
{
first_name: "Another Test",
last_name: "User",
},
{
headers: { authorization: `Bearer ${signup.data.token}` },
}
)
.catch((e) => {
expect(e.response.status).toEqual(401)
expect(e.response.data.message).toEqual("Unauthorized")
})
jest.useRealTimers()
})
it("should resend an invite", async () => { it("should resend an invite", async () => {
const resendResponse = ( const resendResponse = (
await api.post(`/admin/invites/${invite.id}/resend`, {}, adminHeaders) await api.post(`/admin/invites/${invite.id}/resend`, {}, adminHeaders)
@@ -1,14 +1,16 @@
import { IUserModuleService } from "@medusajs/framework/types/dist/user" import { IUserModuleService } from "@medusajs/framework/types"
import { Modules, UserEvents } from "@medusajs/framework/utils" import { Modules, UserEvents } from "@medusajs/framework/utils"
import { import {
MockEventBusService, MockEventBusService,
moduleIntegrationTestRunner, moduleIntegrationTestRunner,
} from "@medusajs/test-utils" } from "@medusajs/test-utils"
import jwt, { JwtPayload } from "jsonwebtoken"
jest.setTimeout(30000) jest.setTimeout(30000)
const today = new Date() const expireDate = new Date().setMilliseconds(
const expireDate = new Date(today.setDate(today.getDate() + 10)) new Date().getMilliseconds() + 60 * 60 * 24
)
const defaultInviteData = [ const defaultInviteData = [
{ {
@@ -111,6 +113,11 @@ moduleIntegrationTestRunner<IUserModuleService>({
id, id,
}) })
) )
const tokenContent = jwt.decode(invite.token) as JwtPayload
expect(tokenContent.exp).toBeLessThanOrEqual(
Date.now() / 1000 + 60 * 60 * 24
)
}) })
it("should throw an error when an invite with the given id does not exist", async () => { it("should throw an error when an invite with the given id does not exist", async () => {
@@ -27,8 +27,7 @@ type InjectedDependencies = {
inviteService: ModulesSdkTypes.IMedusaInternalService<any> inviteService: ModulesSdkTypes.IMedusaInternalService<any>
} }
// 1 day const DEFAULT_VALID_INVITE_DURATION_SECONDS = 60 * 60 * 24
const DEFAULT_VALID_INVITE_DURATION = 60 * 60 * 24 * 1000
export default class UserModuleService export default class UserModuleService
extends MedusaService<{ extends MedusaService<{
User: { User: {
@@ -60,7 +59,7 @@ export default class UserModuleService
jwtSecret: moduleDeclaration["jwt_secret"], jwtSecret: moduleDeclaration["jwt_secret"],
expiresIn: expiresIn:
parseInt(moduleDeclaration["valid_duration"]) || parseInt(moduleDeclaration["valid_duration"]) ||
DEFAULT_VALID_INVITE_DURATION, DEFAULT_VALID_INVITE_DURATION_SECONDS,
} }
if (!this.config.jwtSecret) { if (!this.config.jwtSecret) {
@@ -153,7 +152,7 @@ export default class UserModuleService
return { return {
id: invite.id, id: invite.id,
expires_at: new Date().setMilliseconds( expires_at: new Date().setMilliseconds(
new Date().getMilliseconds() + this.config.expiresIn new Date().getMilliseconds() + this.config.expiresIn * 1000
), ),
token: this.generateToken({ id: invite.id, email: invite.email }), token: this.generateToken({ id: invite.id, email: invite.email }),
} }
@@ -325,7 +324,7 @@ export default class UserModuleService
return { return {
id: invite.id, id: invite.id,
expires_at: new Date().setMilliseconds( expires_at: new Date().setMilliseconds(
new Date().getMilliseconds() + this.config.expiresIn new Date().getMilliseconds() + this.config.expiresIn * 1000
), ),
token: this.generateToken({ id: invite.id, email: invite.email }), token: this.generateToken({ id: invite.id, email: invite.email }),
} }