obsidian-visualiser/server/api/auth/register.post.ts

86 lines
2.9 KiB
TypeScript

import { ZodError, ZodIssue } from 'zod';
import useDatabase from '~/composables/useDatabase';
import { schema } from '~/schemas/registration';
import { checkSession, logSession } from '~/server/utils/user';
import { UserSession, UserSessionRequired } from '~/types/auth';
interface SuccessHandler
{
success: true;
session: UserSession;
}
interface ErrorHandler
{
success: false;
error: Error | ZodError<{
username: string;
email: string;
password: string;
}>;
}
type Return = SuccessHandler | ErrorHandler;
export default defineEventHandler(async (e): Promise<Return> => {
try
{
const session = await getUserSession(e);
const db = useDatabase();
const checkedSession = await checkSession(e, session);
if(checkedSession !== undefined)
return checkedSession;
const body = await readValidatedBody(e, schema.safeParse);
if (!body.success)
{
await clearUserSession(e);
setResponseStatus(e, 406);
return { success: false, error: body.error };
}
const usernameQuery = db.query(`SELECT COUNT(*) as count FROM users WHERE username = ?1`);
const checkUsername = usernameQuery.get(body.data.username) as any;
const emailQuery = db.query(`SELECT COUNT(*) as count FROM users WHERE email = ?1`);
const checkEmail = emailQuery.get(body.data.email) as any;
const errors: ZodIssue[] = [];
if(checkUsername.count !== 0)
errors.push({ code: 'custom', path: ['username'], message: "Ce nom d'utilisateur est déjà utilisé" });
if(checkEmail.count !== 0)
errors.push({ code: 'custom', path: ['email'], message: "Cette adresse mail est déjà utilisée" });
if(errors.length > 0)
{
setResponseStatus(e, 406);
return { success: false, error: new ZodError(errors) };
}
else
{
const hash = await Bun.password.hash(body.data.password);
const registration = db.query(`INSERT INTO users(username, email, hash, state) VALUES(?1, ?2, ?3, 0)`);
registration.run(body.data.username, body.data.email, hash);
const userIdQuery = db.query(`SELECT id FROM users WHERE username = ?1`);
const id = (userIdQuery.get(body.data.username) as any).id;
const registeringData = db.query(`INSERT INTO users_data(user_id, signin_timestamp) VALUES(?1, ?2)`);
registeringData.run(id, Date.now());
logSession(e, await setUserSession(e, { user: { id: id, username: body.data.username, email: body.data.email, state: 0 } }) as UserSessionRequired);
setResponseStatus(e, 201);
return { success: true, session };
}
}
catch(err: any)
{
await clearUserSession(e);
console.error(err);
return { success: false, error: err as Error };
}
});