feat: member phone login — POST /public/auth/member-login + /my/login page
Returning members can now sign in with just their phone number. The bot DMs them a 6-digit OTP; on verify a 30-day session cookie is set. First-time users are directed to their invite link from the login page. - Make OtpChallenge.groupId optional (migration) for re-login challenges - Add memberLogin / memberVerify service methods - Add POST /public/auth/member-login and /member-verify controller endpoints - Add /api/my/login BFF route (sets tower_member_token cookie) - Add /my/login page (phone → OTP two-step form) - /my/* now redirects to /my/login instead of /onboard on no session Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
-- Make groupId optional on OtpChallenge so member re-login challenges
|
||||
-- (which have no group context) can be created without a groupId.
|
||||
ALTER TABLE "OtpChallenge" ALTER COLUMN "groupId" DROP NOT NULL;
|
||||
@@ -496,7 +496,7 @@ model OtpChallenge {
|
||||
scopes ConsentScope[]
|
||||
retentionDays Int @default(90)
|
||||
policyVersion String
|
||||
groupId String
|
||||
groupId String?
|
||||
expiresAt DateTime
|
||||
consumedAt DateTime?
|
||||
sentAt DateTime?
|
||||
|
||||
@@ -224,6 +224,89 @@ export class OnboardingService {
|
||||
};
|
||||
}
|
||||
|
||||
async memberLogin(phone: string): Promise<{ challengeId: string; expiresInSeconds: number }> {
|
||||
const pepper = this.config.get<string>('JWT_SECRET') ?? '';
|
||||
const phoneHash = hashPhone(phone, pepper);
|
||||
|
||||
const user = await this.prisma.towerUser.findFirst({
|
||||
where: { phoneHash },
|
||||
select: { id: true, tenantId: true, jid: true },
|
||||
});
|
||||
if (!user) throw new NotFoundException('No portal account found for this number. Use your original invite link to register first.');
|
||||
|
||||
const code = String(Math.floor(100000 + Math.random() * 900000));
|
||||
const expiresAt = new Date(Date.now() + OTP_TTL_MIN * 60 * 1000);
|
||||
const challengeId = randomBytes(16).toString('hex');
|
||||
|
||||
await this.prisma.otpChallenge.create({
|
||||
data: {
|
||||
id: challengeId,
|
||||
tenantId: user.tenantId,
|
||||
jid: user.jid,
|
||||
phoneHash,
|
||||
code,
|
||||
scopes: DEFAULT_SCOPES,
|
||||
retentionDays: DEFAULT_RETENTION_DAYS,
|
||||
policyVersion: this.policyVersion,
|
||||
expiresAt,
|
||||
},
|
||||
});
|
||||
|
||||
await this.audit.log({
|
||||
tenantId: user.tenantId,
|
||||
action: AuditAction.OTP_REQUESTED,
|
||||
resourceType: 'TowerUser',
|
||||
resourceId: user.id,
|
||||
payload: { jid: user.jid, source: 'member-login' },
|
||||
});
|
||||
|
||||
return { challengeId, expiresInSeconds: OTP_TTL_MIN * 60 };
|
||||
}
|
||||
|
||||
async memberVerify(challengeId: string, phone: string, code: string): Promise<{
|
||||
memberToken: string;
|
||||
user: { id: string; tenantId: string; jid: string; displayName: string | null };
|
||||
}> {
|
||||
const pepper = this.config.get<string>('JWT_SECRET') ?? '';
|
||||
const phoneHash = hashPhone(phone, pepper);
|
||||
|
||||
const challenge = await this.prisma.otpChallenge.findUnique({ where: { id: challengeId } });
|
||||
if (!challenge) throw new NotFoundException('Challenge not found');
|
||||
if (challenge.consumedAt) throw new UnauthorizedException('Challenge already used');
|
||||
if (challenge.expiresAt < new Date()) throw new UnauthorizedException('Code expired');
|
||||
if (challenge.code !== code) throw new UnauthorizedException('Invalid code');
|
||||
if (challenge.phoneHash !== phoneHash) throw new UnauthorizedException('Phone mismatch');
|
||||
|
||||
await this.prisma.otpChallenge.update({
|
||||
where: { id: challengeId },
|
||||
data: { consumedAt: new Date() },
|
||||
});
|
||||
|
||||
const user = await this.prisma.towerUser.findFirst({
|
||||
where: { phoneHash, tenantId: challenge.tenantId },
|
||||
select: { id: true, tenantId: true, jid: true, displayName: true, phoneHash: true },
|
||||
});
|
||||
if (!user) throw new NotFoundException('User not found');
|
||||
|
||||
await this.audit.log({
|
||||
tenantId: user.tenantId,
|
||||
action: AuditAction.OTP_VERIFIED,
|
||||
resourceType: 'TowerUser',
|
||||
resourceId: user.id,
|
||||
payload: { jid: user.jid, source: 'member-login' },
|
||||
});
|
||||
|
||||
const memberToken = await this.jwt.signAsync({
|
||||
kind: 'member',
|
||||
sub: user.id,
|
||||
tenantId: user.tenantId,
|
||||
jid: user.jid,
|
||||
phoneHash: user.phoneHash,
|
||||
} as const);
|
||||
|
||||
return { memberToken, user: { id: user.id, tenantId: user.tenantId, jid: user.jid, displayName: user.displayName } };
|
||||
}
|
||||
|
||||
private normalizeJid(jid: string): string {
|
||||
return jid.trim();
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { Body, Controller, Get, Param, Post, UseGuards } from '@nestjs/common';
|
||||
import { Body, Controller, Get, Param, Post } from '@nestjs/common';
|
||||
import { OnboardingService } from './onboarding.service';
|
||||
import { IsArray, IsInt, IsOptional, IsString, Min, MinLength } from 'class-validator';
|
||||
import { ConsentScope } from '@tower/types';
|
||||
@@ -18,6 +18,16 @@ class VerifyOtpDto {
|
||||
@IsInt() @Min(1) @IsOptional() retentionDays?: number;
|
||||
}
|
||||
|
||||
class MemberLoginDto {
|
||||
@IsString() @MinLength(6) phone!: string;
|
||||
}
|
||||
|
||||
class MemberVerifyDto {
|
||||
@IsString() challengeId!: string;
|
||||
@IsString() @MinLength(6) phone!: string;
|
||||
@IsString() @MinLength(6) code!: string;
|
||||
}
|
||||
|
||||
@Controller('public')
|
||||
export class PublicOnboardingController {
|
||||
constructor(private readonly service: OnboardingService) {}
|
||||
@@ -46,4 +56,16 @@ export class PublicOnboardingController {
|
||||
body.retentionDays,
|
||||
);
|
||||
}
|
||||
|
||||
@Post('auth/member-login')
|
||||
@Public()
|
||||
memberLogin(@Body() body: MemberLoginDto) {
|
||||
return this.service.memberLogin(body.phone);
|
||||
}
|
||||
|
||||
@Post('auth/member-verify')
|
||||
@Public()
|
||||
memberVerify(@Body() body: MemberVerifyDto) {
|
||||
return this.service.memberVerify(body.challengeId, body.phone, body.code);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user