Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ AUTH_JWT_REFRESH_TOKEN_KID=
AUTH_JWT_REFRESH_TOKEN_PRIVATE_KEY_PATH=keys/refresh-token.pem
AUTH_JWT_REFRESH_TOKEN_PUBLIC_KEY_PATH=keys/refresh-token.pub
AUTH_JWT_REFRESH_TOKEN_EXPIRED=7d
AUTH_JWT_REFRESH_TOKEN_ROTATE_ON_RENEWAL=true

AUTH_SOCIAL_GOOGLE_CLIENT_ID=
AUTH_SOCIAL_GOOGLE_CLIENT_SECRET=
Expand Down
1 change: 1 addition & 0 deletions src/configs/auth.config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ export default registerAs(
process.env
.AUTH_JWT_REFRESH_TOKEN_EXPIRED as ms.StringValue
) / 1000,
rotateOnRenewal: process.env.AUTH_JWT_REFRESH_TOKEN_ROTATE_ON_RENEWAL === 'true',
},

algorithm: 'ES512',
Expand Down
16 changes: 15 additions & 1 deletion src/modules/auth/services/auth.service.ts
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ export class AuthService implements IAuthService {
private readonly jwtRefreshTokenPrivateKey: string;
private readonly jwtRefreshTokenPublicKey: string;
private readonly jwtRefreshTokenExpirationTime: number;
private readonly jwtRefreshTokenRotateOnRenewal: boolean;

private readonly jwtPrefix: string;
private readonly jwtAudience: string;
Expand Down Expand Up @@ -111,6 +112,9 @@ export class AuthService implements IAuthService {
this.jwtRefreshTokenExpirationTime = this.configService.get<number>(
'auth.jwt.refreshToken.expirationTime'
);
this.jwtRefreshTokenRotateOnRenewal = this.configService.get<boolean>(
'auth.jwt.refreshToken.rotateOnRenewal'
);

this.jwtPrefix = this.configService.get<string>('auth.jwt.prefix');
this.jwtAudience = this.configService.get<string>('auth.jwt.audience');
Expand Down Expand Up @@ -349,12 +353,22 @@ export class AuthService implements IAuthService {
payloadAccessToken
);

let refreshToken: string = refreshTokenFromRequest
if (this.jwtRefreshTokenRotateOnRenewal) {
const payloadRefreshToken: IAuthJwtRefreshTokenPayload =
this.createPayloadRefreshToken(payloadAccessToken);
refreshToken = this.createRefreshToken(
user._id,
payloadRefreshToken
);
}

return {
tokenType: this.jwtPrefix,
roleType,
expiresIn: this.jwtAccessTokenExpirationTime,
accessToken,
refreshToken: refreshTokenFromRequest,
refreshToken,
};
}

Expand Down