* Atom / RSS meta link * Spike * Feeling good about this spike now * Remove document.collection * Remove koa.ctx from all presenters to make them portable outside requests * Remove full serialized model from events Move events.add to controllers for now, will eventually be in commands * collections.create event parentDocument -> parentDocumentId * Fix up deprecated tests * Fixed: Doc creation * documents.move * Handle collection deleted * 💚 * Authorize room join requests * Move starred data structure Account for documents with no context on sockets * Add socket.io-redis * Add WEBSOCKETS_ENABLED env variable to disable websockets entirely for self hosted New installations will default to true, existing installations to false * 💚 No need for promise response here * Reload notice
26 lines
575 B
JavaScript
26 lines
575 B
JavaScript
// @flow
|
|
import JWT from 'jsonwebtoken';
|
|
import { AuthenticationError } from '../errors';
|
|
import { User } from '../models';
|
|
|
|
export async function getUserForJWT(token: string) {
|
|
let payload;
|
|
try {
|
|
payload = JWT.decode(token);
|
|
} catch (err) {
|
|
throw new AuthenticationError('Unable to decode JWT token');
|
|
}
|
|
|
|
if (!payload) throw new AuthenticationError('Invalid token');
|
|
|
|
const user = await User.findById(payload.id);
|
|
|
|
try {
|
|
JWT.verify(token, user.jwtSecret);
|
|
} catch (err) {
|
|
throw new AuthenticationError('Invalid token');
|
|
}
|
|
|
|
return user;
|
|
}
|