Fix: Code readability

This commit is contained in:
Daniel Hougaard
2024-03-17 18:49:30 +01:00
parent 700a072ec5
commit 1dbf80d4e6
+12 -12
View File
@@ -251,36 +251,36 @@ export const authLoginServiceFactory = ({
}; };
const selectOrganization = async ({ const selectOrganization = async ({
userAgentHeader, userAgent,
authorizationHeader, authJwtToken,
ipAddress, ipAddress,
organizationId organizationId
}: { }: {
userAgentHeader: string | undefined; userAgent: string | undefined;
authorizationHeader: string | undefined; authJwtToken: string | undefined;
ipAddress: string; ipAddress: string;
organizationId: string; organizationId: string;
}) => { }) => {
const cfg = getConfig(); const cfg = getConfig();
if (!authorizationHeader) throw new UnauthorizedError({ name: "Authorization header is required" }); if (!authJwtToken) throw new UnauthorizedError({ name: "Authorization header is required" });
if (!userAgentHeader) throw new UnauthorizedError({ name: "user agent header is required" }); if (!userAgent) throw new UnauthorizedError({ name: "user agent header is required" });
const userAgent = userAgentHeader; // eslint-disable-next-line no-param-reassign
const authToken = authorizationHeader.slice(7); // slice of after Bearer authJwtToken = authJwtToken.replace("Bearer ", ""); // remove bearer from token
// The decoded JWT token, which contains the auth method. // The decoded JWT token, which contains the auth method.
const decodedToken = jwt.verify(authToken, cfg.AUTH_SECRET) as AuthModeJwtTokenPayload; const decodedToken = jwt.verify(authJwtToken, cfg.AUTH_SECRET) as AuthModeJwtTokenPayload;
if (!decodedToken.authMethod) throw new UnauthorizedError({ name: "Auth method not found on existing token" }); if (!decodedToken.authMethod) throw new UnauthorizedError({ name: "Auth method not found on existing token" });
const user = await userDAL.findUserEncKeyByUserId(decodedToken.userId); const user = await userDAL.findUserEncKeyByUserId(decodedToken.userId);
if (!user) throw new BadRequestError({ message: "user not found", name: "Get Me" }); if (!user) throw new BadRequestError({ message: "User not found", name: "Find user from token" });
// Check if the user actually has access to the specified organization. // Check if the user actually has access to the specified organization.
const userOrgs = await orgDAL.findAllOrgsByUserId(user.id); const userOrgs = await orgDAL.findAllOrgsByUserId(user.id);
const hasOrganizationMembership = userOrgs.some((org) => org.id === organizationId);
if (!userOrgs.some((org) => org.id === organizationId)) { if (!hasOrganizationMembership) {
throw new UnauthorizedError({ message: "User does not have access to the organization" }); throw new UnauthorizedError({ message: "User does not have access to the organization" });
} }