feat: implement postal address verification flow
This commit is contained in:
parent
09ea388190
commit
db36e75c46
3 changed files with 85 additions and 0 deletions
|
|
@ -7,6 +7,7 @@ Erster funktionaler Backend-Stand für die Vision:
|
||||||
- Angebote + Gegenangebote + Deal-Annahme (`/offers/...`)
|
- Angebote + Gegenangebote + Deal-Annahme (`/offers/...`)
|
||||||
- Bewertungsgrundlage mit 2-14 Tage Prompt-Fenster (`/reviews/:dealId`)
|
- Bewertungsgrundlage mit 2-14 Tage Prompt-Fenster (`/reviews/:dealId`)
|
||||||
- Datenmodell inkl. postalischer Adress-Verifikation (`backend/sql/schema.sql`)
|
- Datenmodell inkl. postalischer Adress-Verifikation (`backend/sql/schema.sql`)
|
||||||
|
- Address-Change-Flow mit Briefcode (`/addresses/change-request`, `/addresses/verify`)
|
||||||
|
|
||||||
## Start
|
## Start
|
||||||
|
|
||||||
|
|
|
||||||
82
backend/src/routes/addresses.js
Normal file
82
backend/src/routes/addresses.js
Normal file
|
|
@ -0,0 +1,82 @@
|
||||||
|
import { Router } from 'express';
|
||||||
|
import { createHash, randomInt } from 'crypto';
|
||||||
|
import { z } from 'zod';
|
||||||
|
import { pool } from '../db/connection.js';
|
||||||
|
import { requireAuth } from '../middleware/auth.js';
|
||||||
|
|
||||||
|
const router = Router();
|
||||||
|
|
||||||
|
const hashCode = (code) => createHash('sha256').update(code).digest('hex');
|
||||||
|
|
||||||
|
router.post('/change-request', requireAuth, async (req, res) => {
|
||||||
|
const parsed = z.object({ newAddressEncrypted: z.string().min(10) }).safeParse(req.body);
|
||||||
|
if (!parsed.success) return res.status(400).json({ error: parsed.error.flatten() });
|
||||||
|
|
||||||
|
const verificationCode = String(randomInt(100000, 999999));
|
||||||
|
const verificationCodeHash = hashCode(verificationCode);
|
||||||
|
|
||||||
|
const [result] = await pool.query(
|
||||||
|
`INSERT INTO address_change_requests (user_id, new_address_encrypted, verification_code_hash)
|
||||||
|
VALUES (?, ?, ?)`,
|
||||||
|
[req.user.userId, parsed.data.newAddressEncrypted, verificationCodeHash]
|
||||||
|
);
|
||||||
|
|
||||||
|
res.status(201).json({
|
||||||
|
requestId: result.insertId,
|
||||||
|
postalDispatch: 'pending_letter',
|
||||||
|
note: 'Verification code generated for postal letter dispatch.',
|
||||||
|
verificationCode
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
router.post('/verify', requireAuth, async (req, res) => {
|
||||||
|
const parsed = z.object({ requestId: z.number().int().positive(), code: z.string().regex(/^\d{6}$/) }).safeParse(req.body);
|
||||||
|
if (!parsed.success) return res.status(400).json({ error: parsed.error.flatten() });
|
||||||
|
|
||||||
|
const { requestId, code } = parsed.data;
|
||||||
|
|
||||||
|
const [rows] = await pool.query(
|
||||||
|
`SELECT id, user_id, new_address_encrypted, verification_code_hash, status
|
||||||
|
FROM address_change_requests
|
||||||
|
WHERE id = ? LIMIT 1`,
|
||||||
|
[requestId]
|
||||||
|
);
|
||||||
|
|
||||||
|
const request = rows[0];
|
||||||
|
if (!request) return res.status(404).json({ error: 'Request not found' });
|
||||||
|
if (request.user_id !== req.user.userId) return res.status(403).json({ error: 'Forbidden' });
|
||||||
|
if (request.status !== 'pending_letter') return res.status(409).json({ error: 'Request not pending' });
|
||||||
|
|
||||||
|
if (hashCode(code) !== request.verification_code_hash) {
|
||||||
|
return res.status(400).json({ error: 'Invalid verification code' });
|
||||||
|
}
|
||||||
|
|
||||||
|
const conn = await pool.getConnection();
|
||||||
|
try {
|
||||||
|
await conn.beginTransaction();
|
||||||
|
|
||||||
|
await conn.query(
|
||||||
|
`UPDATE address_change_requests
|
||||||
|
SET status = 'verified', verified_at = CURRENT_TIMESTAMP
|
||||||
|
WHERE id = ?`,
|
||||||
|
[requestId]
|
||||||
|
);
|
||||||
|
|
||||||
|
await conn.query(
|
||||||
|
`INSERT INTO addresses (user_id, address_encrypted, postal_verified_at)
|
||||||
|
VALUES (?, ?, CURRENT_TIMESTAMP)`,
|
||||||
|
[req.user.userId, request.new_address_encrypted]
|
||||||
|
);
|
||||||
|
|
||||||
|
await conn.commit();
|
||||||
|
} catch (err) {
|
||||||
|
await conn.rollback();
|
||||||
|
throw err;
|
||||||
|
} finally {
|
||||||
|
conn.release();
|
||||||
|
}
|
||||||
|
|
||||||
|
res.json({ status: 'verified' });
|
||||||
|
});
|
||||||
|
|
||||||
|
export default router;
|
||||||
|
|
@ -4,6 +4,7 @@ import authRoutes from './routes/auth.js';
|
||||||
import helpRequestRoutes from './routes/helpRequests.js';
|
import helpRequestRoutes from './routes/helpRequests.js';
|
||||||
import offerRoutes from './routes/offers.js';
|
import offerRoutes from './routes/offers.js';
|
||||||
import reviewRoutes from './routes/reviews.js';
|
import reviewRoutes from './routes/reviews.js';
|
||||||
|
import addressRoutes from './routes/addresses.js';
|
||||||
|
|
||||||
dotenv.config();
|
dotenv.config();
|
||||||
|
|
||||||
|
|
@ -16,6 +17,7 @@ app.use('/auth', authRoutes);
|
||||||
app.use('/requests', helpRequestRoutes);
|
app.use('/requests', helpRequestRoutes);
|
||||||
app.use('/offers', offerRoutes);
|
app.use('/offers', offerRoutes);
|
||||||
app.use('/reviews', reviewRoutes);
|
app.use('/reviews', reviewRoutes);
|
||||||
|
app.use('/addresses', addressRoutes);
|
||||||
|
|
||||||
const port = Number(process.env.PORT || 3000);
|
const port = Number(process.env.PORT || 3000);
|
||||||
app.listen(port, () => {
|
app.listen(port, () => {
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue