feat(auth): reject login and invalidate token for blocked users
Checks is_active on email login, phone OTP login, and /auth/me so existing tokens also stop working immediately after a user is blocked. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
a8842a2728
commit
4d98c7cb70
@@ -34,6 +34,8 @@ export class AuthService {
|
|||||||
const valid = await bcrypt.compare(password, user.password_hash);
|
const valid = await bcrypt.compare(password, user.password_hash);
|
||||||
if (!valid) throw new UnauthorizedException('Credenciales inválidas');
|
if (!valid) throw new UnauthorizedException('Credenciales inválidas');
|
||||||
|
|
||||||
|
if (user.is_active === false) throw new UnauthorizedException('Tu cuenta ha sido bloqueada');
|
||||||
|
|
||||||
return this.generateToken(user);
|
return this.generateToken(user);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -51,6 +53,7 @@ export class AuthService {
|
|||||||
data: { phone, name: name || phone, is_phone_verified: true },
|
data: { phone, name: name || phone, is_phone_verified: true },
|
||||||
});
|
});
|
||||||
} else {
|
} else {
|
||||||
|
if (user.is_active === false) throw new UnauthorizedException('Tu cuenta ha sido bloqueada');
|
||||||
user = await this.prisma.users.update({
|
user = await this.prisma.users.update({
|
||||||
where: { id: user.id },
|
where: { id: user.id },
|
||||||
data: { is_phone_verified: true },
|
data: { is_phone_verified: true },
|
||||||
@@ -107,6 +110,7 @@ export class AuthService {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
if (!user) throw new UnauthorizedException('Usuario no encontrado');
|
if (!user) throw new UnauthorizedException('Usuario no encontrado');
|
||||||
|
if (user.is_active === false) throw new UnauthorizedException('Tu cuenta ha sido bloqueada');
|
||||||
return { ...user, professional_state: user.pro_state };
|
return { ...user, professional_state: user.pro_state };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user