Files
Site-comptage-heure/lib/auth.ts

69 lines
1.8 KiB
TypeScript

import { NextAuthOptions } from 'next-auth';
import CredentialsProvider from 'next-auth/providers/credentials';
import { prisma } from './prisma';
import bcrypt from 'bcryptjs';
export const authOptions: NextAuthOptions = {
providers: [
CredentialsProvider({
name: 'credentials',
credentials: {
email: { label: 'Email', type: 'email' },
password: { label: 'Password', type: 'password' },
},
async authorize(credentials) {
if (!credentials?.email || !credentials?.password) {
return null;
}
const user = await prisma.user.findUnique({
where: { email: credentials.email },
});
if (!user) {
return null;
}
const isPasswordValid = await bcrypt.compare(
credentials.password,
user.password,
);
if (!isPasswordValid) {
return null;
}
return {
id: user.id.toString(),
email: user.email,
role: user.role,
passwordResetRequired: user.passwordResetRequired,
};
},
}),
],
session: {
strategy: 'jwt',
},
callbacks: {
async jwt({ token, user, trigger, session }) {
if (user) {
token.role = user.role;
token.passwordResetRequired = user.passwordResetRequired;
}
if (trigger === 'update' && session) {
if (typeof session.passwordResetRequired === 'boolean') {
token.passwordResetRequired = session.passwordResetRequired;
}
}
return token;
},
async session({ session, token }) {
if (token) {
session.user.id = token.sub!;
session.user.role = token.role as string;
session.user.passwordResetRequired = token.passwordResetRequired as boolean;
}
return session;
},
},
pages: {
signIn: '/login',
},
};