4b05627f3d
- Create UserService with findByUsername (unscoped), create, update, deactivate, delete - Create AdminSeedService that seeds Super-Admin from Docker ENV on bootstrap (D-05/D-07/D-13) - Create TenantService with findAll, findById, create, update - Create TenantMiddleware extracting tenantId from JWT with Super-Admin tenant switching (D-08/D-10) - Wire PrismaModule, AuthModule, UserModule, TenantModule into AppModule - Register JwtAuthGuard and RolesGuard as global APP_GUARD providers - Apply TenantMiddleware to all routes via NestModule.configure - Add @Public() decorator to HealthController for unauthenticated access
91 lines
2.0 KiB
TypeScript
91 lines
2.0 KiB
TypeScript
import { Injectable } from '@nestjs/common';
|
|
import * as argon2 from 'argon2';
|
|
import { PrismaService } from '../prisma/prisma.service';
|
|
|
|
@Injectable()
|
|
export class UserService {
|
|
constructor(private prisma: PrismaService) {}
|
|
|
|
/**
|
|
* Find user by username. Uses UNSCOPED Prisma (not tenant-scoped)
|
|
* because login must work across all tenants.
|
|
*/
|
|
async findByUsername(username: string) {
|
|
return this.prisma.user.findUnique({ where: { username } });
|
|
}
|
|
|
|
/**
|
|
* Find user by ID.
|
|
*/
|
|
async findById(id: string) {
|
|
return this.prisma.user.findUnique({ where: { id } });
|
|
}
|
|
|
|
/**
|
|
* Create a new user with hashed password.
|
|
*/
|
|
async create(data: {
|
|
username: string;
|
|
email: string;
|
|
password?: string;
|
|
displayName?: string;
|
|
role?: 'SUPER_ADMIN' | 'ADMIN' | 'USER';
|
|
tenantId: string;
|
|
mustChangePassword?: boolean;
|
|
ldapDn?: string;
|
|
}) {
|
|
const { password, ...rest } = data;
|
|
return this.prisma.user.create({
|
|
data: {
|
|
...rest,
|
|
passwordHash: password ? await argon2.hash(password) : null,
|
|
},
|
|
});
|
|
}
|
|
|
|
/**
|
|
* Update user. If password is provided, hash it.
|
|
*/
|
|
async update(
|
|
id: string,
|
|
data: {
|
|
username?: string;
|
|
email?: string;
|
|
password?: string;
|
|
displayName?: string;
|
|
role?: 'SUPER_ADMIN' | 'ADMIN' | 'USER';
|
|
isActive?: boolean;
|
|
mustChangePassword?: boolean;
|
|
},
|
|
) {
|
|
const { password, ...rest } = data;
|
|
const updateData: any = { ...rest };
|
|
|
|
if (password) {
|
|
updateData.passwordHash = await argon2.hash(password);
|
|
}
|
|
|
|
return this.prisma.user.update({
|
|
where: { id },
|
|
data: updateData,
|
|
});
|
|
}
|
|
|
|
/**
|
|
* Deactivate a user (soft delete).
|
|
*/
|
|
async deactivate(id: string) {
|
|
return this.prisma.user.update({
|
|
where: { id },
|
|
data: { isActive: false },
|
|
});
|
|
}
|
|
|
|
/**
|
|
* Hard delete a user.
|
|
*/
|
|
async delete(id: string) {
|
|
return this.prisma.user.delete({ where: { id } });
|
|
}
|
|
}
|