Skip to main content

VM4: Authentication System (JWT & OAuth)

Search Valley features a custom token authentication layer alongside integration for social OAuth.

Authentication Routes​

1. Registration​

  • Route: POST /api/auth/register
  • Request: { "email": "...", "password": "..." }
  • Behavior: Hashes the password using bcryptjs (10 rounds) and generates a verification token. Sends an SMTP confirmation link to the email.

2. Email Verification​

  • Route: GET /api/auth/verify?token=...
  • Behavior: Marks the user record as verified, allowing login.

3. Login​

  • Route: POST /api/auth/login
  • Behavior: Compares password hashes and returns two tokens:
    • accessToken (JWT, 15m expiration)
    • refreshToken (JWT, 7d expiration)

4. Token Refresh​

  • Route: POST /api/auth/refresh
  • Request: { "refreshToken": "..." }
  • Behavior: Decodes the refresh token and returns new token pairs.

5. Profile Info​

  • Route: GET /api/auth/me
  • Behavior: Returns user record payload. Requires Authorization: Bearer <accessToken>.

Google & GitHub OAuth​

OAuth authentication is implemented using arctic configuration clients.

  • Google Login: redirects user authorization flow to Google.
  • Callback redirect handles authentication and creates account details, returning JWT tokens directly.
  • Frontend callback configuration variable: FRONTEND_URL in env.ts.