VM4: Authentication System (JWT & OAuth)
Search Valley features a custom token authentication layer alongside integration for social OAuth.
Authentication Routes
1. Registration
- Route:
POST /api/auth/register - Request:
{ "email": "...", "password": "..." } - Behavior: Hashes the password using
bcryptjs(10 rounds) and generates a verification token. Sends an SMTP confirmation link to the email.
2. Email Verification
- Route:
GET /api/auth/verify?token=... - Behavior: Marks the user record as verified, allowing login.
3. Login
- Route:
POST /api/auth/login - Behavior: Compares password hashes and returns two tokens:
accessToken(JWT, 15m expiration)refreshToken(JWT, 7d expiration)
4. Token Refresh
- Route:
POST /api/auth/refresh - Request:
{ "refreshToken": "..." } - Behavior: Decodes the refresh token and returns new token pairs.
5. Profile Info
- Route:
GET /api/auth/me - Behavior: Returns user record payload. Requires
Authorization: Bearer <accessToken>.
Google & GitHub OAuth
OAuth authentication is implemented using arctic configuration clients.
- Google Login: redirects user authorization flow to Google.
- Callback redirect handles authentication and creates account details, returning JWT tokens directly.
- Frontend callback configuration variable:
FRONTEND_URLin env.ts.