From 2286f5b8bc5ff8c84f6cc4665059272dbdc452d5 Mon Sep 17 00:00:00 2001 From: SanshayMaestro Date: Sun, 27 Sep 2026 19:41:58 +0100 Subject: [PATCH] nvironment variable validation with schema nvironment variable validation with schema --- src/auth/auth-session.service.ts | 12 +++++++----- src/auth/auth.module.ts | 25 +++++++++++++------------ 2 files changed, 20 insertions(+), 17 deletions(-) diff --git a/src/auth/auth-session.service.ts b/src/auth/auth-session.service.ts index 4610003675..a24d7e01cf 100644 --- a/src/auth/auth-session.service.ts +++ b/src/auth/auth-session.service.ts @@ -153,7 +153,7 @@ export class AuthSessionService { try { payload = await this.jwtService.verifyAsync( rawRefreshToken, - { secret: this.refreshSecret }, + { secret: this.refreshSecret, algorithms: ["HS256"] }, ); } catch { throw new UnauthorizedException({ @@ -305,10 +305,11 @@ export class AuthSessionService { } private get refreshSecret(): string { - return this.configService.get( - "JWT_REFRESH_SECRET", - "refresh_secret", - ); + const secret = this.configService.get("JWT_REFRESH_SECRET"); + if (!secret) { + throw new Error("JWT_REFRESH_SECRET is not configured"); + } + return secret; } /** @@ -376,6 +377,7 @@ export class AuthSessionService { this.jwtService.signAsync(refreshPayload, { secret: this.refreshSecret, expiresIn: this.sessionPolicy.refreshTokenTtl, + algorithm: "HS256", }), ]); diff --git a/src/auth/auth.module.ts b/src/auth/auth.module.ts index 6610140b9c..06f0d54484 100644 --- a/src/auth/auth.module.ts +++ b/src/auth/auth.module.ts @@ -1,12 +1,12 @@ -import { Module } from '@nestjs/common'; -import { JwtModule } from '@nestjs/jwt'; -import { ConfigModule, ConfigService } from '@nestjs/config'; -import { JwtLearnerGuard } from './guards/jwt-learner.guard'; -import { JwtTutorGuard } from './guards/jwt-tutor.guard'; -import { JwtAdminGuard } from './guards/jwt-admin.guard'; -import { RolesGuard } from './guards/roles.guard'; -import { AuthSessionService } from './auth-session.service'; -import { AuthSessionController } from './auth-session.controller'; +import { Module } from "@nestjs/common"; +import { JwtModule } from "@nestjs/jwt"; +import { ConfigModule, ConfigService } from "@nestjs/config"; +import { JwtLearnerGuard } from "./guards/jwt-learner.guard"; +import { JwtTutorGuard } from "./guards/jwt-tutor.guard"; +import { JwtAdminGuard } from "./guards/jwt-admin.guard"; +import { RolesGuard } from "./guards/roles.guard"; +import { AuthSessionService } from "./auth-session.service"; +import { AuthSessionController } from "./auth-session.controller"; @Module({ imports: [ @@ -14,13 +14,14 @@ import { AuthSessionController } from './auth-session.controller'; JwtModule.registerAsync({ imports: [ConfigModule], useFactory: (config: ConfigService) => { - const secret = config.get('JWT_SECRET'); + const secret = config.get("JWT_SECRET"); if (!secret) { - throw new Error('JWT_SECRET is not configured'); + throw new Error("JWT_SECRET is not configured"); } return { secret, - signOptions: { expiresIn: '15m' }, + signOptions: { expiresIn: "15m", algorithm: "HS256" }, + verifyOptions: { algorithms: ["HS256"] }, }; }, inject: [ConfigService],