diff --git a/docs/docs/the-basics/coding-with-practica.md b/docs/docs/the-basics/coding-with-practica.md index 3ee4e804..61e1d6df 100644 --- a/docs/docs/the-basics/coding-with-practica.md +++ b/docs/docs/the-basics/coding-with-practica.md @@ -85,9 +85,10 @@ Now visit our [online POSTMAN collection](https://documenter.getpostman.com/view **Note:** The API routes authorize requests, a valid token must be provided. You may generate one yourself ([see here how](../questions-and-answers.md)), or just use the default _development_ token that we generated for you 👇. Put it inside an 'Authorization' header:

```Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE3MzM4NTIyMTk5NzEsImRhdGEiOnsidXNlciI6ImpvZSIsInJvbGVzIjoiYWRtaW4ifSwiaWF0IjoxNzEyMjUyMjE5fQ.kUS7AnwtGum40biJYt0oyOH_le1KfVD2EOrs-ozclY0```

We have the ground ready 🐥. Let's code now, just remember to run the tests (or POSTMAN) once in a while to ensure nothing breaks

## The 3 layers of a component

A typical component (e.g., Microservice) contains 3 main layers. This is a known and powerful pattern that is called ["3-Tiers"](https://www.techopedia.com/definition/24649/three-tier-architecture). It's an architectural structure that strikes a great balance between simplicity and robustness. Unlike other fancy architectures (e.g. hexagonal architecture, etc), this style is more likely to keep things simple and organized. The three layers represent the physical flow of a request with no abstractions: diff --git a/src/code-templates/libraries/common-fastify-plugins/lib/jwt-verifier/jwt-verifier-plugin.ts b/src/code-templates/libraries/common-fastify-plugins/lib/jwt-verifier/jwt-verifier-plugin.ts index 35c3299e..5af95cd8 100644 --- a/src/code-templates/libraries/common-fastify-plugins/lib/jwt-verifier/jwt-verifier-plugin.ts +++ b/src/code-templates/libraries/common-fastify-plugins/lib/jwt-verifier/jwt-verifier-plugin.ts @@ -46,6 +46,7 @@ const verifyTokenOnRequest = ( let token: string; // A token comes in one of two forms: 'token' or 'Bearer token' const authHeaderParts = authenticationHeader.split(' '); + if (authHeaderParts.length > 2) { // It should have 1 or 2 parts (separated by space), the incoming string has unknown structure return { success: false }; diff --git a/src/code-templates/libraries/error-handling/error-handler.ts b/src/code-templates/libraries/error-handling/error-handler.ts index 6a667c81..62c91005 100644 --- a/src/code-templates/libraries/error-handling/error-handler.ts +++ b/src/code-templates/libraries/error-handling/error-handler.ts @@ -33,6 +33,7 @@ export const errorHandler = { handleError: (errorToHandle: unknown): number => { try { + logger.info('Handling error1'); const appError: AppError = covertUnknownToAppError(errorToHandle); logger.error(appError.message, appError); metricsExporter.fireMetric('error', { errorName: appError.name }); // fire any custom metric when handling error diff --git a/src/code-templates/libraries/error-handling/fastify-error-middleware.ts b/src/code-templates/libraries/error-handling/fastify-error-middleware.ts index c92df727..4e31f683 100644 --- a/src/code-templates/libraries/error-handling/fastify-error-middleware.ts +++ b/src/code-templates/libraries/error-handling/fastify-error-middleware.ts @@ -10,6 +10,5 @@ export function fastifyErrorMiddleware( const standardAppError = covertUnknownToAppError(error); standardAppError.isCatastrophic = false; const responseToRequest = errorHandler.handleError(standardAppError); - reply.status(responseToRequest).send({}); } diff --git a/src/code-templates/libraries/error-handling/package.json b/src/code-templates/libraries/error-handling/package.json index 1e6382fd..1374c9d5 100644 --- a/src/code-templates/libraries/error-handling/package.json +++ b/src/code-templates/libraries/error-handling/package.json @@ -25,10 +25,12 @@ "typescript": "^5.2.2" }, "dependencies": { - "@practica/logger": "^0.0.1-alpha.4", + "@practica/logger": "^0.0.5", "jest": "^28.1.0", "jest-sinon": "^1.0.4", - "sinon": "^14.0.0", + "sinon": "^14.0.0" + }, + "peerDependencies": { "fastify": "4.24.3" } } diff --git a/src/code-templates/libraries/jwt-token-verifier/.npmignore b/src/code-templates/libraries/jwt-token-verifier/.npmignore deleted file mode 100644 index e69de29b..00000000 diff --git a/src/code-templates/libraries/jwt-token-verifier/index.ts b/src/code-templates/libraries/jwt-token-verifier/index.ts deleted file mode 100644 index 1e0b7a7c..00000000 --- a/src/code-templates/libraries/jwt-token-verifier/index.ts +++ /dev/null @@ -1 +0,0 @@ -export * from './lib/jwt-verifier-middleware'; diff --git a/src/code-templates/libraries/jwt-token-verifier/lib/jwt-verifier-middleware.ts b/src/code-templates/libraries/jwt-token-verifier/lib/jwt-verifier-middleware.ts deleted file mode 100644 index df7ff3db..00000000 --- a/src/code-templates/libraries/jwt-token-verifier/lib/jwt-verifier-middleware.ts +++ /dev/null @@ -1,52 +0,0 @@ -/* eslint-disable consistent-return */ -import jwt, { VerifyErrors } from 'jsonwebtoken'; - -export type JWTOptions = { - secret: string; -}; - -export const jwtVerifierMiddleware = (options: JWTOptions) => { - // 🔒 TODO - Once your project is off a POC stage, change your JWT flow to async using JWKS - // Read more here: https://www.npmjs.com/package/jwks-rsa - const middleware = (req, res, next) => { - const authenticationHeader = - req.headers.authorization || req.headers.Authorization; - - if (!authenticationHeader) { - return res.sendStatus(401); - } - - let token: string; - - // A token comes in one of two forms: 'token' or 'Bearer token' - const authHeaderParts = authenticationHeader.split(' '); diff --git a/src/code-templates/libraries/jwt-token-verifier/package/lib/index.ts b/src/code-templates/libraries/jwt-token-verifier/package/lib/index.ts deleted file mode 100644 index d596e80d..00000000 --- a/src/code-templates/libraries/jwt-token-verifier/package/lib/index.ts +++ /dev/null @@ -1 +0,0 @@ -export * from './jwt-verifier-middleware'; diff --git a/src/code-templates/libraries/jwt-token-verifier/package/lib/jwt-verifier-middleware.ts b/src/code-templates/libraries/jwt-token-verifier/package/lib/jwt-verifier-middleware.ts deleted file mode 100644 index eef09eae..00000000 --- a/src/code-templates/libraries/jwt-token-verifier/package/lib/jwt-verifier-middleware.ts +++ /dev/null @@ -1,55 +0,0 @@ -/* eslint-disable consistent-return */ -import jwt, { VerifyErrors } from 'jsonwebtoken'; - -export type JWTOptions = { - secret: string; -}; - -export const jwtVerifierMiddleware = (options: JWTOptions) => { - // 🔒 TODO - Once your project is off a POC stage, change your JWT flow to async using JWKS - // Read more here: https://www.npmjs.com/package/jwks-rsa - const middleware = (req, res, next) => { - const authenticationHeader = - req.headers.authorization || req.headers.Authorization; - - if (!authenticationHeader) { - return res.sendStatus(401); - } - - let token: string; - - // A token comes in one of two forms: 'token' or 'Bearer token' - const authHeaderParts = authenticationHeader.split(' '); - if (authHeaderParts.length > 2) { - // It should have 1 or 2 parts (separated by space), the incoming string is not supported - return res.sendStatus(401); - } - - if (authHeaderParts.length === 2) { - [, token] = authHeaderParts; - } else { - token = authenticationHeader; - } - - jwt.verify( - token, - options.secret, - // TODO: we should remove this any according to the library, jwtContent can not contain data property - // eslint-disable-next-line @typescript-eslint/no-explicit-any - (err: VerifyErrors | null, jwtContent: any) => { - // @todo: use logger and error handler here - // eslint-disable-next-line no-console - console.log(err); - - if (err) { - return res.sendStatus(401); - } - - req.user = jwtContent.data; - - next(); - } - ); - }; - return middleware; -}; diff --git a/src/code-templates/libraries/jwt-token-verifier/package/test/jwt-helper.ts b/src/code-templates/libraries/jwt-token-verifier/package/test/jwt-helper.ts deleted file mode 100644 index 4069aa0b..00000000 --- a/src/code-templates/libraries/jwt-token-verifier/package/test/jwt-helper.ts +++ /dev/null @@ -1,30 +0,0 @@ -import jwt from 'jsonwebtoken'; This only applies when targeting `react` JSX emit. */ - // "noLib": true, /* Disable including any library files, including the default lib.d.ts. */ - // "useDefineForClassFields": true, /* Emit ECMAScript-standard-compliant class fields. */ - - /* Modules */ - "module": "commonjs" /* Specify what module code is generated. */, - // "rootDir": "./", /* Specify the root folder within your source files. */ - // "moduleResolution": "node", /* Specify how TypeScript looks up a file from a given module specifier. */ - // "baseUrl": "./", /* Specify the base directory to resolve non-relative module names. */ - // "paths": {}, /* Specify a set of entries that re-map imports to additional lookup locations. */ - // "rootDirs": [], /* Allow multiple folders to be treated as one when resolving modules. */ - // "typeRoots": [], /* Specify multiple folders that act like `./node_modules/@types`. */ - // "types": [], /* Specify type package names to be included without being referenced in a source file. */ - // "allowUmdGlobalAccess": true, /* Allow accessing UMD globals from modules. */ - // "resolveJsonModule": true, /* Enable importing .json files */ - // "noResolve": true, /* Disallow `import`s, `require`s or ``s from expanding the number of files TypeScript should add to a project. */ - - /* JavaScript Support */ - // "allowJs": true, /* Allow JavaScript files to be a part of your program. Use the `checkJS` option to get errors from these files. */ - // "checkJs": true, /* Enable error reporting in type-checked JavaScript files. */ - // "maxNodeModuleJsDepth": 1, /* Specify the maximum folder depth used for checking JavaScript files from `node_modules`. Only applicable with `allowJs`. */ - - /* Emit */ - // "declaration": true, /* Generate .d.ts files from TypeScript and JavaScript files in your project. */ - // "declarationMap": true, /* Create sourcemaps for d.ts files. */ - // "emitDeclarationOnly": true, /* Only output d.ts files and not JavaScript files. */ - // "sourceMap": true, /* Create source map files for emitted JavaScript files. */ - // "outFile": "./", /* Specify a file that bundles all outputs into one JavaScript file. If `declaration` is true, also designates a file that bundles all .d.ts output. */ - "outDir": "./.dist" /* Specify an output folder for all emitted files. */, - // "removeComments": true, /* Disable emitting comments. */ - // "noEmit": true, /* Disable emitting files from a compilation. */ - // "importHelpers": true, /* Allow importing helper functions from tslib once per project, instead of including them per-file. */ - // "importsNotUsedAsValues": "remove", /* Specify emit/checking behavior for imports that are only used for types */ - // "downlevelIteration": true, /* Emit more compliant, but verbose and less performant JavaScript for iteration. */ - // "sourceRoot": "", /* Specify the root path for debuggers to find the reference source code. */ - // "mapRoot": "", /* Specify the location where debugger should locate map files instead of generated locations. */ - // "inlineSourceMap": true, /* Include sourcemap files inside the emitted JavaScript. */ - // "inlineSources": true, /* Include source code in the sourcemaps inside the emitted JavaScript. */ - // "emitBOM": true, /* Emit a UTF-8 Byte Order Mark (BOM) in the beginning of output files. */ - // "newLine": "crlf", /* Set the newline character for emitting files. */ - // "stripInternal": true, /* Disable emitting declarations that have `@internal` in their JSDoc comments. */ - // "noEmitHelpers": true, /* Disable generating custom helper functions like `__extends` in compiled output. */ - // "noEmitOnError": true, /* Disable emitting files if any type checking errors are reported. */ - // "preserveConstEnums": true, /* Disable erasing `const enum` declarations in generated code. */ - // "declarationDir": "./", /* Specify the output directory for generated declaration files. */ - - /* Interop Constraints */ - // "isolatedModules": true, /* Ensure that each file can be safely transpiled without relying on other imports. */ - // "allowSyntheticDefaultImports": true, /* Allow 'import x from y' when a module doesn't have a default export. */ - "esModuleInterop": true /* Emit additional JavaScript to ease support for importing CommonJS modules. This enables `allowSyntheticDefaultImports` for type compatibility. */, - // "preserveSymlinks": true, /* Disable resolving symlinks to their realpath. This correlates to the same flag in node. */ - "forceConsistentCasingInFileNames": true /* Ensure that casing is correct in imports. */, - - /* Type Checking */ - "strict": true /* Enable all strict type-checking options. */, - "noImplicitAny": false /* Enable error reporting for expressions and declarations with an implied `any` type.. */, - // "strictNullChecks": true, /* When type checking, take into account `null` and `undefined`. */ - // "strictFunctionTypes": true, /* When assigning functions, check to ensure parameters and the return values are subtype-compatible. */ - // "strictBindCallApply": true, /* Check that the arguments for `bind`, `call`, and `apply` methods match the original function. */ - // "strictPropertyInitialization": true, /* Check for class properties that are declared but not set in the constructor. */ - // "noImplicitThis": true, /* Enable error reporting when `this` is given the type `any`. */ - // "useUnknownInCatchVariables": true, /* Type catch clause variables as 'unknown' instead of 'any'. */ - // "alwaysStrict": true, /* Ensure 'use strict' is always emitted. */ - // "noUnusedLocals": true, /* Enable error reporting when a local variables aren't read. */ - // "noUnusedParameters": true, /* Raise an error when a function parameter isn't read */ - // "exactOptionalPropertyTypes": true, /* Interpret optional property types as written, rather than adding 'undefined'. */ - // "noImplicitReturns": true, /* Enable error reporting for codepaths that do not explicitly return in a function. */ - // "noFallthroughCasesInSwitch": true, /* Enable error reporting for fallthrough cases in switch statements. */ - // "noUncheckedIndexedAccess": true, /* Include 'undefined' in index signature results */ - // "noImplicitOverride": true, /* Ensure overriding members in derived classes are marked with an override modifier. */ - // "noPropertyAccessFromIndexSignature": true, /* Enforces using indexed accessors for keys declared using an indexed type */ - // "allowUnusedLabels": true, /* Disable error reporting for unused labels. */ - // "allowUnreachableCode": true, /* Disable error reporting for unreachable code. */ - - /* Completeness */ - // "skipDefaultLibCheck": true, /* Skip type checking .d.ts files that are included with TypeScript. */ - "skipLibCheck": true /* Skip type checking all .d.ts files. */ - } -} diff --git a/src/code-templates/libraries/logger/index.ts b/src/code-templates/libraries/logger/index.ts index 2d2d3245..0d2d44b5 100644 --- a/src/code-templates/libraries/logger/index.ts +++ b/src/code-templates/libraries/logger/index.ts @@ -7,7 +7,6 @@ export class LoggerWrapper implements Logger { #getInitializeLogger(): Logger { this.configureLogger({}, false); - // eslint-disable-next-line @typescript-eslint/no-non-null-assertion return this.#underlyingLogger!; } diff --git a/src/code-templates/libraries/logger/package.json b/src/code-templates/libraries/logger/package.json index 8b6b7108..dc83b69e 100644 --- a/src/code-templates/libraries/logger/package.json +++ b/src/code-templates/libraries/logger/package.json @@ -1,8 +1,8 @@ { "name": "@practica/logger", - @practica/logger": "^0.0.5",
    "@practica/validation": "^0.0.3",
    "@prisma/client": "^4.6.1",
    "@sinclair/typebox": "^0.31.28", @practica/logger": "^0.0.5",
    "@practica/validation": "^0.0.3",
    "@prisma/client": "^4.6.1",
    "@sinclair/typebox": "^0.31.28",

export function signValidTokenWithDefaultUser() {
  return internalSignTokenSynchronously(
    'joe',
    'admin',
    Date.now() + 60 * 60 * 60 * 100000
  );
}

export function signValidToken(user, role) {

function internalSignTokenSynchronously(user, roles, expirationInUnixTime) {
  const token = jwt.sign(
    {
      exp: expirationInUnixTime,
      data: {
        user,
        roles,
      },
    },
    exampleSecret
  );

  return token;
}

export const exampleSecret = 'just-a-default-secret';