feat: registration and login with JWT auth

- users table: email, password_hash (bcrypt), role, is_active
- POST /auth/register — checks blocklist, hashes password, returns JWT
- POST /auth/login — verifies password, returns JWT
- Auth middleware: accepts env tokens (dev) OR valid JWTs
- end-user role → 403 Insufficient permissions on all /api/* routes
- JWT_SECRET + JWT_EXPIRES_IN env vars

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-05-21 13:04:17 +02:00
parent 5f79e76b67
commit 217aab7dcd
6 changed files with 246 additions and 6 deletions

View File

@@ -22,6 +22,9 @@ app.get('/health', async (req, res) => {
res.json({ status: 'ok', db });
});
// Public routes
app.use('/auth', require('./routes/auth'));
// Routes — protected by Bearer token
app.use('/api', auth, require('./routes/index'));
app.use('/api/pictures', auth, require('./routes/pictures'));