feat(api): invalidate sessions on user deactivation (MS21-AUTH-004)
Some checks failed
ci/woodpecker/push/api Pipeline failed
Some checks failed
ci/woodpecker/push/api Pipeline failed
This commit is contained in:
@@ -192,19 +192,22 @@ export class AdminService {
|
|||||||
throw new BadRequestException(`User ${id} is already deactivated`);
|
throw new BadRequestException(`User ${id} is already deactivated`);
|
||||||
}
|
}
|
||||||
|
|
||||||
const user = await this.prisma.user.update({
|
const [user] = await this.prisma.$transaction([
|
||||||
where: { id },
|
this.prisma.user.update({
|
||||||
data: { deactivatedAt: new Date() },
|
where: { id },
|
||||||
include: {
|
data: { deactivatedAt: new Date() },
|
||||||
workspaceMemberships: {
|
include: {
|
||||||
include: {
|
workspaceMemberships: {
|
||||||
workspace: { select: { id: true, name: true } },
|
include: {
|
||||||
|
workspace: { select: { id: true, name: true } },
|
||||||
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
}),
|
||||||
});
|
this.prisma.session.deleteMany({ where: { userId: id } }),
|
||||||
|
]);
|
||||||
|
|
||||||
this.logger.log(`User deactivated: ${id}`);
|
this.logger.log(`User deactivated and sessions invalidated: ${id}`);
|
||||||
|
|
||||||
return {
|
return {
|
||||||
id: user.id,
|
id: user.id,
|
||||||
|
|||||||
Reference in New Issue
Block a user