All files / server/api/auth register.post.ts

100% Statements 30/30
80% Branches 12/15
100% Functions 0/0
100% Lines 30/30

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 311x 8x 8x 8x 8x 8x 8x 3x 3x 3x 8x 1x 1x 1x 8x 2x 2x 2x 2x 2x 8x 1x 1x 1x 1x 1x 1x 1x 1x 1x  
export default defineEventHandler(async event => {
    const body = await readBody(event);
    const email = String(body.email || "").trim().toLowerCase();
    const firstName = String(body.firstName || "").trim();
    const lastName = String(body.lastName || "").trim();
    const password = String(body.password || "");
    if (!firstName || firstName.length > 80 || !lastName || lastName.length > 80) throw createError({
        statusCode: 400,
        statusMessage: "Le prénom et le nom sont obligatoires"
    });
    if (!/^[^\s@]+@[^\s@]+\.[^\s@]+$/.test(email)) throw createError({
        statusCode: 400,
        statusMessage: "Adresse e-mail invalide"
    });
    if (password.length < 10 || password.length > 128) throw createError({
        statusCode: 400,
        statusMessage: "Le mot de passe doit contenir au moins 10 caractères"
    });
    const db = database(event);
    await ready(db);
    if (await db.prepare("SELECT id FROM users WHERE email=?").bind(email).first()) throw createError({
        statusCode: 409,
        statusMessage: "Un compte existe déjà avec cette adresse"
    });
    await db.prepare("INSERT INTO users(email,first_name,last_name,password_hash,role,active,must_change_password,created_at) VALUES(?,?,?,?,?,1,0,?)").bind(email, firstName, lastName, await hashPassword(password), "customer", new Date().toISOString()).run();
    const user = await db.prepare("SELECT id,email,role FROM users WHERE email=?").bind(email).first<any>();
    await signSession(event, user);
    setResponseStatus(event, 201);
    return {user: {id: user.id, email: user.email, role: user.role}};
});