Verification Results

Last updated

This page explains what the three flags of the VerifyResult returned by VerifyJWT() mean, and which values each scenario produces.

Shape

interface VerifyResult {
  data?: AuthData;
  isAuth: boolean;
  isError: boolean;
  isGuest: boolean;
}
Flag Meaning
isAuth Verification succeeded; data holds the user
isError The request looks suspicious (fingerprint mismatch, bad signature); respond with 400
isGuest Not logged in; always true when isAuth is false

Scenario Table

Scenario isAuth isError isGuest
Valid Access Token, fingerprint matches true false false
Access Token expired, refresh succeeded true false false
No Access Token and no Refresh ID false false true
Access Token on the revocation blacklist false false true
checkUserExists() returned false false false true
Refresh data fingerprint mismatch false false true
Access Token fingerprint mismatch false true true
Invalid signature or malformed token false true true
Refresh data missing false true true

Routing on the Result

import { NextFunction, Request, Response } from "express";
import { JWTAuth } from "@pardnchiu/jwt-auth";

export async function requireAuth(req: Request, res: Response, next: NextFunction) {
  try {
    const result = await JWTAuth.VerifyJWT(req, res);
    if (result.isAuth) {
      res.locals.user = result.data;
      return next();
    }
    res.status(result.isError ? 400 : 401).json({
      error: result.isError ? "Bad Request" : "Unauthorized",
    });
  } catch (err) {
    // Reached only when init() was never called
    res.status(500).json({ error: (err as Error).message });
  }
}

Legacy Return Values

Older VerifyJWT() versions returned AuthData or the status codes 400 / 401. JWTAuth.GetAuth() converts those into the same three-flag shape:

Input Output
AuthData { ...data, isAuth: true, isError: false, isGuest: false }
401 { isAuth: false, isError: false, isGuest: true }
400 { isAuth: false, isError: true, isGuest: true }

Related: Refresh Token Rotation, Device Fingerprint

中文