{"_id":"mail-passify","_rev":"33-0a91869e4a0419662aba69661273fe8b","name":"mail-passify","dist-tags":{"latest":"3.0.0","beta":"3.2.2-beta.0"},"versions":{"0.0.1":{"name":"mail-passify","version":"0.0.1","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.js","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"dotenv":"^16.3.1","express":"^4.18.2","mongoose":"^7.5.0","sendgrid":"^5.2.3"},"_id":"mail-passify@0.0.1","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-2MX692KF9lkGVVrIH1XAMxPl/QfsT4Z7FkTQ6J/htjTAxyapE2ZmBeGQ3lifi0r/cMQsJaIEaDRr3fj+0JvJKg==","shasum":"891a0388423950a08042b06ae706a58650c22740","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-0.0.1.tgz","fileCount":2,"unpackedSize":747,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIH/PVLsFvbH085JWlzXtHOoKJ+j+tOLuF9sxlWnsY4V0AiEA+dJjKMNetUTlnpsNPYy4a49YBdEWH8KBfiC1w2wt+SQ="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_0.0.1_1693553904884_0.37885854176752964"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.0.1-beta.0":{"name":"mail-passify","version":"0.0.1-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.js","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.js"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","mongoose":"^7.5.0","randomstring":"^1.3.0"},"bin":{"generating-config-json-file":"stubs/config-generator.js"},"readme":"# What Is Mail-Passify?\r\n\r\nNote:- This is currently in beta, please refrain from using this in your main projects.\r\n\r\n## Deme Link:-\r\n\r\nTo test a demo before using this, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo]()\r\n\r\n## # Overview\r\n\r\nMail-Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB for now.\r\n\r\n## # Features\r\n\r\n- ✅ Sign-Up With Two-Step Verification.\r\n- ✅ Sign-In With Two-Step Verification.\r\n- ✅ Resend OTP.\r\n- ✅ OTP Limits.\r\n- ✅ Forgot Password With Two-Step Verification.\r\n- ✅ Auto User Session Checking.\r\n- ✅ Logout From Current Device.\r\n- ✅ Logout From All Devices.\r\n- ✅ Referral System.\r\n- ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n- ❌ Unlock The Locked User Account (User + Auto).\r\n\r\n## # More Features To Be Added Later\r\n\r\n* Add Phone Number In Accounts Model With Verification.\r\n* Change/Update User Info.\r\n* Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\n```js\r\nnpm i mail-passify cookies-next\r\n```\r\n\r\n2. Create the configuration file:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n3. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n4. Include and configure the following in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nconst { signup } = require(\"mail-passify\");\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nconst { signUpVerify } = require(\"mail-passify\");\r\nconst response = await signUpVerify(userName, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nconst { signin } = require(\"mail-passify\");\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, they will receive an OTP on their registered email. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nIf the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n};\r\n```\r\n\r\nAs we did above, store the userName and token in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nconst { signInVerify } = require(\"mail-passify\");\r\nconst response = await signInVerify(userName, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Login Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `AuthSignInCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nconst { autoSignIn } = require(\"mail-passify\");\r\nconst response = await autoSignIn(userName, userToken);\r\n// Note:- IP will be automatically fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are any doubts, please direct them to the login page and advise them to clear their cookies from their browser. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 204,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. Logout Current Session Only: The user gets logged out only from the current device.\r\n2. Logout All Sessions: The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst tokenCookie = getCookie('token');\r\nconst data = { userNameCookie, tokenCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nconst { logoutOnce } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, tokenCookie)\r\n```\r\n\r\nOnce the user's session is deleted, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userName');\r\ndeleteCookie('token');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nconst { logoutAll } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, tokenCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nconst { forgotPassword } = require(\"mail-passify\");\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n","readmeFilename":"README.md","gitHead":"834bcfa9bf81d55c184b87dacfc1b12942d77bfb","_id":"mail-passify@0.0.1-beta.0","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-k8S4oodCjZJV42yM32EAmTbr2icw/Y1oNSkqXq6+WojuM/vMA4Zqx40GhyQq4boarC0cHNmFyrUaw519yXlblA==","shasum":"28c6085325a11d6dc45d94dedf660052593d05d3","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-0.0.1-beta.0.tgz","fileCount":23,"unpackedSize":57075,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEYPVvPTxmkuyZfbXpKFRPEU0YUJdoLfirdmme0cM6nzAiEA1LH0dgBXPeplNHO+i5kdrrLro+xuB4RMQ3QUgEzM/ig="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_0.0.1-beta.0_1695389896542_0.7937162772244042"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"1.0.0":{"name":"mail-passify","version":"1.0.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.js","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.js"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","mongoose":"^7.5.0","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.js"},"gitHead":"208018262f9c7e4ce8e3be5e17c4726e7a270e18","_id":"mail-passify@1.0.0","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-jLL6PgGMZNX0HSjXNPtbgp6NFbxltlTLUTLg6HnGSVXuTc3UohtUphF9twZ77Lrtl/YM3sSV47pyDbSKg3uB/A==","shasum":"7118b54dfe1a383fc33f0d498744631cff5169cd","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-1.0.0.tgz","fileCount":23,"unpackedSize":57685,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCHWhHWcmvwSO1m/20GP9ZhA+BPLSiYrk25FGZHhd8dMQIhALeuvpKHm4ahsQ8RsT4QKjT1U6mn5KVz2d/HNn9wSp1k"}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_1.0.0_1695393623376_0.9474536765947723"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0":{"name":"mail-passify","version":"2.0.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.js","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.js"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.5.0","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.js"},"gitHead":"59b0d206a89ef01e657dd046c54004b628e3b1bd","_id":"mail-passify@2.0.0","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-cIYat1W/lRrqzduE82kR/JdUMPubU48uUge/3XrvmWNKsafjPF8KUZOlK45D8ju8dyvbTnGPIPGHnCKPlVQbTw==","shasum":"353e31352149c2aa11233274a7c07e6051fd2cca","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-2.0.0.tgz","fileCount":23,"unpackedSize":74980,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCKknaEjFMcsesRmzeJPUbzELOKY1yvi05a5FmFWRZKjAIgcic4H86SfsnbHWl1jV40N8DMbxH61M/+wbUBda3L8rk="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_2.0.0_1697138249931_0.9901624959664423"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.1":{"name":"mail-passify","version":"2.0.1","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.js","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.js"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.5.0","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.js"},"gitHead":"e55d311970988e9c0a5c7ab163756415101c04c2","_id":"mail-passify@2.0.1","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-WMCBNb7uQ/78SXKCyoYtpe4SPvrxZSljsTX2LDtSdKuST7x2TQsx4kDfkQvtDjwUy8oLMLyeH3VRBRyg4zltWA==","shasum":"abcee53b5f446bbd26cc5f8346f985f14549ce78","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-2.0.1.tgz","fileCount":24,"unpackedSize":242484,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAYgVQ8KorXQsXiAS72Om6t0TiGjauyiQj84sGPHWvSIAiAgJ9hvxDE6/beV02hLFM+vrsH+mCBUeMqZCSeaB5BEhg=="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_2.0.1_1697253679712_0.3370684624134306"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.0-beta.0":{"name":"mail-passify","version":"3.0.0-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^1.0.0-beta.0","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"readme":"# What Is Mail-Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v2.0.0](https://github.com/Capta1nRaj/mail-passify/tree/v2.0.0)\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0](https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0)\r\n\r\n## # Overview\r\n\r\nMail-Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v2.0.0\r\n\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#3-sign-in-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Compatibility With Next.js.\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/server, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies.\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n3. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n4. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n5. Include and configure the following in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nconst { signup } = require(\"mail-passify\");\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nconst { signUpVerify } = require(\"mail-passify\");\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nconst { signin } = require(\"mail-passify\");\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('token', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nconst { signInVerify } = require(\"mail-passify\");\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nconst { autoSignIn } = require(\"mail-passify\");\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nconst { logoutOnce } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nconst { logoutAll } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nconst { forgotPassword } = require(\"mail-passify\");\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to send OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁","readmeFilename":"README.md","gitHead":"ea596e0a6f8684f7d34f749d427ef22e8dee617f","_id":"mail-passify@3.0.0-beta.0","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-1EcOyS4u5WkLI53abwaiJglC4tyoekfu+xYbPUzyONTypgNrx4GZVSbAd/l+IPYqSfLtN1zHyWQZ1jbueVTSZw==","shasum":"f496cf342f2cb86a3f4c90bfb17b4071f635dee7","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.0-beta.0.tgz","fileCount":25,"unpackedSize":242798,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDHY2w/vak0mQExfvzGO1HZ9p9Fa66amp/wxrsZQrSSUwIhAOlEvYDae7l+8s+lp/jsmdbhCA10TxOhp/PDimBfCGCV"}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.0-beta.0_1697314124389_0.7002818107599096"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.2":{"name":"mail-passify","version":"2.0.2","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"gitHead":"ea596e0a6f8684f7d34f749d427ef22e8dee617f","_id":"mail-passify@2.0.2","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-yoUOzrmWahXgJBA5onffqmlwLovCanqOjWxjRs07Nqfn1gWyvxI0dE9TxKqiFjBjlCdvPdST/iKsexORIXZegA==","shasum":"842a61f3ff0341d4a09e73597927dfdf9176c89e","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-2.0.2.tgz","fileCount":25,"unpackedSize":242784,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDKjc7SrXFS3ptOZ51o0hmN0FS+5whcMClKgD1JpxCGzgIhALiiXMaC1AC/ZdYuEGxhWtBiNxVuXImPApIzWCHIQxQO"}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_2.0.2_1697314224705_0.4420174700732762"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.1-beta.0":{"name":"mail-passify","version":"3.0.1-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.0.1-beta.0","readme":"# What Is Mail-Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v2.0.0](https://github.com/Capta1nRaj/mail-passify/tree/v2.0.0)\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0](https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0)\r\n\r\n## # Overview\r\n\r\nMail-Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v2.0.0\r\n\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#3-sign-in-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Compatibility With Next.js.\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/server, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies.\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n3. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n4. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n5. Include and configure the following in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nconst { signup } = require(\"mail-passify\");\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nconst { signUpVerify } = require(\"mail-passify\");\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nconst { signin } = require(\"mail-passify\");\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('token', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nconst { signInVerify } = require(\"mail-passify\");\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nconst { autoSignIn } = require(\"mail-passify\");\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nconst { logoutOnce } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nconst { logoutAll } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nconst { forgotPassword } = require(\"mail-passify\");\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to send OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁","readmeFilename":"README.md","gitHead":"9136cc30253759fc8c0fb443530d95401244ce64","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-mSRPmWU1VL3Ic7o78UtERIxTcjmyyYsOa3F51+A19nm7o/ULUiTQJq8u44WKjETZ7giwk4tyLJSvxZJYW0j81Q==","shasum":"d99dc799383fe867c8722c83e97d80bbf3406230","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.1-beta.0.tgz","fileCount":26,"unpackedSize":246916,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDeYt0AsWDhj7E6In9BfU2nlp78CwXzzqDxn2DsNh0rGwIgQ9gQKyxKjd8t/kXw+ILUQ3KTA7v8XaLPmbOZIUbNODs="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.1-beta.0_1697488439349_0.7688128967383325"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.2-beta.0":{"name":"mail-passify","version":"3.0.2-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.0.2-beta.0","readme":"# What Is Mail-Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v2.0.0](https://github.com/Capta1nRaj/mail-passify/tree/v2.0.0)\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0](https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0)\r\n\r\n## # Overview\r\n\r\nMail-Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v2.0.0\r\n\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#3-sign-in-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Compatibility With Next.js.\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/server, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies.\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n3. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n4. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n5. Include and configure the following in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nconst { signup } = require(\"mail-passify\");\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nconst { signUpVerify } = require(\"mail-passify\");\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nconst { signin } = require(\"mail-passify\");\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('token', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nconst { signInVerify } = require(\"mail-passify\");\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nconst { autoSignIn } = require(\"mail-passify\");\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nconst { logoutOnce } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nconst { logoutAll } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nconst { forgotPassword } = require(\"mail-passify\");\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to send OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁","readmeFilename":"README.md","gitHead":"9136cc30253759fc8c0fb443530d95401244ce64","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-WQglHgf7kvzd4wLAKY3cLWTwOrWxIl3CU9B+8Y8Ac0wC0lQdVP1xYSRw9GNrH4H9Bwg+s8fGlYzBPQlABhOOzQ==","shasum":"66cbbad5aca4bfa93a2582aae817acc807f14120","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.2-beta.0.tgz","fileCount":26,"unpackedSize":246962,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFJ9oczpw2ipBGpgUCYKMM8MapBMi+yJIb95UAB0vpC0AiEAx1Ux7aBHXN3eJS1ixtjoCSE8uoEfcxNE82OUd2Q5/so="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.2-beta.0_1697489057900_0.19390226058638116"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.3-beta.0":{"name":"mail-passify","version":"3.0.3-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.0.3-beta.0","readme":"# What Is Mail-Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v2.0.0](https://github.com/Capta1nRaj/mail-passify/tree/v2.0.0)\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0](https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0)\r\n\r\n## # Overview\r\n\r\nMail-Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v2.0.0\r\n\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#3-sign-in-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Compatibility With Next.js.\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/server, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies.\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n3. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n4. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n5. Include and configure the following in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nconst { signup } = require(\"mail-passify\");\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nconst { signUpVerify } = require(\"mail-passify\");\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nconst { signin } = require(\"mail-passify\");\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('token', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nconst { signInVerify } = require(\"mail-passify\");\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nconst { autoSignIn } = require(\"mail-passify\");\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nconst { logoutOnce } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nconst { logoutAll } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nconst { forgotPassword } = require(\"mail-passify\");\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to send OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁","readmeFilename":"README.md","gitHead":"c0ceb91721fa7a7135b0bfed5a286b97a8a00478","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-YK3AvYwKPTQLb/w8AtiuvOxsdpl8/mGjO0Rqd6Xt6TgOYL35dq46Ot6/zq46ANtLr7ivTfpbc+wa2h3Gfqvcqg==","shasum":"d14bf906340f9d69dabd4d08b4d72cb71c65e7ee","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.3-beta.0.tgz","fileCount":26,"unpackedSize":247007,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICVdy1KnxLnw/oJD1VxvwS6Ojn/9WgBqAWehW5pTbhn2AiBO/MwuBEUcGUT70t1c02zv/WMMaWwfVZvJJoLuGR5Xmg=="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.3-beta.0_1697568152825_0.29279441298843034"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.4-beta.0":{"name":"mail-passify","version":"3.0.4-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.0.4-beta.0","readme":"# What Is Mail-Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v2.0.0](https://github.com/Capta1nRaj/mail-passify/tree/v2.0.0)\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0](https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0)\r\n\r\n## # Overview\r\n\r\nMail-Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v2.0.0\r\n\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#3-sign-in-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Compatibility With Next.js.\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/server, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies.\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n3. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n4. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n5. Include and configure the following in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nconst { signup } = require(\"mail-passify\");\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nconst { signUpVerify } = require(\"mail-passify\");\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nconst { signin } = require(\"mail-passify\");\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('token', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nconst { signInVerify } = require(\"mail-passify\");\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nconst { autoSignIn } = require(\"mail-passify\");\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nconst { logoutOnce } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nconst { logoutAll } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nconst { forgotPassword } = require(\"mail-passify\");\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to send OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁","readmeFilename":"README.md","gitHead":"c0ceb91721fa7a7135b0bfed5a286b97a8a00478","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-56FVL9syo5s36jOW6ioHnkFTCzx6YbhmEPp/eUBoVR8CvlsPFTdw41aajPbC+jANbgjrJdDYlJmygIfN7OX/Tw==","shasum":"d250e3e19b40689408158d6801acd6334f28d89a","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.4-beta.0.tgz","fileCount":26,"unpackedSize":247034,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDE6JvOGtUq3RHuSsIN9b6S5uTgD+yU6fVyqAIWwKSnGgIgW6XNoAOMROM7He2oOdwySI+aOhuYIWucG3b5SVFPymc="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.4-beta.0_1697568718932_0.9906456937131896"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.5-beta.0":{"name":"mail-passify","version":"3.0.5-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.0.5-beta.0","readme":"# What Is Mail-Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v2.0.0](https://github.com/Capta1nRaj/mail-passify/tree/v2.0.0)\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0](https://github.com/Capta1nRaj/mail-passify-demo/tree/v2.0.0)\r\n\r\n## # Overview\r\n\r\nMail-Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v2.0.0\r\n\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#3-sign-in-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify#6-logout-)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify#installation-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Compatibility With Next.js.\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/server, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies.\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n3. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n4. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n5. Include and configure the following in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nconst { signup } = require(\"mail-passify\");\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nconst { signUpVerify } = require(\"mail-passify\");\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nconst { signin } = require(\"mail-passify\");\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('token', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nconst { signInVerify } = require(\"mail-passify\");\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nconst { autoSignIn } = require(\"mail-passify\");\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nconst { logoutOnce } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nconst { logoutAll } = require(\"mail-passify\");\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nconst { forgotPassword } = require(\"mail-passify\");\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to send OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁","readmeFilename":"README.md","gitHead":"c0ceb91721fa7a7135b0bfed5a286b97a8a00478","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-SvGx/lp60aFD27w2QLl0EPqrKOWrqAVvRxVA4h65gIp6LgInFdssW6hE0zuK0IIbCnQ+NLlrY0zPD2oBiYno3g==","shasum":"a2823dd89dc7276aa2e89f22d223fe9635305152","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.5-beta.0.tgz","fileCount":26,"unpackedSize":247034,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIA8xQWeBD7tCSuj4CRrbTaqYUWSFP9grF3K/9gMDMLL6AiEAoKvVFG49UWg0N6W03AnUnNLzphwzTzef6HYLnuVH10Q="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.5-beta.0_1697569140478_0.02323007676586686"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.6-beta.0":{"name":"mail-passify","version":"3.0.6-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.0.6-beta.0","readme":"# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3](https://github.com/Capta1nRaj/mail-passify/tree/v3).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://www.npmjs.com/package/mail-passify1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://www.npmjs.com/package/mail-passify3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://www.npmjs.com/package/mail-passifyinstallation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://www.npmjs.com/package/mail-passifyinstallation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://www.npmjs.com/package/mail-passifyinstallation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://www.npmjs.com/package/mail-passify7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://www.npmjs.com/package/mail-passify5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://www.npmjs.com/package/mail-passify6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://www.npmjs.com/package/mail-passify6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n   \r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://www.npmjs.com/package/mail-passifymethod-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://www.npmjs.com/package/mail-passifymethod-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://www.npmjs.com/package/mail-passifyfunction-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://www.npmjs.com/package/mail-passifyfunction-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://www.npmjs.com/package/mail-passifyfunction-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"6f160d02b46145b69f273e90fde4b07b16bd01f2","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-bLyuuEcQrX6eD4kYAnw9JkWbJYJZBZzQWWZ4lcbf3aoBkofKqJVJcRusq6Or8vXbjJBWcewnguYa7mZ29Iu5Ww==","shasum":"71b5912e26d6e142debc6c11d8fa5bd182fa07f7","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.6-beta.0.tgz","fileCount":26,"unpackedSize":247528,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAjJwtZCWfn5JOqSJha1DycKzVOBbOkZ9Ukc9FzdkyL9AiB8d9YJBcc92JIpl/3DSmZKEBXaihkBrb+2i3e0jjrTxw=="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.6-beta.0_1697713626300_0.32012418992357694"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.7-beta.0":{"name":"mail-passify","version":"3.0.7-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.0.7-beta.0","readme":"# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3](https://github.com/Capta1nRaj/mail-passify/tree/v3).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://www.npmjs.com/package/mail-passify#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://www.npmjs.com/package/mail-passify#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://www.npmjs.com/package/mail-passify#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://www.npmjs.com/package/mail-passify#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://www.npmjs.com/package/mail-passify#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://www.npmjs.com/package/mail-passify#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://www.npmjs.com/package/mail-passify#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://www.npmjs.com/package/mail-passify#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://www.npmjs.com/package/mail-passify#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n   \r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://www.npmjs.com/package/mail-passify#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://www.npmjs.com/package/mail-passify#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://www.npmjs.com/package/mail-passify#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://www.npmjs.com/package/mail-passify#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://www.npmjs.com/package/mail-passify#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"6f160d02b46145b69f273e90fde4b07b16bd01f2","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-ocxwT3lTrOKglk6cklaoaUGPQLh2CHpNpkChqwohWqxsaGkJWqzcY5llqO3ZcXkFGlS+/redfoktAuGsdWNRrQ==","shasum":"123763b0e8eb045e377fe70bb2cf899c7bf65ec8","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.7-beta.0.tgz","fileCount":26,"unpackedSize":247542,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCWMHqnf32P6Bz1a146XMvr+teP82dqgoKA8GFIK5Q6/gIhAL2w/2v9S18mpS1vsxHPuvWfoHAnB+ri2YPGaLzE5G3L"}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.7-beta.0_1697713694203_0.7129522994771136"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.0":{"name":"mail-passify","version":"3.0.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.0.0","gitHead":"457d79574ebd2adc28827ee5797fbe6410394467","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-hQANAS5oJIoQ3zG1pqbGl+rcXaqE7voDAcIcH3QSI6RRWc2TjI5KGH485UY+jltB+vhAeIhLtesMvHm1CSTooA==","shasum":"debf4845dd0ae0e5a1540657f9e0acd3883dd1d4","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.0.0.tgz","fileCount":26,"unpackedSize":248676,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAdhKMZhWeFYmZojOP2I3wgls2Z68WXyKJkldkOBuJyWAiAjPWsV/SmSlSt0vAkOggdejBdM3xFbx1j/x4+D7xQsPw=="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.0.0_1697715778156_0.7328884332594217"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.0-beta.0":{"name":"mail-passify","version":"3.1.0-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.0-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3](https://github.com/Capta1nRaj/mail-passify/tree/v3).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate a ``mail-passify.json`` file. In this file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | COMPANY_WEBSITE_URL                 | String  | Your company's website URL.            |\r\n   | COMPANY_WEBSITE_ICON                | String  | URL of your company's website icon.    |\r\n   | COMPANY_WEBSITE_ICON_WIDTH          | String  | Width of the website icon.             |\r\n   | COMPANY_CONTACT_MAIL                | String  | Company's contact email address.       |\r\n   | COMPANY_CUSTOMER_CARE_LINK          | String  | Link for customer support.             |\r\n   | COMPANY_INSTAGRAM_LINK              | String  | Link to your Instagram profile.        |\r\n   | COMPANY_INSTAGRAM_ICON              | String  | URL of the Instagram icon.             |\r\n   | COMPANY_TWITTER_LINK                | String  | Link to your Twitter profile.          |\r\n   | COMPANY_TWITTER_ICON                | String  | URL of the Twitter icon.               |\r\n   | COMPANY_YOUTUBE_LINK                | String  | Link to your YouTube channel.          |\r\n   | COMPANY_YOUTUBE_ICON                | String  | URL of the YouTube icon.               |\r\n   | COMPANY_MAIL_LINK                   | String  | Company's email address.               |\r\n   | COMPANY_MAIL_ICON                   | String  | URL of the mail icon.                  |\r\n   | COMPANY_FACEBOOK_LINK               | String  | Link to your Facebook page.            |\r\n   | COMPANY_FACEBOOK_ICON               | String  | URL of the Facebook icon.              |\r\n   | COMPANY_ANDROID_APP_LINK            | String  | Link to your Android app.              |\r\n   | COMPANY_ANDROID_APP_ICON            | String  | URL of the Android app icon.           |\r\n   | COMPANY_IOS_APP_LINK                | String  | Link to your iOS app.                  |\r\n   | COMPANY_IOS_APP_ICON                | String  | URL of the iOS app icon.               |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n   \r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"cf4b1c1c10fb1738e89764e98a395cc119317eff","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-OIYxKsvwujV81G3Rj9y2+ZUvsggu2x/pTNUzrO4E5ntZaiEukHGfS0HVSfFbG083Ef26mwCiv0xpsw6bJ2GIUw==","shasum":"16998abf956571e23eb2425952b7e7a20625383e","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.0-beta.0.tgz","fileCount":26,"unpackedSize":247364,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC7m5egdhcJ7Fy0EcAOivTXVqxnUvvfVK1GiKZHXM0woAIhANNW/b9ICNXCVshwZR7JK5RxHNmP3zxeltc0f2ZACuhE"}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.0-beta.0_1698086021894_0.338667838092362"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.1-beta.0":{"name":"mail-passify","version":"3.1.1-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.1-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-JOIrJKYFqfRVSyMn2NWc4ic/NwswFF+O5xmEL68vyUhONREpk+UudNAqScBYvE6F4L26l9bTbYE7Vcekfgz9aw==","shasum":"f5f9752d4e29632f2425607f68ad88289427cfb5","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.1-beta.0.tgz","fileCount":26,"unpackedSize":246065,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCHSbBcQrC3MH1p4y8DvKhYQY5o1/UF5QZNhODpuOkGLwIhAPZXAFwn4713SMpPv4jYykSiruw8CEnlocNsWgiWoQ6u"}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.1-beta.0_1698251766371_0.9663372850817107"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.2-beta.0":{"name":"mail-passify","version":"3.1.2-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.2-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-INb8KRYh9yTxQn3m87KKNOuKpDKXeiAm6Hr9fWJEmYyyPLGn+R9SwISvQEz2/BStSdgrRpTTlrniFyX9F/VyTQ==","shasum":"1e484dc5b99b5a8f169b53fe0cdcd727a9268b63","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.2-beta.0.tgz","fileCount":26,"unpackedSize":247029,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAxphvLrjBUSyhlSmZcZ32pfux8evazaNUOif4Ahxvl7AiEAgQ9bgom8X4HmtSrdStMaimKQcExwGOeYpvlrPho4uNI="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.2-beta.0_1698340768941_0.6924129024952825"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.3-beta.0":{"name":"mail-passify","version":"3.1.3-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.3-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-805Z/7VCzobaBw1lizXxB240RTVSPju1ZcUbmWfcD//89YTk7DF8xmS1ySuOobg3KIll0C4HY3mfpWm3J8NCdA==","shasum":"502dca774815e7c7f11ff73f1d2c4a6717e7b331","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.3-beta.0.tgz","fileCount":26,"unpackedSize":246163,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCVIVZqinJNnFdGUhmt77mxt6/wyJECQG69JdVdCIvpcAIgWiedOudqdVicSwg3mg2xUbvz9OZRGSH0akGEk1OG9kI="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.3-beta.0_1698342315864_0.5103785280147124"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.4-beta.0":{"name":"mail-passify","version":"3.1.4-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.4-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-phsrHby8LeGuz9uaoPP7+eYkAkwShIBfQG0IudqucczGzqDmVh77mw3es7fwrhlZLphmZS6aaccBydFXZVVeYA==","shasum":"8fbd631597b1a5dc301be5f75542efcf6c7f0fc9","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.4-beta.0.tgz","fileCount":26,"unpackedSize":246139,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBx6qi3ZF5r+/UD6ZItmyTCo+f7hZpdcItO8/yNwakUSAiEAsQeiA5Vj1g64l0j7avQCmyi9XrAjfSmrgSJvgBIMCQU="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.4-beta.0_1698342723071_0.8625255505555409"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.5-beta.0":{"name":"mail-passify","version":"3.1.5-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.5-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-1q18pn7RUQeiwObOCW374Ffj9wvZ3EV+neAo7xXjb+oGpvrM83APlxzs4da8vq1wGtATcUm3go7aa8fKa4F1VQ==","shasum":"72392292b983944ed9837a3762d3781958660b3d","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.5-beta.0.tgz","fileCount":26,"unpackedSize":246375,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAbLMXNmfn3Xis/vma7I5HSi8lzj0JHJMBMBbBmcFHiRAiB74Xgu4BZXaO7wYBzKjITEuntjHyI7m5vyol+ivZMK0A=="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.5-beta.0_1698343198981_0.03653760575046738"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.6-beta.0":{"name":"mail-passify","version":"3.1.6-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.6-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-fsHF132BNWPAQsQ9nQoJkJEbshogXanKKna3O8sh6wS4ASJU6dZnVcnU786D8Utn4su//NuHam6UH92nm3QjUw==","shasum":"573ff9e7a06f9b32a623046b21e29248d644dd92","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.6-beta.0.tgz","fileCount":26,"unpackedSize":246408,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD8f7/eNXSHXypGpDZEPolYz7mBgvdRsqK0sxnymom1TQIgCYTe7pLs6kvid9yWc2/0npoSomKy1PfWh4hKNsvsrj4="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.6-beta.0_1698343641503_0.560766051175241"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.7-beta.0":{"name":"mail-passify","version":"3.1.7-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.7-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-HPwv2fDpm6iM0WIsG328D0IxXKfzbXIwoXk6jwUD3leNzw0xcdAe6UgQn8Mi8FZs7Pe5P9Lfr2C0f712/iYv4Q==","shasum":"ed390aadb2e85da4fb4dbb9f46655b6df779b0a5","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.7-beta.0.tgz","fileCount":26,"unpackedSize":246374,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGMnjy/0LP3jlGmgP41SC6E6tHx0PZY6/fSg7IvLHFzAAiAm/cvBdldNmsp7piyqmsy+P1qcdIdtEXq0Mnyg0QPpjw=="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.7-beta.0_1698343944306_0.7260966633690675"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.8-beta.0":{"name":"mail-passify","version":"3.1.8-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.8-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-BQOk4vwAUA8edTQeetFe8FC+2mPy3geA0BT0eXwq9suBjZQr/MEw9CjelW+blmTEaFVpfmqLScAY+1Vd1n1WUA==","shasum":"e1da532d6f25a8f3718b0865930c20bda2980025","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.8-beta.0.tgz","fileCount":26,"unpackedSize":245942,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDwwmT5p2yuXV370CUdzh7dSo3nh2RjLLxzjf93W9nZkQIgBvJ+LBAYPhQ9MKtF26n7VPabn/Y3WNp9JOaIDV+LMcA="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.8-beta.0_1698401320294_0.23895871111664446"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.1.9-beta.0":{"name":"mail-passify","version":"3.1.9-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.1.9-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"fc97508f116397b81c1d5efeb6819690085e526b","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-cuS0CKfkN3y+HG1s522Jy+x5chD3T3xNS7C3D/cwBgMiunZeBsHvAnpXwqXguOZ3d2ST8slK4VugD0Ndq5Bksw==","shasum":"ec23a66b0c80a9f578819f69158df0c1cc906eaa","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.1.9-beta.0.tgz","fileCount":26,"unpackedSize":247232,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDzYsJ47OpEeRzB6kYD82BgXa5MyuyKPq5100PnWuDplAiBMMPKvjMQ3Neop0rMGZMV9kY7THW1Ay4aN8zjmC3h3cw=="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.1.9-beta.0_1698521040279_0.0160057763001471"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.2.0-beta.0":{"name":"mail-passify","version":"3.2.0-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.2.0-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"9f38d6ac745e68d17924fd6a1ecb78cb354c48eb","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-095dPgnlKAR54uzkzoPgfj836+G+VkRtPYuc5n3JPaxEnPyRtxlkY8hk+wlbOF58JzZBKz8N1OQyL70DJ+d4HQ==","shasum":"2612d84f27b21ea886e03580715d1d9fc7c5c416","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.2.0-beta.0.tgz","fileCount":26,"unpackedSize":247702,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDN2zy56TdihJBXwjT5WcRZW+4vNEQCcpnBw4uO77Wy2AiEA3G2RYKx0s+8OaKVY7CAbjM/853+iNjw0exRtTuz9ocs="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.2.0-beta.0_1698523326515_0.24556285596370153"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.2.1-beta.0":{"name":"mail-passify","version":"3.2.1-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.2.1-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"a2196c156aeeb239d449fcc6d78947b973247044","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-sPRZf5AF1tsaWxSCRuiABI9dipqd9aXBb2NsdxtIE2dQVTG2j39Hw0xM/Qj9CGdV2L0iCFhnsElgBhEMHUOGBg==","shasum":"e6d226b8e34a710c02953b4fb11c6b1e255bd9e5","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.2.1-beta.0.tgz","fileCount":26,"unpackedSize":247631,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC5n5TVdtLgt7mNvzKxUhCqHBCgy5vew+fcwSb9XL2bFAIhAPTqpnsEwfXwXuiszct5TZiC+W0K97BLaHkr5VTCNhxJ"}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.2.1-beta.0_1698524740135_0.5979775650574293"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.2.2-beta.0":{"name":"mail-passify","version":"3.2.2-beta.0","description":"Custom email and password authentication with two-step verification via SendGrid.","main":"index.mjs","type":"module","scripts":{"init":"npm run generate-config","generate-config":"./stubs/config-generator.mjs"},"repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"license":"ISC","bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"homepage":"https://github.com/Capta1nRaj/mail-passify#readme","dependencies":{"@react-email/render":"^0.0.7","@sendgrid/mail":"^7.7.0","connect2mongodb":"^0.4.1","crypto-random-string":"^5.0.0","dotenv":"^16.3.1","express":"^4.18.2","external-ip":"^2.3.1","mongoose":"^7.6.2","nodemon":"^3.0.1","randomstring":"^1.3.0"},"keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"],"bin":{"generating-config-json-file":"stubs/config-generator.mjs"},"_id":"mail-passify@3.2.2-beta.0","readme":"<p align=\"center\">\r\n  <a href=\"https://github.com/Capta1nRaj/mail-passify\" target=\"_blank\"><img width=\"200px\" src=\"https://github.com/Capta1nRaj/mail-passify/assets/101660221/91b0dd5c-a57b-4959-b9da-863e845ac820\" /></a>\r\n  <h3 align=\"center\">Mail Passify</h3>\r\n  <p align=\"center\" style=\"align: center;\">\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/stargazers\">\r\n         <img src=\"https://img.shields.io/github/stars/Capta1nRaj/mail-passify\" alt=\"Github Stars\" />\r\n      </a>\r\n      <a href=\"https://github.com/Capta1nRaj/mail-passify/blob/main/LICENSE\">\r\n         <img src=\"https://img.shields.io/github/license/Capta1nRaj/mail-passify\" alt=\"Licence\" />\r\n      </a>\r\n      <a href=\"https://www.npmtrends.com/mail-passify\">\r\n         <img src=\"https://img.shields.io/npm/dm/mail-passify\" alt=\"Downloads\" />\r\n      </a>\r\n      <a href=\"https://bundlephobia.com/package/mail-passify@3.0.0\">\r\n         <img src=\"https://img.shields.io/bundlephobia/min/mail-passify/3.0.0\" alt=\"Size\" />\r\n      </a>\r\n   </p>\r\n</p>\r\n\r\n# What Is Mail Passify?\r\n\r\n**Note:-** Please refer to the documentation on my GitHub repository in case I missed or inaccurately mentioned something here. Documentation for [v3.1](https://github.com/Capta1nRaj/mail-passify/tree/v3.1).\r\n\r\n## Demo Link:-\r\n\r\nTo test a demo before using in your main project, visit here and read the README before starting:- [https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1](https://github.com/Capta1nRaj/mail-passify-demo/tree/v3.1)\r\n\r\n## # Overview\r\n\r\nMail Passify is a Node.js module that empowers you to create a robust user **sign-up** and **sign-in** system with **two-step verification** using **SendGrid**(freemium). It's also equipped with a **built-in referral system** to enhance user engagement and growth. **Note:-** It only supports MongoDB as database for now.\r\n\r\n## # Features In v3.1\r\n\r\n- ✅ [Compatible with Next.js.](https://nextjs.org/)\r\n- ✅ [Custom Mail Template*](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#9-custom-email-template-)\r\n- ✅ [Sign-Up With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#1-sign-up-)\r\n- ✅ [Sign-In With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#3-sign-in-)\r\n- ✅ [Passwords Are Encrypted With Crypto.](https://nodejs.org/api/crypto.html)\r\n- ✅ [Referral System.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [No Disposable E-Mails Are Allowed To Signup.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Resend OTP With Limited Requests.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#installation-)\r\n- ✅ [Forgot Password With Two-Step Verification.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#7-forgot-password-)\r\n- ✅ [Auto User Session Checking.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#5-auto-user-session-check-)\r\n- ✅ [Logout Session Of Current Device.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n- ✅ [Logout Sessions Of All Devices.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#6-logout-)\r\n\r\n## # More Features To Be Added Later\r\n\r\n* ❌ Lock User After N-Times Failed Login Attempts & Send Notification Email To The User.\r\n* ❌ Unlock The Locked User Account (User + Auto).\r\n* ❌ Add Phone Number In Accounts Model With 2 Step Verification.\r\n* ❌ Change/Update User Info.\r\n* ❌ Delete Account But Make Sure User Don't Get Referral Points Again Once He Sign Up With Any Referral Code.\r\n\r\n## # Getting Started\r\n\r\n### Installation:-\r\n\r\n1. Begin by installing the packages:-\r\n\r\nIn back-end/front-end, depends on your use, install **mail-paasify**:-\r\n\r\n```js\r\nnpm i mail-passify\r\n```\r\n\r\nWhereas, in front-end, for fetching cookies, install **cookies-next**:-\r\n**Note:-** You can use your own method for fetching cookies. For eg.:- You can also set/fetch cookies via server-side in Next.js, [READ HERE](https://nextjs.org/docs/app/api-reference/functions/cookies).\r\n\r\n```js\r\nnpm i cookies-next\r\n```\r\n\r\n2. Configure & Include the following values in your .env file:\r\n\r\n```js\r\nMONGODB_URI = YOUR_MONGODB_URI (mongodb://127.0.0.1:27017/DB-NAME)\r\nSENDGRID_API_KEY = YOUR_SENDGRID_API_KEY\r\nSENDGRID_EMAIL_ID = YOUR_SENDGRID_EMAIL_ID\r\nSECRET_KEY = YOUR_SECRET_KEY_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nSECRET_IV = YOUR_SECRET_IV_FOR_ENCRYPTION_OF_LENGTH_32_OR_GREATER\r\nALLOWED_EMAIL_DOMAINS=@gmail.com,@hotmail.com {YOU_CAN_ADD_MORE_BY_SEPERATING_WITH_,(comma)}\r\n```\r\n\r\n3. Generate the configuration file in server by using the command:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n4. This will generate 2 files ``mail-passify.json`` & ``email-template.html`` files. In ``mail-passify.json`` file, you can configure your data. Please ensure that you maintain the variables in the JSON file as specified below.\r\n\r\n   | Name                                | Type    | Usage                                  |\r\n   | ----------------------------------- | ------- | -------------------------------------- |\r\n   | SENDGRID_SIGN_UP_MAIL_TITLE         | String  | Custom title for sign-up confirmation. |\r\n   | SENDGRID_SIGN_IN_MAIL_TITLE         | String  | Custom title for sign-in confirmation. |\r\n   | SENDGRID_FORGOT_PASSWORD_MAIL_TITLE | String  | Custom-Forgot-Password-Title.          |\r\n   | REFERRED_POINTS                     | Integer | Points awarded to the referrer.        |\r\n   | REFERRED_PERSON_POINTS              | Integer | Points awarded to the referred person. |\r\n   | OTP_LIMITS                          | Integer | Max Times User Can Request For OTP.    |\r\n\r\n5. Once you update these values, again run this command to update your referral points values in your MongoDB database:-\r\n\r\n```js\r\nnpx mail-passify init\r\n```\r\n\r\n## # Usage\r\n\r\n### 1. Sign Up:-\r\n\r\nTo get started, set up the sign-up module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {fullName, userName, emailID, password, referralCode};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-up module on the Back-End:-\r\n\r\n```js\r\nimport signup from \"mail-passify\";\r\nconst response = await signup(fullName, userName, emailID, password, referralCode);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs up, they will receive an OTP on their registered email. Consequently, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"Account Created Successfully\",\r\n   userName: username,\r\n};\r\n```\r\n\r\nFollowing that, in your front-end code, use cookies-next to store the userName **(which we obtained from the response above)** in the browser's cookies:\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\n```\r\n\r\nAfter sending the OTP, redirect the user to the account verification page and follow the steps provided.\r\n\r\n### 2. Sign Up Verify:-\r\n\r\nTo start, in your front-end code, use **cookies-next** to extract the userName from cookies, as well as the **OTP** entered by the user. Then, send this data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst data = {userNameCookie, OTP};\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nSet up the sign-up verify module in Back-End. Make sure to fetch userName from **cookies** as we stored it above.\r\n\r\n```js\r\nimport { signUpVerify } from \"mail-passify\";\r\nconst response = await signUpVerify(userNameCookie, OTP);\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user verifies their account in the **MongoDB accounts model**, the userVerified section in their document will change from **false** to **true**. If they have been **referred**, they will also receive **referral points**. As a result, you will receive a response similar to this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 3. Sign In:-\r\n\r\nTo get started, set up the sign-in module data in the Front-End first and pass it to the Back-End **(you can use your preferred method to send the data)**:-\r\n\r\n```js\r\nconst data = {userName, userPassword};\r\n// You can use fetch or any method you are comfortable with.\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nNext, configure the sign-in module on the Back-End:-\r\n\r\n```js\r\nimport { signin } from \"mail-passify\";\r\nconst response = await signin(userName, userPassword)\r\nconsole.log(response);\r\n```\r\n\r\nAfter the user signs in with correct details, if the user is registered & has verified their account, they will receive an OTP on their email. You will receive this response, and you should then redirect them to the sign-in verification page:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Sign In Successful, OTP Sent To Mail\",\r\n   userName: username,\r\n   token: userTokenAddress,\r\n   id: savedData.id\r\n};\r\n```\r\n\r\n**Note:-** If the user is registered but hasn't verified their account, you will receive this response, and you should redirect them to the verification/signUpVerify page:-\r\n\r\n```js\r\nreturn {\r\n   status: 401,\r\n   message: \"Please Verify Your Account\",\r\n   userName: username,\r\n}\r\n```\r\n\r\nAs we did above, store the userName, token, & Id in cookies that we received from the response above ***(similar like this)***:-\r\n\r\n```js\r\nimport { setCookie } from 'cookies-next';\r\nconst setUserNameCookies = setCookie('userName', getUserNameFromResponse);\r\nconst setToken = setCookie('token', getTokenFromResponse);\r\nconst setId = setCookie('id', getIdFromResponse);\r\n```\r\n\r\n### 4. Sign-in Verify:-\r\n\r\nAs mentioned above, the user has signed in with their details, and they are verified, then, you have redirected them to the sign-in verification page. To proceed, use the following functions in the front-end to pass the data to the Back-End:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = {userNameCookie, OTP, userId}\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is sent to the Back-End, use this method to verify the user:-\r\n\r\n```js\r\nimport { signInVerify } from \"mail-passify\";\r\nconst response = await signInVerify(userNameCookie, OTP, userId);\r\nconsole.log(response);\r\n```\r\n\r\nIf the user enters the correct OTP, in the **MongoDB Session Model**, the user document **OTP field** will be removed, and the document's expiry will be changed to 10 days. In return, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Account Verified\"\r\n}\r\n```\r\n\r\n### 5. Auto User Session Check:-\r\n\r\nWhat if the user's session has expired, and they are still logged in, or if they attempt to manipulate cookies and perform unauthorized actions? You know that's not good, right? So, use the `sessionCheck()` function to verify if the user's session is legitimate and active. Follow these steps:-\r\n\r\n```js\r\nimport { sessionCheck } from \"mail-passify\";\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst response = await sessionCheck(userNameCookie, userTokenCookie, userId);\r\n// Note:- IP Will Be Automatically Fetched.\r\n```\r\n\r\nIf the user is legitimate, you will receive this response, and their session will remain logged in:-\r\n\r\n```js\r\nreturn {\r\n   status: 202,\r\n   message: \"Session Exist\"\r\n}\r\n```\r\n\r\nElse, if there are no session found, then, redirect them to the login page. The response you will receive is:-\r\n\r\n```js\r\nreturn {\r\n   status: 400,\r\n   message: \"Session Don't Exist\"\r\n}\r\n```\r\n\r\n### 6. Logout:-\r\n\r\nThere are **2 methods** to logout the user:-\r\n\r\n1. [Logout Current Session Only:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-1-current-session-only-) The user gets logged out only from the current device.\r\n2. [Logout All Sessions:-](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#method-2-all-sessions-) The user gets logged out from all sessions.\r\n\r\n#### Method 1 (Current Session Only):-\r\n\r\nTo begin, fetch **userName** and **token** from cookies in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nimport { getCookie } from 'cookies-next';\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken ');\r\nconst userIdCookie = getCookie('userId');\r\nconst data = { userNameCookie, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data);\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **logoutOnce** function to remove the session from MongoDB, like this:-\r\n\r\n```js\r\nimport { logoutOnce } from \"mail-passify\";\r\nconst response = await logoutOnce(userNameCookie, userTokenCookie, userId)\r\n```\r\n\r\nOnce the user's session is deleted, redirect them to homepage, & you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"User Session Deleted.\",\r\n};\r\n```\r\n\r\nAfter deleting the session from MongoDB, please clear the user's browser cookies via the Front-End like this:-\r\n\r\n```js\r\nimport { deleteCookie } from 'cookies-next';\r\ndeleteCookie('userNameCookie');\r\ndeleteCookie('userTokenCookie');\r\n```\r\n\r\n#### Method 2 (All Sessions):-\r\n\r\nAll steps are the same as we did above in **Method 1**, just in the Back-End, you need to change the imports like this:-\r\n\r\n```js\r\nimport { logoutAll } from \"mail-passify\";\r\nconst response = await logoutAll(userNameCookie, userTokenCookie, userIdCookie)\r\n```\r\n\r\n### 7. Forgot Password:-\r\n\r\nTo begin, get **userName** in the Front-End, then pass them to the Back-End, similar like this:-\r\n\r\n```js\r\nconst data = { userName }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is passed to the Back-End, use the **forgotPassword** function to reset/update the password in MongoDB like this:-\r\n\r\n```js\r\nimport { forgotPassword } from \"mail-passify\";\r\nconst response = await forgotPassword(userName);\r\n```\r\n\r\nAfter this, it will first verify whether the user exists in MongoDB or not. If the user exists, you will receive this response:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Sent To Mail\",\r\n   userName: userName,\r\n};\r\n```\r\n\r\nKindly save the userName to cookies as we did above. After that, pass your OTP and newPassword to the Back-End via the Front-End similar like this:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst data = { userNameCookie, OTP, newPassword }\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await forgotPassword(userNameCookie, OTP, newPassword)\r\n```\r\n\r\nNow, firstly, we will check if the OTP is correct or not. If the OTP is correct, we will update the new password. Once the password is updated, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 200,\r\n   message: \"Password Updated.\"\r\n}\r\n```\r\n\r\nTo resend OTP for the **forgot password** functionality, use these values:-\r\n\r\n```js\r\nconst response = await resendOTP(userNameCookie, 'forgotPassword')\r\n```\r\n\r\n### 8. Resend OTP:-\r\n\r\nThere are **3 functions** to resend OTP to the user:-\r\n\r\n1. [Resend OTP For New/Unverified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-1-for-new-users-)\r\n2. [Resend OTP For Old/Verified User.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-2-for-old-users-)\r\n3. [Resend OTP For Forgot Password.](https://github.com/Capta1nRaj/mail-passify/tree/v3.1#function-3-for-forgot-password-)\r\n\r\n#### Function 1 (For New Users):-\r\n\r\nOnce the user is on **signup verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'newUserVerification'; //This Helps Module To Know That Resend OTP For The unverified User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n#### Function 2 (For Old Users):-\r\n\r\nOnce the user is on **signin verify page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst userTokenCookie = getCookie('userToken');\r\nconst userIdCookie = getCookie('userId');\r\nconst method = 'oldUserVerification'; //This Helps Module To Know That Resend OTP For The verified User\r\nconst data = { userNameCookie, method, userTokenCookie, userIdCookie };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** If a user reaches the maximum OTP request limit, they can still attempt to sign in again, which will generate different values.\r\n\r\n#### Function 3 (For Forgot Password):-\r\n\r\nOnce the user is on **forgot password page**, & if he requests to resend the OTP, use this below syntax in your front-end:-\r\n\r\n```js\r\nconst userNameCookie = getCookie('userName');\r\nconst method = 'forgotPassword'; //This Helps Module To Know That Resend OTP For The forgotPassword User\r\nconst data = { userNameCookie, method };\r\nconst response = await axios.post('YOUR_URL', data)\r\n```\r\n\r\nOnce the data is received in the back-end, please perform the following actions:-\r\n\r\n```js\r\nconst response = await resendOTP(data.userNameCookie, data.method)\r\n```\r\n\r\nNow it will find the document in the DB, & update the new OTP in the document, & will also increment the OTPCount by +1. Once the OTP is sent to the user, & updated in the DB, then, you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 201,\r\n   message: \"OTP Resent To The User.\",\r\n};\r\n```\r\n\r\nIf the OTPCount === OTP_LIMITS(mailpassify.json), then, it will not send OTP to the user, and you will receive a response like this:-\r\n\r\n```js\r\nreturn {\r\n   status: 403,\r\n   message: \"Max OTP Limit Reached, Please Try After 10 Minutes.\"\r\n};\r\n```\r\n\r\n**Note:-** Once the OTP limits are reached, the user can try again after waiting for 5-10 minutes, as the OTP document from the database will be automatically deleted after this period.\r\n\r\n### 9. Custom Email Template:-\r\n\r\nTo create custom template, update the ``email-template.html`` file. Currently the tempalte only support **plain html with in-line css**, your can checkout the pre-installed template in the file. You can use ChatGPT to convert your template to **plain html with in-line css**.\r\n\r\n### Feel free to raise an issue if you find any bugs. Thanks in advance! 😁\r\n","readmeFilename":"README.md","gitHead":"abc07333b6b169c0c82940bd592d0516ad218f8d","_nodeVersion":"18.18.2","_npmVersion":"10.2.0","dist":{"integrity":"sha512-DXMxrl8l6nAfnLleU9idhuBeQQfcyU57qLCsrS7PC/h3wHTJO1w8ohmhUu3TvLWkRldUsIZ9jfnX79mZxfIP5Q==","shasum":"0ff566dbe24aeca323c344c4f4dbecb4fb564737","tarball":"https://registry.npmjs.org/mail-passify/-/mail-passify-3.2.2-beta.0.tgz","fileCount":26,"unpackedSize":247858,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFbIZKqsB2K+2CK7laU31FlSQZsONXigY+afFySZFw8tAiEAgxLAg4DZ8g4MtO2MmMb0h//laSNjcJBGBdf8UR7PhHc="}]},"_npmUser":{"name":"priyalraj","email":"priyalraj99@gmail.com"},"directories":{},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/mail-passify_3.2.2-beta.0_1698526973117_0.686936189966691"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."}},"time":{"created":"2023-09-01T07:38:24.883Z","0.0.1":"2023-09-01T07:38:25.091Z","modified":"2023-10-29T18:19:18.649Z","0.0.2-beta.1":"2023-09-22T13:25:37.184Z","0.0.2-beta.0":"2023-09-22T13:34:01.084Z","0.0.1-beta.0":"2023-09-22T13:38:16.764Z","1.0.0":"2023-09-22T14:40:23.629Z","2.0.0":"2023-10-12T19:17:30.119Z","2.0.1":"2023-10-14T03:21:20.023Z","2.0.0-beta.0":"2023-10-14T20:07:20.155Z","3.0.0-beta.0":"2023-10-14T20:08:44.579Z","2.0.2":"2023-10-14T20:10:24.961Z","3.0.1-beta.0":"2023-10-16T20:33:59.574Z","3.0.2-beta.0":"2023-10-16T20:44:18.248Z","3.0.3-beta.0":"2023-10-17T18:42:33.091Z","3.0.4-beta.0":"2023-10-17T18:51:59.363Z","3.0.5-beta.0":"2023-10-17T18:59:00.622Z","3.0.6-beta.0":"2023-10-19T11:07:06.852Z","3.0.7-beta.0":"2023-10-19T11:08:14.414Z","3.0.0":"2023-10-19T11:42:58.400Z","3.1.0-beta.0":"2023-10-23T18:33:42.142Z","3.1.1-beta.0":"2023-10-25T16:36:06.753Z","3.1.2-beta.0":"2023-10-26T17:19:29.107Z","3.1.3-beta.0":"2023-10-26T17:45:16.019Z","3.1.4-beta.0":"2023-10-26T17:52:03.321Z","3.1.5-beta.0":"2023-10-26T17:59:59.269Z","3.1.6-beta.0":"2023-10-26T18:07:21.876Z","3.1.7-beta.0":"2023-10-26T18:12:24.494Z","3.1.8-beta.0":"2023-10-27T10:08:40.469Z","3.1.9-beta.0":"2023-10-28T19:24:00.528Z","3.2.0-beta.0":"2023-10-28T20:02:06.735Z","3.2.1-beta.0":"2023-10-28T20:25:40.320Z","3.2.2-beta.0":"2023-10-28T21:02:53.340Z"},"maintainers":[{"name":"priyalraj","email":"priyalraj99@gmail.com"}],"description":"Custom email and password authentication with two-step verification via SendGrid.","homepage":"https://github.com/Capta1nRaj/mail-passify#readme","repository":{"type":"git","url":"git+https://github.com/Capta1nRaj/mail-passify.git"},"author":{"name":"Priyal \"Capta1n\" Raj"},"bugs":{"url":"https://github.com/Capta1nRaj/mail-passify/issues"},"license":"ISC","readme":"","readmeFilename":"","keywords":["express","mongodb","mognoose","mongo","dotenv","database","db","react","nodejs","oauth","jwt","authentication","nextjs","backend","nextauth","mail-passify"]}