var __decorate = (this && this.__decorate) || function (decorators, target, key, desc) { var c = arguments.length, r = c < 3 ? target : desc === null ? desc = Object.getOwnPropertyDescriptor(target, key) : desc, d; if (typeof Reflect === "object" && typeof Reflect.decorate === "function") r = Reflect.decorate(decorators, target, key, desc); else for (var i = decorators.length - 1; i >= 0; i--) if (d = decorators[i]) r = (c < 3 ? d(r) : c > 3 ? d(target, key, r) : d(target, key)) || r; return c > 3 && r && Object.defineProperty(target, key, r), r; }; var __metadata = (this && this.__metadata) || function (k, v) { if (typeof Reflect === "object" && typeof Reflect.metadata === "function") return Reflect.metadata(k, v); }; var __param = (this && this.__param) || function (paramIndex, decorator) { return function (target, key) { decorator(target, key, paramIndex); } }; import { Inject, Injectable, UnauthorizedException } from '@nestjs/common'; import { JwtService } from '@nestjs/jwt'; function readCookieToken(request) { const header = request.headers.cookie; if (header === undefined) { return undefined; } const tokenPair = header .split(';') .map((part) => part.trim()) .find((part) => part.startsWith('okr_token=')); return tokenPair?.slice('okr_token='.length); } let JwtAuthGuard = class JwtAuthGuard { jwtService; constructor(jwtService) { this.jwtService = jwtService; } canActivate(context) { const request = context.switchToHttp().getRequest(); const authHeader = request.headers.authorization; const bearer = authHeader?.startsWith('Bearer ') === true ? authHeader.slice(7) : undefined; const token = bearer ?? readCookieToken(request); if (token === undefined || token.length === 0) { throw new UnauthorizedException('Authentication required'); } try { request.user = this.jwtService.verify(token); return true; } catch { throw new UnauthorizedException('Invalid or expired token'); } } }; JwtAuthGuard = __decorate([ Injectable(), __param(0, Inject(JwtService)), __metadata("design:paramtypes", [JwtService]) ], JwtAuthGuard); export { JwtAuthGuard };