Identity, Authentication & Authorization (IAM)
Every person on NexusOne gets a permanent NexusOne ID, authenticates via email/password or mobile OTP, and is authorized through a 16-role hierarchy enforced in-memory on every request. Sessions are stateless JWTs with revocation support, passwords are bcrypt-hashed, and every security-relevant event is written to an IAM audit log. This entire chapter is Basic tier — there are no AI-gated features here.
Basic Tier Features
BasicNexusOne ID & Account Status
- Every user gets a permanent, sequential nexusOneId (NX-000000001…) on creation — globally unique, never reused
- accountStatus lifecycle: pending → active → suspended / archived, enforced in both the login controller and the protect middleware
- Account locking: loginAttempts + lockUntil block login after repeated failures; admins unlock via PATCH /api/users/:id/unlock
Login Methods
- Email + password login with bcrypt verification, returning a JWT access token and user object
- Students can log in with their NexusOne ID or Student NexusOne ID (e.g. NX-STU-000001) instead of email — useful for admin-admitted students who don't have a real email on file
- Mobile OTP login (primary for parents/students) — POST /api/auth/otp/request then /api/auth/otp/verify
- Google OAuth and Microsoft OAuth are specified but not yet implemented (Planned)
Session & Token Management
- Stateless JWT auth: short-lived access token + refresh token via POST /api/auth/refresh
- Logout revokes the token's jti in the RevokedToken collection so it cannot be reused before expiry
- "Revoke all sessions" invalidates every existing token at once by bumping passwordChangedAt — the protect middleware rejects any token issued before that timestamp
- Web: /dashboard/profile/security page · Mobile: (student)/sessions.tsx screen
Password Security
- bcryptjs hashing at 12 salt rounds; a pre-save guard prevents double-hashing an already-hashed password
- Reset tokens are crypto.randomBytes(32), SHA-256 hashed in the database, and expire after 1 hour
- changedPasswordAfter() invalidates any JWT issued before the last password change
- Own-password change via PATCH /api/auth/change-password
Role-Based Access Control
- 11 roles in the User.role enum: platform_admin, super_admin, admin, teacher, student, parent, accountant, librarian, facilities_admin, driver, alumni
- authorize(...roles) middleware calls hasRole() against a static ROLE_HIERARCHY object — higher roles automatically satisfy lower-role route requirements, with zero database lookups
- belongsToSchool() / requireSchool() / ownerOrAdmin enforce tenant and record-level scoping on top of the role check
IAM Audit Log
- AuditLog captures login success/failure, logout, password changes, account status changes, session revocations, and unlocks
- GET /api/auth/audit-log (admin and above) returns a paginated, filterable trail
- Web: /dashboard/admin/iam viewer with action-type labels and locked-account management · Mobile: (admin)/iam-security.tsx
Profile & Preferences
- Profile fields: name, phone, address, profile photo (Cloudinary) via PATCH /api/users/me and /api/users/me/photo
- Per-user preferences sub-document: language, theme, timezone, and per-channel notification toggles (email/push/whatsapp/sms)
- Web: /dashboard/profile and /dashboard/profile/preferences · Mobile: (student)/profile.tsx and (student)/preferences.tsx
Still Planned
Roadmap — Not Yet Implemented
- Google OAuth and Microsoft OAuth login
- Platform Admin / Super Admin impersonation (specified, time-limited and audited, but no code path exists yet)
- Multi-Factor Authentication (TOTP) and WhatsApp-based identity verification
- OpenID Connect / SAML SSO for enterprise schools
API Reference — Chapter 3
Authentication (/api/auth) — all rate-limited via authLimiter, 10 req/15 min
/api/auth/registerRegister a new user account
/api/auth/loginEmail, NexusOne ID, or Student NexusOne ID + password login — returns JWT access token + user object
/api/auth/otp/requestRequest a mobile OTP for login
/api/auth/otp/verifyVerify OTP and issue a session token
/api/auth/forgot-passwordSend password reset email (3/hour limiter)
/api/auth/reset-passwordReset password via emailed token
/api/auth/refreshRefresh an access token
/api/auth/meGet the current authenticated user
/api/auth/logoutRevoke the current token and end the session
/api/auth/change-passwordChange own password
/api/auth/revoke-all-sessionsInvalidate every existing token by bumping passwordChangedAt
/api/auth/audit-logIAM audit trail (admin and above)
Profile & Preferences (/api/users)
/api/users/meUpdate own name, phone, address
/api/users/me/photoUpload profile photo (Cloudinary)
/api/users/me/preferencesGet language, theme, timezone, notification preferences
/api/users/me/preferencesUpdate preferences
User & Account Management (/api/users, admin)
/api/usersList users in school (admin, super_admin)
/api/users/:idGet a user (owner or admin)
/api/users/:idUpdate a user; admins may also change role/isActive/verification flags
/api/users/:id/statusSuspend, activate, or archive a user account
/api/users/:id/unlockClear failed-login lock on an account
/api/users/inviteInvite a new user by email with a temporary password
/api/users/:idDeactivate a user (admin)
Platform Admin — Cross-Tenant User Management
/api/platform-admin/users(via superAdminController) all users across all schools
/api/platform-admin/users/:id/schoolsGrant a user multi-school access
/api/platform-admin/users/:id/schools/:schoolIdRevoke a user's access to a school
Frontend Pages
| Path | Role | Description | Tier |
|---|---|---|---|
| /login | Public | Email or NX ID + password login with role-based dashboard redirect; links to OTP login and school registration | Basic |
| /otp-login | Public | Mobile OTP login flow with 6-digit input and resend countdown | Basic |
| /register | Public | New user account registration | Basic |
| /forgot-password | Public | Email-based password reset request | Basic |
| /dashboard/profile | All authenticated roles | NexusOne ID, account details, profile photo | Basic |
| /dashboard/profile/security | All authenticated roles | Change password, revoke all sessions | Basic |
| /dashboard/profile/preferences | All authenticated roles | Language, theme, timezone, notification toggles | Basic |
| /dashboard/admin/iam | Admin | IAM audit log viewer, locked-account management | Basic |
| /dashboard/admin/users | Admin | User list, role and status management, invites | Basic |
Mobile Screens
(auth)/login(auth)/otp-login(auth)/forgot-password(student)/profile(student)/sessions(student)/preferences(admin)/iam-security