const jwt = require('jsonwebtoken'); const winston = require('winston'); // Configure logger const logger = winston.createLogger({ level: 'info', format: winston.format.combine( winston.format.timestamp(), winston.format.json() ), transports: [ new winston.transports.Console() ] }); const authMiddleware = (req, res, next) => { try { const token = req.headers.authorization?.split(' ')[1]; if (!token) { return res.status(401).json({ message: 'Authentication required' }); } const decoded = jwt.verify(token, process.env.JWT_SECRET); req.user = decoded; next(); } catch (error) { logger.error('Auth middleware error:', error); return res.status(401).json({ message: 'Invalid token' }); } }; const adminMiddleware = (req, res, next) => { if (!req.user.is_admin) { return res.status(403).json({ message: 'Admin access required' }); } next(); }; module.exports = { authMiddleware, adminMiddleware };