basic-backend-nilesh
v1.0.2
Published
basic backend setup
Maintainers
Readme
Basic Backend Nilesh
A production-ready Node.js/Express backend starter pack with built-in authentication (JWT + cookies), OTP-based password reset, MongoDB integration, and email notifications — all pre-configured and ready to use.
✨ Features
- 🔐 Full Authentication System — Register, Login, Logout with JWT tokens stored in HTTP-only cookies
- 📧 Email Notifications — Welcome emails on registration using Nodemailer (Gmail SMTP)
- 🔑 OTP-Based Password Reset — Forgot password flow with 6-digit OTP, verification, and secure password reset
- 🛡️ Auth Middleware — Protect routes with JWT verification (supports cookies & Bearer tokens)
- 📦 CLI Scaffolding Tool — Generate a fresh backend project instantly via
npx - 🗄️ MongoDB + Mongoose — Pre-configured database connection with clean schema models
- 🍪 Cookie Parser — Secure cookie-based session management
- ⚡ Express 5 — Built on the latest Express framework
- 🏗️ Modular Structure — Well-organized controllers, models, routes, and utilities
🚀 Quick Start
Scaffold a new backend project in seconds:
npx basic-backend-nilesh my-app
cd my-app
npm installThen configure your environment variables and start developing.
📋 Prerequisites
- Node.js >= 18.x
- MongoDB (local or Atlas)
- A Gmail account with an App Password (for email features)
🛠️ Installation & Setup
Option 1 — Using NPX (recommended)
npx basic-backend-nilesh my-project
cd my-projectOption 2 — Manual Clone
git clone https://github.com/NileshMargaj/basic-backend-nilesh.git
cd basic-backend-nileshInstall Dependencies
npm installEnvironment Variables
Create a .env file in the root directory:
# MongoDB
MONGO_CONNECTION_URI=mongodb://localhost:27017
# JWT
JWT_SECRET=your-super-secret-jwt-key
# Email (Gmail App Password)
[email protected]
EMAIL_PASS=your-gmail-app-password
# Environment
NODE_ENV=development⚠️ Important: Never commit your
.envfile to version control. It's already included in.gitignore.
Start the Server
# Development (with auto-reload)
npm run dev
# Production
npm startThe server will start on http://localhost:3000 (or the port specified in PORT env variable).
📡 API Reference
All endpoints are prefixed with /api/auth.
Public Endpoints
| Method | Endpoint | Description | Request Body |
|--------|---------------------------|----------------------------------|--------------------------------------------------|
| POST | /api/auth/register | Register a new user | { username, email, password } |
| POST | /api/auth/login | Login with email & password | { email, password } |
| POST | /api/auth/logout | Logout and clear auth cookie | — |
| POST | /api/auth/forgot-password | Request OTP for password reset | { email } |
| POST | /api/auth/verify-otp | Verify the 6-digit OTP | { email, otp } |
| POST | /api/auth/reset-password | Reset password with verified OTP | { email, otp, newPassword } |
Protected Endpoint
| Method | Endpoint | Description | Auth Required |
|--------|-----------------------|------------------------|---------------|
| GET | /api/auth/profile | Get current user info | ✅ Yes |
Headers for protected routes:
Authorization: Bearer <token>
or the token is automatically read from thetokencookie.
Response Format
All API responses follow a consistent structure:
{
"success": true,
"message": "User registered successfully",
"user": {
"_id": "...",
"username": "...",
"email": "...",
"createdAt": "..."
}
}Error responses:
{
"success": false,
"message": "User already exists"
}📁 Project Structure
backend/
├── bin/
│ └── cli.js # CLI scaffolding entry point
├── src/
│ ├── constant/
│ │ └── constant.js # App constants (DB_NAME, etc.)
│ ├── controller/
│ │ └── user.controller.js # Auth business logic
│ ├── database/
│ │ └── db.js # MongoDB connection
│ ├── middlewre/
│ │ └── auth.middleware.js # JWT authentication middleware
│ ├── model/
│ │ ├── user.model.js # User schema
│ │ └── otp.model.js # OTP schema (auto-expires in 10 min)
│ ├── route/
│ │ └── user.route.js # All auth route definitions
│ ├── utility/
│ │ └── sendEmil.utils.js # Nodemailer email utility
│ └── app.js # Express app setup & middleware
├── server.js # Entry point
├── package.json
└── .gitignore🔐 Authentication Flow
Registration
- User sends
POST /api/auth/registerwith{ username, email, password } - Server hashes the password with bcrypt (10 salt rounds)
- Creates user in MongoDB, generates a JWT, sets it as an HTTP-only cookie
- Sends a welcome email to the user
- Returns user data (without password)
Login
- User sends
POST /api/auth/loginwith{ email, password } - Server verifies credentials, generates a JWT (expires in 2 days)
- Sets JWT as an HTTP-only cookie
- Returns user data (without password)
Password Reset Flow
- Forgot Password — User requests OTP via email
- Verify OTP — User submits the received 6-digit OTP
- Reset Password — User sets a new password (OTP expires after verification)
OTPs are stored with a TTL (Time-To-Live) index and auto-delete after 10 minutes.
🧰 Built With
| Technology | Purpose | |------------|---------| | Express | Web framework (v5) | | Mongoose | MongoDB ODM | | JSON Web Token | Authentication | | bcrypt | Password hashing | | Nodemailer | Email delivery | | cookie-parser | Cookie handling | | dotenv | Environment variables |
🤝 Contributing
Contributions are welcome! Here's how you can help:
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
Please make sure your code follows the existing style and all tests pass.
🐛 Bug Reports & Feature Requests
Found a bug or have an idea? Open an issue on GitHub.
📄 License
This project is licensed under the ISC License.
👨💻 Author
Nilesh Margaj
- GitHub: @NileshMargaj
- npm: basic-backend-nilesh
