# AuthService.signin custom logic

```ts
const { email, password } = body.data;
const doc = await this.userModel.findOne({ email, is_deleted: false });
if (!doc) throw new exceptions.UnauthorizedException("User not found");

if (doc.attributes.is_suspended)
  throw new exceptions.UnauthorizedException("User suspended");

const authManager = new AuthManager();
const isValidPassword = await authManager.verifyPassword(
  password,
  doc.password
);
if (!isValidPassword)
  throw new exceptions.UnauthorizedException("Invalid password");

const payload: Jsm.Core.Security.JWTUserAuthPayload = {
  _id: doc._id.toString(),
  tracking_id: doc.tracking_id,
  role: doc.role,
  space: "default",
};
const token = authManager.generateToken(
  payload,
  "default",
  false,
  config.security.jwt
);
const refresh_token = authManager.generateToken(
  payload,
  "default",
  true,
  config.security.jwt
);

// update last login time
if (!doc.auth_meta)
  doc.auth_meta = {
    last_login: null,
    last_logout: null,
    last_password_change: null,
    last_password_reset: null,
    last_password_reset_request: null,
    password_reset_token: null,
    password_reset_token_expiration: null,
    password_reset_token_used: null,
    password_reset_token_used_at: null,
  };
doc.auth_meta.last_login = new Date();
try {
  await doc.save();
} catch (error) {
  this.logger.error(this.signin.name, error);
}

// dispatch event
this.eventDispatcher.dispatch<Jsm.Core.Auth.Events.Payloads.UserSignedIn>(
  authEvents.userSignedIn,
  {
    data: mapDocumentToExposed(doc),
  }
);

// return result
result = {
  data: {
    user: mapDocumentToExposed(doc),
    token,
    refresh_token,
  },
};
```
