This commit is contained in:
Daniel Hougaard
2024-03-17 18:49:30 +01:00
parent 771498b817
commit 41323f205d
3 changed files with 6 additions and 2 deletions
@@ -68,12 +68,15 @@ export const registerMfaRouter = async (server: FastifyZodProvider) => {
}, },
handler: async (req, res) => { handler: async (req, res) => {
const userAgent = req.headers["user-agent"]; const userAgent = req.headers["user-agent"];
const mfaJwtToken = req.headers.authorization?.replace("Bearer ", "");
if (!userAgent) throw new Error("user agent header is required"); if (!userAgent) throw new Error("user agent header is required");
if (!mfaJwtToken) throw new Error("authorization header is required");
const appCfg = getConfig(); const appCfg = getConfig();
const { user, token } = await server.services.login.verifyMfaToken({ const { user, token } = await server.services.login.verifyMfaToken({
userAgent, userAgent,
ip: req.realIp, ip: req.realIp,
mfaJwtToken,
userId: req.mfa.userId, userId: req.mfa.userId,
orgId: req.mfa.orgId, orgId: req.mfa.orgId,
mfaToken: req.body.mfaToken mfaToken: req.body.mfaToken
@@ -314,14 +314,14 @@ export const authLoginServiceFactory = ({
* Multi factor authentication verification of code * Multi factor authentication verification of code
* Third step of login in which user completes with mfa * Third step of login in which user completes with mfa
* */ * */
const verifyMfaToken = async ({ userId, mfaToken, ip, userAgent, orgId }: TVerifyMfaTokenDTO) => { const verifyMfaToken = async ({ userId, mfaToken, mfaJwtToken, ip, userAgent, orgId }: TVerifyMfaTokenDTO) => {
await tokenService.validateTokenForUser({ await tokenService.validateTokenForUser({
type: TokenType.TOKEN_EMAIL_MFA, type: TokenType.TOKEN_EMAIL_MFA,
userId, userId,
code: mfaToken code: mfaToken
}); });
const decodedToken = jwt.verify(mfaToken, getConfig().AUTH_SECRET) as AuthModeMfaJwtTokenPayload; const decodedToken = jwt.verify(mfaJwtToken, getConfig().AUTH_SECRET) as AuthModeMfaJwtTokenPayload;
const userEnc = await userDAL.findUserEncKeyByUserId(userId); const userEnc = await userDAL.findUserEncKeyByUserId(userId);
if (!userEnc) throw new Error("Failed to authenticate user"); if (!userEnc) throw new Error("Failed to authenticate user");
@@ -17,6 +17,7 @@ export type TLoginClientProofDTO = {
export type TVerifyMfaTokenDTO = { export type TVerifyMfaTokenDTO = {
userId: string; userId: string;
mfaToken: string; mfaToken: string;
mfaJwtToken: string;
ip: string; ip: string;
userAgent: string; userAgent: string;
orgId?: string; orgId?: string;