misc: removed mfa from existing login

This commit is contained in:
Sheen Capadngan
2024-10-16 22:44:04 +08:00
parent 36bb954373
commit 8da2213bf1
4 changed files with 52 additions and 76 deletions
@@ -280,10 +280,6 @@ export const registerSsoRouter = async (server: FastifyZodProvider) => {
providerAuthToken: req.body.providerAuthToken providerAuthToken: req.body.providerAuthToken
}); });
if (data.isMfaEnabled) {
return { mfaEnabled: true, token: data.token } as const; // for discriminated union
}
void res.setCookie("jid", data.token.refresh, { void res.setCookie("jid", data.token.refresh, {
httpOnly: true, httpOnly: true,
path: "/", path: "/",
+22 -21
View File
@@ -47,7 +47,8 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
}), }),
response: { response: {
200: z.object({ 200: z.object({
token: z.string() token: z.string(),
isMfaEnabled: z.boolean()
}) })
} }
}, },
@@ -60,6 +61,13 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
ipAddress: req.realIp ipAddress: req.realIp
}); });
if (tokens.isMfaEnabled) {
return {
token: tokens.mfa as string,
isMfaEnabled: true
};
}
void res.setCookie("jid", tokens.refresh, { void res.setCookie("jid", tokens.refresh, {
httpOnly: true, httpOnly: true,
path: "/", path: "/",
@@ -67,7 +75,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
secure: cfg.HTTPS_ENABLED secure: cfg.HTTPS_ENABLED
}); });
return { token: tokens.access }; return { token: tokens.access, isMfaEnabled: false };
} }
}); });
@@ -86,21 +94,18 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
password: z.string().optional() password: z.string().optional()
}), }),
response: { response: {
200: z.discriminatedUnion("mfaEnabled", [ 200: z.object({
z.object({ mfaEnabled: z.literal(true), token: z.string() }), mfaEnabled: z.literal(false),
z.object({ encryptionVersion: z.number().default(1).nullable().optional(),
mfaEnabled: z.literal(false), protectedKey: z.string().nullable(),
encryptionVersion: z.number().default(1).nullable().optional(), protectedKeyIV: z.string().nullable(),
protectedKey: z.string().nullable(), protectedKeyTag: z.string().nullable(),
protectedKeyIV: z.string().nullable(), publicKey: z.string(),
protectedKeyTag: z.string().nullable(), encryptedPrivateKey: z.string(),
publicKey: z.string(), iv: z.string(),
encryptedPrivateKey: z.string(), tag: z.string(),
iv: z.string(), token: z.string()
tag: z.string(), })
token: z.string()
})
])
} }
}, },
handler: async (req, res) => { handler: async (req, res) => {
@@ -118,10 +123,6 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
password: req.body.password password: req.body.password
}); });
if (data.isMfaEnabled) {
return { mfaEnabled: true, token: data.token } as const; // for discriminated union
}
void res.setCookie("jid", data.token.refresh, { void res.setCookie("jid", data.token.refresh, {
httpOnly: true, httpOnly: true,
path: "/", path: "/",
+29 -50
View File
@@ -298,30 +298,6 @@ export const authLoginServiceFactory = ({
}); });
} }
// send multi factor auth token if they it enabled
if (userEnc.isMfaEnabled && userEnc.email) {
enforceUserLockStatus(Boolean(user.isLocked), user.temporaryLockDateEnd);
const mfaToken = jwt.sign(
{
authMethod,
authTokenType: AuthTokenType.MFA_TOKEN,
userId: userEnc.userId
},
cfg.AUTH_SECRET,
{
expiresIn: cfg.JWT_MFA_LIFETIME
}
);
await sendUserMfaCode({
userId: userEnc.userId,
email: userEnc.email
});
return { isMfaEnabled: true, token: mfaToken } as const;
}
const token = await generateUserTokens({ const token = await generateUserTokens({
user: { user: {
...userEnc, ...userEnc,
@@ -333,7 +309,7 @@ export const authLoginServiceFactory = ({
organizationId organizationId
}); });
return { token, isMfaEnabled: false, user: userEnc } as const; return { token, user: userEnc } as const;
}; };
const selectOrganization = async ({ const selectOrganization = async ({
@@ -373,6 +349,30 @@ export const authLoginServiceFactory = ({
}); });
} }
// send multi factor auth token if they it enabled
if (user.isMfaEnabled && user.email) {
enforceUserLockStatus(Boolean(user.isLocked), user.temporaryLockDateEnd);
const mfaToken = jwt.sign(
{
authMethod: decodedToken.authMethod,
authTokenType: AuthTokenType.MFA_TOKEN,
userId: user.id
},
cfg.AUTH_SECRET,
{
expiresIn: cfg.JWT_MFA_LIFETIME
}
);
await sendUserMfaCode({
userId: user.id,
email: user.email
});
return { isMfaEnabled: true, mfa: mfaToken } as const;
}
const tokens = await generateUserTokens({ const tokens = await generateUserTokens({
authMethod: decodedToken.authMethod, authMethod: decodedToken.authMethod,
user, user,
@@ -381,7 +381,10 @@ export const authLoginServiceFactory = ({
organizationId organizationId
}); });
return tokens; return {
...tokens,
isMfaEnabled: false
};
}; };
/* /*
@@ -629,7 +632,6 @@ export const authLoginServiceFactory = ({
const oauth2TokenExchange = async ({ userAgent, ip, providerAuthToken, email }: TOauthTokenExchangeDTO) => { const oauth2TokenExchange = async ({ userAgent, ip, providerAuthToken, email }: TOauthTokenExchangeDTO) => {
const decodedProviderToken = validateProviderAuthToken(providerAuthToken, email); const decodedProviderToken = validateProviderAuthToken(providerAuthToken, email);
const appCfg = getConfig();
const { authMethod, userName } = decodedProviderToken; const { authMethod, userName } = decodedProviderToken;
if (!userName) throw new BadRequestError({ message: "Missing user name" }); if (!userName) throw new BadRequestError({ message: "Missing user name" });
const organizationId = const organizationId =
@@ -644,29 +646,6 @@ export const authLoginServiceFactory = ({
if (!userEnc) throw new BadRequestError({ message: "Invalid token" }); if (!userEnc) throw new BadRequestError({ message: "Invalid token" });
if (!userEnc.serverEncryptedPrivateKey) if (!userEnc.serverEncryptedPrivateKey)
throw new BadRequestError({ message: "Key handoff incomplete. Please try logging in again." }); throw new BadRequestError({ message: "Key handoff incomplete. Please try logging in again." });
// send multi factor auth token if they it enabled
if (userEnc.isMfaEnabled && userEnc.email) {
enforceUserLockStatus(Boolean(userEnc.isLocked), userEnc.temporaryLockDateEnd);
const mfaToken = jwt.sign(
{
authMethod,
authTokenType: AuthTokenType.MFA_TOKEN,
userId: userEnc.userId
},
appCfg.AUTH_SECRET,
{
expiresIn: appCfg.JWT_MFA_LIFETIME
}
);
await sendUserMfaCode({
userId: userEnc.userId,
email: userEnc.email
});
return { isMfaEnabled: true, token: mfaToken } as const;
}
const token = await generateUserTokens({ const token = await generateUserTokens({
user: { ...userEnc, id: userEnc.userId }, user: { ...userEnc, id: userEnc.userId },
+1 -1
View File
@@ -65,7 +65,7 @@ export const selectOrganization = async (data: {
organizationId: string; organizationId: string;
userAgent?: UserAgentType; userAgent?: UserAgentType;
}) => { }) => {
const { data: res } = await apiRequest.post<{ token: string }>( const { data: res } = await apiRequest.post<{ token: string; isMfaEnabled: boolean }>(
"/api/v3/auth/select-organization", "/api/v3/auth/select-organization",
data data
); );