feat: applied hashed password change in change-password route

This commit is contained in:
=
2024-06-12 19:25:06 +05:30
parent e3f87382a3
commit a9bec84d27
8 changed files with 768 additions and 213 deletions
@@ -51,7 +51,8 @@ export const registerPasswordRouter = async (server: FastifyZodProvider) => {
encryptedPrivateKeyIV: z.string().trim(), encryptedPrivateKeyIV: z.string().trim(),
encryptedPrivateKeyTag: z.string().trim(), encryptedPrivateKeyTag: z.string().trim(),
salt: z.string().trim(), salt: z.string().trim(),
verifier: z.string().trim() verifier: z.string().trim(),
password: z.string().trim()
}), }),
response: { response: {
200: z.object({ 200: z.object({
+13 -4
View File
@@ -20,11 +20,20 @@ export const registerUserRouter = async (server: FastifyZodProvider) => {
response: { response: {
200: z.object({ 200: z.object({
user: UsersSchema.merge( user: UsersSchema.merge(
UserEncryptionKeysSchema.omit({ UserEncryptionKeysSchema.pick({
clientPublicKey: true,
serverPrivateKey: true,
encryptionVersion: true,
protectedKey: true,
protectedKeyIV: true,
protectedKeyTag: true,
publicKey: true,
encryptedPrivateKey: true,
iv: true,
tag: true,
salt: true,
verifier: true, verifier: true,
serverEncryptedPrivateKey: true, userId: true
serverEncryptedPrivateKeyIV: true,
serverEncryptedPrivateKeyTag: true
}) })
) )
}) })
+17 -1
View File
@@ -255,7 +255,23 @@ export const registerUserRouter = async (server: FastifyZodProvider) => {
description: "Retrieve the current user on the request", description: "Retrieve the current user on the request",
response: { response: {
200: z.object({ 200: z.object({
user: UsersSchema.merge(UserEncryptionKeysSchema.omit({ verifier: true })) user: UsersSchema.merge(
UserEncryptionKeysSchema.pick({
clientPublicKey: true,
serverPrivateKey: true,
encryptionVersion: true,
protectedKey: true,
protectedKeyIV: true,
protectedKeyTag: true,
publicKey: true,
encryptedPrivateKey: true,
iv: true,
tag: true,
salt: true,
verifier: true,
userId: true
})
)
}) })
} }
}, },
@@ -1,3 +1,4 @@
import bcrypt from "bcrypt";
import jwt from "jsonwebtoken"; import jwt from "jsonwebtoken";
import { SecretEncryptionAlgo, SecretKeyEncoding } from "@app/db/schemas"; import { SecretEncryptionAlgo, SecretKeyEncoding } from "@app/db/schemas";
@@ -57,7 +58,8 @@ export const authPaswordServiceFactory = ({
encryptedPrivateKeyTag, encryptedPrivateKeyTag,
salt, salt,
verifier, verifier,
tokenVersionId tokenVersionId,
password
}: TChangePasswordDTO) => { }: TChangePasswordDTO) => {
const userEnc = await userDAL.findUserEncKeyByUserId(userId); const userEnc = await userDAL.findUserEncKeyByUserId(userId);
if (!userEnc) throw new Error("Failed to find user"); if (!userEnc) throw new Error("Failed to find user");
@@ -76,6 +78,8 @@ export const authPaswordServiceFactory = ({
); );
if (!isValidClientProof) throw new Error("Failed to authenticate. Try again?"); if (!isValidClientProof) throw new Error("Failed to authenticate. Try again?");
const appCfg = getConfig();
const hashedPassword = await bcrypt.hash(password, appCfg.BCRYPT_SALT_ROUND);
await userDAL.updateUserEncryptionByUserId(userId, { await userDAL.updateUserEncryptionByUserId(userId, {
encryptionVersion: 2, encryptionVersion: 2,
protectedKey, protectedKey,
@@ -87,7 +91,8 @@ export const authPaswordServiceFactory = ({
salt, salt,
verifier, verifier,
serverPrivateKey: null, serverPrivateKey: null,
clientPublicKey: null clientPublicKey: null,
password: hashedPassword
}); });
if (tokenVersionId) { if (tokenVersionId) {
@@ -10,6 +10,7 @@ export type TChangePasswordDTO = {
salt: string; salt: string;
verifier: string; verifier: string;
tokenVersionId?: string; tokenVersionId?: string;
password: string;
}; };
export type TResetPasswordViaBackupKeyDTO = { export type TResetPasswordViaBackupKeyDTO = {
+726 -205
View File
File diff suppressed because it is too large Load Diff
@@ -72,6 +72,7 @@ const attemptChangePassword = ({ email, currentPassword, newPassword }: Params):
}); });
await changePassword({ await changePassword({
password: newPassword,
clientProof, clientProof,
protectedKey, protectedKey,
protectedKeyIV, protectedKeyIV,
+1
View File
@@ -108,6 +108,7 @@ export type VerifySignupInviteDTO = {
}; };
export type ChangePasswordDTO = { export type ChangePasswordDTO = {
password: string;
clientProof: string; clientProof: string;
protectedKey: string; protectedKey: string;
protectedKeyIV: string; protectedKeyIV: string;