feat: check if secret is expired before checking if secret has password

This commit is contained in:
lemmyMwaura
2024-08-07 19:23:10 +03:00
parent 69fe5bf71d
commit b0a5023723
6 changed files with 42 additions and 34 deletions

View File

@@ -80,7 +80,7 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
orgId: req.permission?.orgId orgId: req.permission?.orgId
}); });
// only return secret if it exists and has no password set // return undefined if it does not exist, has password set or has no more views allowed.
if (!sharedSecret || sharedSecret.password) return undefined; if (!sharedSecret || sharedSecret.password) return undefined;
return { return {

View File

@@ -179,10 +179,12 @@ export const secretSharingServiceFactory = ({
if (accessType === SecretSharingAccessType.Organization && orgId !== sharedSecret.orgId) if (accessType === SecretSharingAccessType.Organization && orgId !== sharedSecret.orgId)
throw new UnauthorizedError(); throw new UnauthorizedError();
if (sharedSecret.password) return undefined; await checkIfExpired(sharedSecret, sharedSecretId);
if (sharedSecret.password !== null) return undefined;
// we only update the view count when secret has no password, when password is set view count is updated when we validate the password. // decrement when we are sure the user will view secret.
manageSecretViewCount(sharedSecret, sharedSecretId); await decrementSecretViewCount(sharedSecret, sharedSecretId);
return { return {
...sharedSecret, ...sharedSecret,
@@ -215,13 +217,11 @@ export const secretSharingServiceFactory = ({
if (accessType === SecretSharingAccessType.Organization && orgId !== sharedSecret.orgId) if (accessType === SecretSharingAccessType.Organization && orgId !== sharedSecret.orgId)
throw new UnauthorizedError(); throw new UnauthorizedError();
if (!sharedSecret.password) return undefined;
const isMatch = await bcrypt.compare(password, sharedSecret.password); const isMatch = await bcrypt.compare(password, sharedSecret.password);
if (!isMatch) return undefined; if (!isMatch) return undefined
// reduce view count when we are sure the password matches. // we reduce the view count when we are sure the password matches.
manageSecretViewCount(sharedSecret, sharedSecretId) await decrementSecretViewCount(sharedSecret, sharedSecretId);
return { return {
...sharedSecret, ...sharedSecret,
@@ -240,7 +240,8 @@ export const secretSharingServiceFactory = ({
return deletedSharedSecret; return deletedSharedSecret;
}; };
const manageSecretViewCount = async (sharedSecret: any, sharedSecretId: string) => { /** Checks if secret is expired and throws error if true */
const checkIfExpired = async (sharedSecret: any, sharedSecretId: string) => {
const { expiresAt, expiresAfterViews } = sharedSecret; const { expiresAt, expiresAfterViews } = sharedSecret;
if (expiresAt !== null && expiresAt < new Date()) { if (expiresAt !== null && expiresAt < new Date()) {
@@ -258,6 +259,10 @@ export const secretSharingServiceFactory = ({
message: "Access denied: Secret has expired by view count" message: "Access denied: Secret has expired by view count"
}); });
} }
}
const decrementSecretViewCount = async (sharedSecret: any, sharedSecretId: string) => {
const { expiresAfterViews } = sharedSecret;
if (expiresAfterViews) { if (expiresAfterViews) {
// decrement view count if view count expiry set // decrement view count if view count expiry set

View File

@@ -2,7 +2,7 @@ import { useQuery } from "@tanstack/react-query";
import { apiRequest } from "@app/config/request"; import { apiRequest } from "@app/config/request";
import { TSharedSecret, TViewSharedSecretResponse, ValidateSecretPassword } from "./types"; import { TSharedSecret, TViewSharedSecretResponse } from "./types";
export const secretSharingKeys = { export const secretSharingKeys = {
allSharedSecrets: () => ["sharedSecrets"] as const, allSharedSecrets: () => ["sharedSecrets"] as const,
@@ -77,7 +77,7 @@ export const fetchSecretIfPasswordIsValid = async (
hashedHex: string, hashedHex: string,
password: string, password: string,
) => { ) => {
const { data } = await apiRequest.post<ValidateSecretPassword>( const { data } = await apiRequest.post<TViewSharedSecretResponse>(
`/api/v1/secret-sharing/public/${sharedSecretId}/validate`, `/api/v1/secret-sharing/public/${sharedSecretId}/validate`,
{ {
hashedHex, hashedHex,

View File

@@ -31,7 +31,6 @@ export type TViewSharedSecretResponse = {
tag: string; tag: string;
accessType: SecretSharingAccessType; accessType: SecretSharingAccessType;
orgName?: string; orgName?: string;
password?: string;
}; };
export type TDeleteSharedSecretRequest = { export type TDeleteSharedSecretRequest = {
@@ -41,8 +40,4 @@ export type TDeleteSharedSecretRequest = {
export enum SecretSharingAccessType { export enum SecretSharingAccessType {
Anyone = "anyone", Anyone = "anyone",
Organization = "organization" Organization = "organization"
} }
export type ValidateSecretPassword = {
isValid: boolean
}

View File

@@ -5,12 +5,13 @@ import { useRouter } from "next/router";
import { faArrowRight } from "@fortawesome/free-solid-svg-icons"; import { faArrowRight } from "@fortawesome/free-solid-svg-icons";
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
import { useGetActiveSharedSecretById } from "@app/hooks/api/secretSharing"; import { TViewSharedSecretResponse, useGetActiveSharedSecretById } from "@app/hooks/api/secretSharing";
import { SecretContainer, SecretErrorContainer, PasswordContainer } from "./components"; import { SecretContainer, SecretErrorContainer, PasswordContainer } from "./components";
export const ViewSecretPublicPage = () => { export const ViewSecretPublicPage = () => {
const [secret, setSecret] = useState(null) const [secret, setSecret] = useState(null)
const [error, setError] = useState(null)
const router = useRouter(); const router = useRouter();
const { id, key: urlEncodedPublicKey } = router.query; const { id, key: urlEncodedPublicKey } = router.query;
@@ -18,17 +19,18 @@ export const ViewSecretPublicPage = () => {
? urlEncodedPublicKey.toString().split("-") ? urlEncodedPublicKey.toString().split("-")
: ["", ""]; : ["", ""];
const { data, error } = useGetActiveSharedSecretById({ const { data: fetchSecret, error: fetchError, isLoading } = useGetActiveSharedSecretById({
sharedSecretId: id as string, sharedSecretId: id as string,
hashedHex hashedHex
}); });
useEffect(() => { useEffect(() => {
if (data) setSecret(data) if (fetchSecret) setSecret(fetchSecret)
}, [data]) if (fetchError) setError(fetchError)
}, [fetchSecret, fetchError])
const handleSecret = useCallback((val: any) => { const handleSecret = useCallback((value: TViewSharedSecretResponse) => {
setSecret(val) setSecret(value)
}, [setSecret]) }, [setSecret])
return ( return (
@@ -62,13 +64,19 @@ export const ViewSecretPublicPage = () => {
</a> </a>
</p> </p>
</div> </div>
{!secret ? ( {!isLoading && (
<PasswordContainer secretId={id as string} hashedHex={hashedHex} handleSecret={handleSecret} /> <>
) : ( {!error && !secret && (
key && <SecretContainer secret={secret} secretKey={key} /> <PasswordContainer
) secretId={id as string}
} hashedHex={hashedHex}
{error && <SecretErrorContainer />} handleSecret={handleSecret}
/>
)}
{!error && secret && key && <SecretContainer secret={secret} secretKey={key} />}
{error && <SecretErrorContainer />}
</>
)}
<div className="m-auto my-8 flex w-full"> <div className="m-auto my-8 flex w-full">
<div className="w-full border-t border-mineshaft-600" /> <div className="w-full border-t border-mineshaft-600" />
</div> </div>

View File

@@ -6,7 +6,7 @@ import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
import { zodResolver } from "@hookform/resolvers/zod"; import { zodResolver } from "@hookform/resolvers/zod";
import { Button, FormControl, IconButton, Input } from "@app/components/v2"; import { Button, FormControl, IconButton, Input } from "@app/components/v2";
import { fetchSecretIfPasswordIsValid } from "@app/hooks/api/secretSharing"; import { fetchSecretIfPasswordIsValid, TViewSharedSecretResponse } from "@app/hooks/api/secretSharing";
import { createNotification } from "@app/components/notifications"; import { createNotification } from "@app/components/notifications";
type Props = { type Props = {
@@ -33,7 +33,7 @@ export const PasswordContainer = ({ secretId, hashedHex, handleSecret }: Props)
const onFormSubmit = async ({ password }: FormData) => { const onFormSubmit = async ({ password }: FormData) => {
try { try {
const secret = await fetchSecretIfPasswordIsValid( const secret: TViewSharedSecretResponse = await fetchSecretIfPasswordIsValid(
secretId, secretId,
hashedHex, hashedHex,
password, password,
@@ -71,7 +71,7 @@ export const PasswordContainer = ({ secretId, hashedHex, handleSecret }: Props)
label="Password" label="Password"
> >
<div className="flex items-center gap-2 justify-between rounded-md"> <div className="flex items-center gap-2 justify-between rounded-md">
<Input {...field} placeholder="Enter Password to view secret"></Input> <Input {...field} placeholder="Enter Password to view secret" type="password"></Input>
<div className="flex"> <div className="flex">
<IconButton <IconButton
ariaLabel="copy icon" ariaLabel="copy icon"