feat: hashpassword and add validation endpoint

This commit is contained in:
lemmyMwaura
2024-08-06 17:01:13 +03:00
parent 15cc157c5f
commit e420973dd2
2 changed files with 48 additions and 1 deletions

View File

@@ -1,4 +1,5 @@
import { z } from "zod";
import bcrypt from "bcrypt"
import { SecretSharingSchema } from "@app/db/schemas";
import { SecretSharingAccessType } from "@app/lib/types";
@@ -94,6 +95,49 @@ export const registerSecretSharingRouter = async (server: FastifyZodProvider) =>
}
});
server.route({
method: "POST",
url: "/public/:id/validate",
config: {
rateLimit: publicEndpointLimit
},
schema: {
params: z.object({
id: z.string().uuid()
}),
body: z.object({
password: z.string().min(1),
hashedHex: z.string()
}),
response: {
200: z.object({
isValid: z.boolean()
})
}
},
handler: async (req) => {
const { id } = req.params;
const { password, hashedHex } = req.body;
const sharedSecret = await req.server.services.secretSharing.getActiveSharedSecretById({
sharedSecretId: id,
hashedHex,
orgId: req.permission?.orgId
});
if (!sharedSecret) {
return { isValid: false };
}
if (sharedSecret.password) {
const isMatch = await bcrypt.compare(password, sharedSecret.password);
return { isValid: isMatch };
}
return { isValid: false };
}
});
server.route({
method: "POST",
url: "/public",

View File

@@ -1,3 +1,5 @@
import bcrypt from "bcrypt";
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
import { BadRequestError, ForbiddenRequestError, NotFoundError, UnauthorizedError } from "@app/lib/errors";
import { SecretSharingAccessType } from "@app/lib/types";
@@ -61,9 +63,10 @@ export const secretSharingServiceFactory = ({
throw new BadRequestError({ message: "Shared secret value too long" });
}
const hashedPassword = password ? await bcrypt.hash(password, 10) : null;
const newSharedSecret = await secretSharingDAL.create({
name,
password,
password: hashedPassword,
encryptedValue,
hashedHex,
iv,