Harden CMS security and theme contrast

This commit is contained in:
Simo committed 2026-07-11 20:27:20 +02:00
1 parent 2465ff2170
commit 4a1e1115b3
57 files changed
+1023 -231

No files matched your search

+4 -5
View File
@@ -1,5 +1,7 @@
import { createHash, randomBytes } from "node:crypto";
import { prisma } from "@/lib/prisma";
import { personalTokenScope, USER_TOKENABLE_TYPE } from "@/lib/auth/personal-token-scope";
import { databaseUserId } from "@/lib/auth/session-user";
/**
* Bearer-token auth for the public REST API, backed by personal_access_tokens
@@ -7,8 +9,6 @@ import { prisma } from "@/lib/prisma";
* stored as the sha256 of the plaintext; the client sends the plaintext (or the
* Sanctum "{id}|{plaintext}" form) as `Authorization: Bearer …`.
*/
const TOKENABLE_TYPE = "App\\Models\\User";
function hashToken(raw: string): string {
return createHash("sha256").update(raw).digest("hex");
}
@@ -36,7 +36,7 @@ export async function bearerUserId(req: Request): Promise<number | null> {
prisma.personalAccessTokens
.update({ where: { id: row.id }, data: { lastUsedAt: new Date() }, select: { id: true } })
.catch(() => {});
return Number(row.tokenableId);
return databaseUserId(row.tokenableId);
} catch {
return null;
}
@@ -48,8 +48,7 @@ export async function issueToken(userId: number, name = "api"): Promise<string |
try {
await prisma.personalAccessTokens.create({
data: {
tokenableId: BigInt(userId),
tokenableType: TOKENABLE_TYPE,
...personalTokenScope(userId),
name: name.slice(0, 100),
token: hashToken(plaintext),
abilities: '["*"]',