Harden CMS security and theme contrast
This commit is contained in:
1 parent
2465ff2170
commit
4a1e1115b3
57 files changed
+1023
-231
No files matched your search
+4
-5
@@ -1,5 +1,7 @@
|
||||
import { createHash, randomBytes } from "node:crypto";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { personalTokenScope, USER_TOKENABLE_TYPE } from "@/lib/auth/personal-token-scope";
|
||||
import { databaseUserId } from "@/lib/auth/session-user";
|
||||
|
||||
/**
|
||||
* Bearer-token auth for the public REST API, backed by personal_access_tokens
|
||||
@@ -7,8 +9,6 @@ import { prisma } from "@/lib/prisma";
|
||||
* stored as the sha256 of the plaintext; the client sends the plaintext (or the
|
||||
* Sanctum "{id}|{plaintext}" form) as `Authorization: Bearer …`.
|
||||
*/
|
||||
const TOKENABLE_TYPE = "App\\Models\\User";
|
||||
|
||||
function hashToken(raw: string): string {
|
||||
return createHash("sha256").update(raw).digest("hex");
|
||||
}
|
||||
@@ -36,7 +36,7 @@ export async function bearerUserId(req: Request): Promise<number | null> {
|
||||
prisma.personalAccessTokens
|
||||
.update({ where: { id: row.id }, data: { lastUsedAt: new Date() }, select: { id: true } })
|
||||
.catch(() => {});
|
||||
return Number(row.tokenableId);
|
||||
return databaseUserId(row.tokenableId);
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
@@ -48,8 +48,7 @@ export async function issueToken(userId: number, name = "api"): Promise<string |
|
||||
try {
|
||||
await prisma.personalAccessTokens.create({
|
||||
data: {
|
||||
tokenableId: BigInt(userId),
|
||||
tokenableType: TOKENABLE_TYPE,
|
||||
...personalTokenScope(userId),
|
||||
name: name.slice(0, 100),
|
||||
token: hashToken(plaintext),
|
||||
abilities: '["*"]',
|
||||
|
||||
Reference in new issue
Block a user