Security hardening: 12 improvements across the stack
1. env.ts: APP_KEY placeholder detection with validation 2. schema.prisma: password column widened to varchar(255) for argon2id 3. auth.ts: trustHost restricted to development only 4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers 5. api.ts: CORS restricted to APP_URL instead of wildcard 6. register-form.tsx: migrated from REST API fetch to server action (useActionState) 7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed) 8. register.ts: password min length 8 + complexity requirements (upper, lower, digit) 9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation 10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets 11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff) 12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
This commit is contained in:
1 parent
a1950e5b65
commit
5628e7d6b7
19 files changed
+370
-220
No files matched your search
@@ -23,11 +23,11 @@ export default async function TwoFactorPage({
|
||||
const sp = await searchParams;
|
||||
const id = Number(session.user.id);
|
||||
|
||||
let user: { twoFactorSecret: string | null; twoFactorConfirmedAt: Date | null } | null = null;
|
||||
let user: { twoFactorSecret: string | null; twoFactorConfirmedAt: Date | null; twoFactorRecoveryCodes: string | null } | null = null;
|
||||
try {
|
||||
user = await prisma.user.findUnique({
|
||||
where: { id },
|
||||
select: { twoFactorSecret: true, twoFactorConfirmedAt: true },
|
||||
select: { twoFactorSecret: true, twoFactorConfirmedAt: true, twoFactorRecoveryCodes: true },
|
||||
});
|
||||
} catch {
|
||||
user = null;
|
||||
@@ -40,10 +40,14 @@ export default async function TwoFactorPage({
|
||||
|
||||
let secret = "";
|
||||
let uri = "";
|
||||
let recoveryCodes: string[] = [];
|
||||
if (pending && hasAppKey && user?.twoFactorSecret) {
|
||||
try {
|
||||
secret = new LaravelEncrypter(env.APP_KEY as string).decrypt(user.twoFactorSecret);
|
||||
uri = totpKeyUri(secret, session.user.name ?? "user", hotelName);
|
||||
if (user.twoFactorRecoveryCodes) {
|
||||
recoveryCodes = JSON.parse(user.twoFactorRecoveryCodes) as string[];
|
||||
}
|
||||
} catch {
|
||||
secret = "";
|
||||
}
|
||||
@@ -61,7 +65,40 @@ export default async function TwoFactorPage({
|
||||
subtitle={t("subtitle")}
|
||||
>
|
||||
{sp.enabled ? (
|
||||
<p style={{ color: "var(--color-accent)", marginTop: 0 }}>{t("nowEnabled")}</p>
|
||||
<>
|
||||
<p style={{ color: "var(--color-accent)", marginTop: 0 }}>{t("nowEnabled")}</p>
|
||||
<div style={{
|
||||
background: "var(--color-surface)",
|
||||
border: "1px solid var(--color-border)",
|
||||
borderRadius: 8,
|
||||
padding: "1rem",
|
||||
marginTop: "0.5rem",
|
||||
}}>
|
||||
<h4 style={{ margin: "0 0 0.5rem" }}>Recovery Codes</h4>
|
||||
<p className="muted" style={{ fontSize: "0.85rem", margin: "0 0 0.75rem" }}>
|
||||
Store these one-time use codes in a safe place. Each can be used once
|
||||
if you lose access to your authenticator app.
|
||||
</p>
|
||||
<div style={{
|
||||
display: "grid",
|
||||
gridTemplateColumns: "1fr 1fr",
|
||||
gap: "0.25rem",
|
||||
fontFamily: "monospace",
|
||||
fontSize: "0.9rem",
|
||||
}}>
|
||||
{recoveryCodes.map((code) => (
|
||||
<code key={code} style={{
|
||||
userSelect: "all",
|
||||
padding: "0.25rem 0.5rem",
|
||||
background: "var(--color-background)",
|
||||
borderRadius: 4,
|
||||
}}>
|
||||
{code}
|
||||
</code>
|
||||
))}
|
||||
</div>
|
||||
</div>
|
||||
</>
|
||||
) : null}
|
||||
{sp.disabled ? (
|
||||
<p className="muted" style={{ marginTop: 0 }}>
|
||||
|
||||
Reference in new issue
Block a user