Security hardening: 12 improvements across the stack

1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
This commit is contained in:
openhands committed 2026-07-04 18:52:00 +02:00
1 parent a1950e5b65
commit 5628e7d6b7
19 files changed
+370 -220

No files matched your search

+40 -3
View File
@@ -23,11 +23,11 @@ export default async function TwoFactorPage({
const sp = await searchParams;
const id = Number(session.user.id);
let user: { twoFactorSecret: string | null; twoFactorConfirmedAt: Date | null } | null = null;
let user: { twoFactorSecret: string | null; twoFactorConfirmedAt: Date | null; twoFactorRecoveryCodes: string | null } | null = null;
try {
user = await prisma.user.findUnique({
where: { id },
select: { twoFactorSecret: true, twoFactorConfirmedAt: true },
select: { twoFactorSecret: true, twoFactorConfirmedAt: true, twoFactorRecoveryCodes: true },
});
} catch {
user = null;
@@ -40,10 +40,14 @@ export default async function TwoFactorPage({
let secret = "";
let uri = "";
let recoveryCodes: string[] = [];
if (pending && hasAppKey && user?.twoFactorSecret) {
try {
secret = new LaravelEncrypter(env.APP_KEY as string).decrypt(user.twoFactorSecret);
uri = totpKeyUri(secret, session.user.name ?? "user", hotelName);
if (user.twoFactorRecoveryCodes) {
recoveryCodes = JSON.parse(user.twoFactorRecoveryCodes) as string[];
}
} catch {
secret = "";
}
@@ -61,7 +65,40 @@ export default async function TwoFactorPage({
subtitle={t("subtitle")}
>
{sp.enabled ? (
<p style={{ color: "var(--color-accent)", marginTop: 0 }}>{t("nowEnabled")}</p>
<>
<p style={{ color: "var(--color-accent)", marginTop: 0 }}>{t("nowEnabled")}</p>
<div style={{
background: "var(--color-surface)",
border: "1px solid var(--color-border)",
borderRadius: 8,
padding: "1rem",
marginTop: "0.5rem",
}}>
<h4 style={{ margin: "0 0 0.5rem" }}>Recovery Codes</h4>
<p className="muted" style={{ fontSize: "0.85rem", margin: "0 0 0.75rem" }}>
Store these one-time use codes in a safe place. Each can be used once
if you lose access to your authenticator app.
</p>
<div style={{
display: "grid",
gridTemplateColumns: "1fr 1fr",
gap: "0.25rem",
fontFamily: "monospace",
fontSize: "0.9rem",
}}>
{recoveryCodes.map((code) => (
<code key={code} style={{
userSelect: "all",
padding: "0.25rem 0.5rem",
background: "var(--color-background)",
borderRadius: 4,
}}>
{code}
</code>
))}
</div>
</div>
</>
) : null}
{sp.disabled ? (
<p className="muted" style={{ marginTop: 0 }}>