Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete
This commit is contained in:
commit
64bb230de5
23 files changed
+846
-1248
No files matched your search
@@ -1,19 +1,25 @@
|
||||
// @ts-nocheck
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { checkLogin } from "@/lib/auth/password";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
import { captchaConfig, verifyCaptcha } from "@/lib/services/captcha";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
import { precheckLogin } from "./auth-precheck";
|
||||
|
||||
const { queryPreparedOne } = vi.hoisted(() => {
|
||||
const queryPreparedOne = vi.fn().mockResolvedValue(null);
|
||||
return { queryPreparedOne };
|
||||
});
|
||||
const core = vi.hoisted(() => ({
|
||||
getLoginUser: vi.fn(),
|
||||
verifyLoginPassword: vi.fn(),
|
||||
isEmailUnverified: vi.fn(),
|
||||
runDummyHashCheck: vi.fn(),
|
||||
normalizeLoginInput: (username: unknown, password: unknown) => ({
|
||||
username: String(username ?? "")
|
||||
.normalize("NFC")
|
||||
.trim(),
|
||||
password: String(password ?? "").normalize("NFC"),
|
||||
}),
|
||||
}));
|
||||
|
||||
vi.mock("@/env", () => ({ env: { CONVERT_PASSWORDS: false } }));
|
||||
vi.mock("@/lib/auth/password", () => ({ checkLogin: vi.fn() }));
|
||||
vi.mock("@/lib/db", () => ({ queryPreparedOne }));
|
||||
vi.mock("@/lib/auth/login-core", () => core);
|
||||
vi.mock("@/lib/rate-limit", () => ({ clientIp: vi.fn(), rateLimit: vi.fn() }));
|
||||
vi.mock("@/lib/services/captcha", () => ({
|
||||
captchaConfig: vi.fn(),
|
||||
@@ -23,33 +29,35 @@ vi.mock("@/lib/services/site-settings", () => ({
|
||||
siteSettings: { getBool: vi.fn() },
|
||||
}));
|
||||
|
||||
const user = (overrides = {}) => ({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
...overrides,
|
||||
});
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
vi.mocked(clientIp).mockResolvedValue("1.2.3.4");
|
||||
vi.mocked(rateLimit).mockResolvedValue({ ok: true });
|
||||
vi.mocked(checkLogin).mockResolvedValue({ valid: true } as never);
|
||||
vi.mocked(captchaConfig).mockResolvedValue({ provider: "none" } as never);
|
||||
queryPreparedOne.mockResolvedValue(null);
|
||||
core.getLoginUser.mockResolvedValue(null);
|
||||
core.verifyLoginPassword.mockResolvedValue({ valid: true });
|
||||
core.isEmailUnverified.mockResolvedValue(false);
|
||||
core.runDummyHashCheck.mockResolvedValue(undefined);
|
||||
});
|
||||
|
||||
describe("precheckLogin", () => {
|
||||
it("returns ok for valid login without 2FA", async () => {
|
||||
queryPreparedOne.mockResolvedValue({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
});
|
||||
core.getLoginUser.mockResolvedValue(user());
|
||||
expect(await precheckLogin("user", "pass")).toBe("ok");
|
||||
});
|
||||
|
||||
it("returns twofactor when 2FA is set up", async () => {
|
||||
queryPreparedOne.mockResolvedValue({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: new Date(),
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
});
|
||||
core.getLoginUser.mockResolvedValue(
|
||||
user({ twoFactorConfirmedAt: new Date() }),
|
||||
);
|
||||
expect(await precheckLogin("user", "pass")).toBe("twofactor");
|
||||
});
|
||||
|
||||
@@ -62,30 +70,20 @@ describe("precheckLogin", () => {
|
||||
provider: "hcaptcha",
|
||||
} as never);
|
||||
vi.mocked(verifyCaptcha).mockResolvedValue(false);
|
||||
queryPreparedOne.mockResolvedValue({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
});
|
||||
core.getLoginUser.mockResolvedValue(user());
|
||||
expect(await precheckLogin("user", "pass", "bad-token")).toBe("captcha");
|
||||
});
|
||||
|
||||
it("returns invalid when user not found (dummy hash check)", async () => {
|
||||
queryPreparedOne.mockResolvedValue(null);
|
||||
core.getLoginUser.mockResolvedValue(null);
|
||||
const result = await precheckLogin("nonexistent", "pass");
|
||||
expect(result).toBe("invalid");
|
||||
expect(checkLogin).toHaveBeenCalled();
|
||||
expect(core.runDummyHashCheck).toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("returns unverified when email verification required", async () => {
|
||||
queryPreparedOne.mockResolvedValue({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: "[email protected]",
|
||||
mailVerified: "0",
|
||||
});
|
||||
vi.mocked(siteSettings.getBool).mockResolvedValue(true);
|
||||
core.getLoginUser.mockResolvedValue(user({ mail: "[email protected]" }));
|
||||
core.isEmailUnverified.mockResolvedValue(true);
|
||||
expect(await precheckLogin("user", "pass")).toBe("unverified");
|
||||
});
|
||||
});
|
||||
@@ -1,11 +1,14 @@
|
||||
"use server";
|
||||
|
||||
import { env } from "@/env";
|
||||
import { checkLogin } from "@/lib/auth/password";
|
||||
import { queryPreparedOne } from "@/lib/db";
|
||||
import {
|
||||
getLoginUser,
|
||||
isEmailUnverified,
|
||||
normalizeLoginInput,
|
||||
runDummyHashCheck,
|
||||
verifyLoginPassword,
|
||||
} from "@/lib/auth/login-core";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
import { captchaConfig, verifyCaptcha } from "@/lib/services/captcha";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
|
||||
export type PrecheckResult =
|
||||
| "ok"
|
||||
@@ -24,10 +27,7 @@ export async function precheckLogin(
|
||||
password: string,
|
||||
captchaToken?: string | null,
|
||||
): Promise<PrecheckResult> {
|
||||
const u = String(username ?? "")
|
||||
.normalize("NFC")
|
||||
.trim();
|
||||
const p = String(password ?? "");
|
||||
const { username: u, password: p } = normalizeLoginInput(username, password);
|
||||
if (!u || !p) return "invalid";
|
||||
|
||||
const ip = await clientIp();
|
||||
@@ -38,49 +38,17 @@ export async function precheckLogin(
|
||||
if (!(await verifyCaptcha(captchaToken ?? null, ip))) return "captcha";
|
||||
}
|
||||
|
||||
let user: {
|
||||
password: string;
|
||||
twoFactorConfirmedAt: Date | null;
|
||||
mail: string | null;
|
||||
mailVerified: string;
|
||||
} | null;
|
||||
try {
|
||||
user = await queryPreparedOne<{
|
||||
password: string;
|
||||
twoFactorConfirmedAt: Date | null;
|
||||
mail: string | null;
|
||||
mailVerified: string;
|
||||
}>(
|
||||
`SELECT password, two_factor_confirmed_at AS twoFactorConfirmedAt,
|
||||
mail, mail_verified AS mailVerified
|
||||
FROM users WHERE username = ? LIMIT 1`,
|
||||
[u],
|
||||
);
|
||||
} catch {
|
||||
return "invalid";
|
||||
}
|
||||
const user = await getLoginUser(u);
|
||||
if (!user) {
|
||||
// Prevent timing-based enumeration: always run a dummy hash check.
|
||||
await checkLogin(
|
||||
p,
|
||||
"$2y$12$abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZabcd",
|
||||
{
|
||||
convertPasswords: false,
|
||||
},
|
||||
);
|
||||
await runDummyHashCheck(p);
|
||||
return "invalid";
|
||||
}
|
||||
|
||||
const res = await checkLogin(p, user.password, {
|
||||
convertPasswords: env.CONVERT_PASSWORDS,
|
||||
});
|
||||
const res = await verifyLoginPassword(user, p);
|
||||
if (!res.valid) return "invalid";
|
||||
|
||||
if (
|
||||
(await siteSettings.getBool("require_email_verification", false)) &&
|
||||
user.mail &&
|
||||
user.mailVerified !== "1"
|
||||
) {
|
||||
if (await isEmailUnverified(user)) {
|
||||
return "unverified";
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user