fix: resolve auth security issues - 2FA require TOTP on disable, rate limiting, timing-safe login, token expiry check
This commit is contained in:
1 parent
4a06b30263
commit
64f50b2dde
6 files changed
+63
-9
No files matched your search
@@ -2,6 +2,7 @@
|
||||
|
||||
import { checkLogin } from "@/lib/auth/password";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
import { env } from "@/env";
|
||||
|
||||
export type PrecheckResult = "ok" | "invalid" | "twofactor";
|
||||
@@ -18,6 +19,8 @@ export async function precheckLogin(
|
||||
const p = String(password ?? "");
|
||||
if (!u || !p) return "invalid";
|
||||
|
||||
if (!rateLimit(`precheck:${await clientIp()}`, 10, 5 * 60_000).ok) return "invalid";
|
||||
|
||||
let user: { password: string; twoFactorConfirmedAt: Date | null } | null = null;
|
||||
try {
|
||||
user = await prisma.user.findUnique({
|
||||
@@ -27,7 +30,15 @@ export async function precheckLogin(
|
||||
} catch {
|
||||
return "invalid";
|
||||
}
|
||||
if (!user) return "invalid";
|
||||
if (!user) {
|
||||
// Prevent timing-based enumeration: always run a dummy hash check.
|
||||
await checkLogin(
|
||||
p,
|
||||
"$2y$12$abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZabcd",
|
||||
{ convertPasswords: false },
|
||||
);
|
||||
return "invalid";
|
||||
}
|
||||
|
||||
const res = await checkLogin(p, user.password, {
|
||||
convertPasswords: env.CONVERT_PASSWORDS,
|
||||
|
||||
@@ -14,9 +14,11 @@ import { siteSettings } from "@/lib/services/site-settings";
|
||||
// The token is therefore deterministic per (email, secret) pair and stays valid
|
||||
// until the account's mail_verified flips to '1' (after which /verify no-ops).
|
||||
|
||||
/** Secret mixed into the digest. Falls back to AUTH_SECRET, then a constant. */
|
||||
/** Secret mixed into the digest. Requires at least one of APP_KEY or AUTH_SECRET. */
|
||||
function verifySecret(): string {
|
||||
return env.APP_KEY || env.AUTH_SECRET || "atom-cms-verify";
|
||||
const secret = env.APP_KEY || env.AUTH_SECRET;
|
||||
if (!secret) throw new Error("APP_KEY or AUTH_SECRET must be set for email verification");
|
||||
return secret;
|
||||
}
|
||||
|
||||
/** Compute the verification token for an email (lowercased + trimmed). */
|
||||
|
||||
@@ -6,6 +6,7 @@ import { LaravelEncrypter } from "@/lib/auth/laravel-encrypter";
|
||||
import { generateTotpSecret, verifyTotp } from "@/lib/auth/totp";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
import { env } from "@/env";
|
||||
|
||||
async function sessionUserId(): Promise<number> {
|
||||
@@ -31,6 +32,9 @@ export async function beginTwoFactor(): Promise<void> {
|
||||
export async function confirmTwoFactor(formData: FormData): Promise<void> {
|
||||
const id = await sessionUserId();
|
||||
if (!env.APP_KEY) redirect("/settings/2fa?error=noappkey");
|
||||
|
||||
if (!rateLimit(`2fa-confirm:${id}`, 5, 30_000).ok) redirect("/settings/2fa?error=ratelimit");
|
||||
|
||||
const code = String(formData.get("code") ?? "").trim();
|
||||
|
||||
const user = await prisma.user.findUnique({
|
||||
@@ -53,8 +57,30 @@ export async function confirmTwoFactor(formData: FormData): Promise<void> {
|
||||
redirect("/settings/2fa?enabled=1");
|
||||
}
|
||||
|
||||
export async function disableTwoFactor(): Promise<void> {
|
||||
export async function disableTwoFactor(formData: FormData): Promise<void> {
|
||||
const id = await sessionUserId();
|
||||
if (!env.APP_KEY) redirect("/settings/2fa?error=noappkey");
|
||||
|
||||
if (!rateLimit(`2fa-disable:${id}`, 5, 30_000).ok) redirect("/settings/2fa?error=ratelimit");
|
||||
|
||||
const code = String(formData.get("code") ?? "").trim();
|
||||
|
||||
const user = await prisma.user.findUnique({
|
||||
where: { id },
|
||||
select: { twoFactorSecret: true },
|
||||
});
|
||||
|
||||
let ok = false;
|
||||
if (user?.twoFactorSecret && code) {
|
||||
try {
|
||||
const secret = new LaravelEncrypter(env.APP_KEY).decrypt(user.twoFactorSecret);
|
||||
ok = verifyTotp(code, secret);
|
||||
} catch {
|
||||
ok = false;
|
||||
}
|
||||
}
|
||||
if (!ok) redirect("/settings/2fa?error=badcode");
|
||||
|
||||
await prisma.user.update({
|
||||
where: { id },
|
||||
data: {
|
||||
|
||||
@@ -73,6 +73,11 @@ export default async function TwoFactorPage({
|
||||
{t("badCode")}
|
||||
</p>
|
||||
) : null}
|
||||
{sp.error === "ratelimit" ? (
|
||||
<p style={{ color: "var(--color-danger)", marginTop: 0 }}>
|
||||
{t("rateLimit")}
|
||||
</p>
|
||||
) : null}
|
||||
|
||||
{!hasAppKey ? (
|
||||
<p style={{ margin: 0 }}>
|
||||
@@ -84,7 +89,8 @@ export default async function TwoFactorPage({
|
||||
<p style={{ marginTop: 0 }}>
|
||||
<strong>{t("isEnabled")}</strong> {t("onYourAccount")}
|
||||
</p>
|
||||
<form action={disableTwoFactor}>
|
||||
<form action={disableTwoFactor} style={{ display: "flex", gap: "0.5rem" }}>
|
||||
<input name="code" placeholder={t("codePlaceholder")} inputMode="numeric" required />
|
||||
<button type="submit" className="btn btn-danger">
|
||||
{t("disable")}
|
||||
</button>
|
||||
|
||||
+4
-3
@@ -6,8 +6,6 @@ import { prisma } from "@/lib/prisma";
|
||||
* (the Laravel Sanctum table that already exists in the emulator DB). Tokens are
|
||||
* stored as the sha256 of the plaintext; the client sends the plaintext (or the
|
||||
* Sanctum "{id}|{plaintext}" form) as `Authorization: Bearer …`.
|
||||
*
|
||||
* NOTE: the live amx_test table has NO expires_at column — never read/write it.
|
||||
*/
|
||||
const TOKENABLE_TYPE = "App\\Models\\User";
|
||||
|
||||
@@ -27,7 +25,10 @@ export async function bearerUserId(req: Request): Promise<number | null> {
|
||||
|
||||
try {
|
||||
const row = await prisma.personalAccessTokens.findFirst({
|
||||
where: { token: hashToken(raw) },
|
||||
where: {
|
||||
token: hashToken(raw),
|
||||
OR: [{ expiresAt: null }, { expiresAt: { gt: new Date() } }],
|
||||
},
|
||||
select: { id: true, tokenableId: true },
|
||||
});
|
||||
if (!row) return null;
|
||||
|
||||
+9
-1
@@ -29,7 +29,15 @@ export const { handlers, signIn, signOut, auth } = NextAuth({
|
||||
if (!rateLimit(`login:${await clientIp()}`, 10, 5 * 60_000).ok) return null;
|
||||
|
||||
const user = await prisma.user.findUnique({ where: { username } });
|
||||
if (!user) return null;
|
||||
if (!user) {
|
||||
// Prevent timing-based enumeration: always run a dummy hash check.
|
||||
await checkLogin(
|
||||
password,
|
||||
"$2y$12$abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZabcd",
|
||||
{ convertPasswords: false },
|
||||
);
|
||||
return null;
|
||||
}
|
||||
|
||||
// Byte-compatible AtomCMS check (argon2id/bcrypt + md5->argon2id upgrade).
|
||||
const res = await checkLogin(password, user.password, {
|
||||
|
||||
Reference in new issue
Block a user