fix: resolve auth security issues - 2FA require TOTP on disable, rate limiting, timing-safe login, token expiry check

This commit is contained in:
remco committed 2026-07-02 14:54:25 +02:00
1 parent 4a06b30263
commit 64f50b2dde
6 files changed
+63 -9

No files matched your search

+4 -2
View File
@@ -14,9 +14,11 @@ import { siteSettings } from "@/lib/services/site-settings";
// The token is therefore deterministic per (email, secret) pair and stays valid
// until the account's mail_verified flips to '1' (after which /verify no-ops).
/** Secret mixed into the digest. Falls back to AUTH_SECRET, then a constant. */
/** Secret mixed into the digest. Requires at least one of APP_KEY or AUTH_SECRET. */
function verifySecret(): string {
return env.APP_KEY || env.AUTH_SECRET || "atom-cms-verify";
const secret = env.APP_KEY || env.AUTH_SECRET;
if (!secret) throw new Error("APP_KEY or AUTH_SECRET must be set for email verification");
return secret;
}
/** Compute the verification token for an email (lowercased + trimmed). */