fix: resolve auth security issues - 2FA require TOTP on disable, rate limiting, timing-safe login, token expiry check

This commit is contained in:
remco committed 2026-07-02 14:54:25 +02:00
1 parent 4a06b30263
commit 64f50b2dde
6 files changed
+63 -9

No files matched your search

+9 -1
View File
@@ -29,7 +29,15 @@ export const { handlers, signIn, signOut, auth } = NextAuth({
if (!rateLimit(`login:${await clientIp()}`, 10, 5 * 60_000).ok) return null;
const user = await prisma.user.findUnique({ where: { username } });
if (!user) return null;
if (!user) {
// Prevent timing-based enumeration: always run a dummy hash check.
await checkLogin(
password,
"$2y$12$abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZabcd",
{ convertPasswords: false },
);
return null;
}
// Byte-compatible AtomCMS check (argon2id/bcrypt + md5->argon2id upgrade).
const res = await checkLogin(password, user.password, {