Add 2FA, email + password reset, and batch-7 pages

Auth (hand-built on the auth core):
- 2FA: User model gains two_factor_secret/recovery_codes/confirmed_at (+ idempotent
  MariaDB migration). authorize() requires a valid TOTP code when 2FA is confirmed
  (secret decrypted via Laravel APP_KEY, fail-closed). Two-step login (precheckLogin
  reveals the code field). /settings/2fa enable/confirm/disable flow.
- Password reset: nodemailer email service; PasswordReset model + migration;
  /forgot (request, generic response) + /reset (token sha256 + 1h TTL, sets argon2id
  hash). Login links to forgot.

Batch 7 (parallel agents): /admin/commandocentrum (RCON controls + emulator_errors),
social write actions (friend request + guild forum new thread), /help/[category],
/badges (public). env: APP_KEY, APP_URL, SMTP_*. Nav extended.

Verified: tsc exit 0, vitest 48/48, next build exit 0 (64 page routes).
This commit is contained in:
Simo committed 2026-06-28 14:25:19 +02:00
1 parent 486ce51559
commit e668fa85ec
24 files changed
+1223 -34

No files matched your search

+113
View File
@@ -0,0 +1,113 @@
import Link from "next/link";
import { redirect } from "next/navigation";
import { beginTwoFactor, confirmTwoFactor, disableTwoFactor } from "@/actions/twofactor";
import { LaravelEncrypter } from "@/lib/auth/laravel-encrypter";
import { totpKeyUri } from "@/lib/auth/totp";
import { auth } from "@/lib/auth";
import { prisma } from "@/lib/prisma";
import { siteSettings } from "@/lib/services/site-settings";
import { env } from "@/env";
export const dynamic = "force-dynamic";
export default async function TwoFactorPage({
searchParams,
}: {
searchParams: Promise<{ error?: string; enabled?: string; disabled?: string }>;
}) {
const session = await auth();
if (!session?.user?.id) redirect("/login");
const sp = await searchParams;
const id = Number(session.user.id);
let user: { twoFactorSecret: string | null; twoFactorConfirmedAt: Date | null } | null = null;
try {
user = await prisma.user.findUnique({
where: { id },
select: { twoFactorSecret: true, twoFactorConfirmedAt: true },
});
} catch {
user = null;
}
const hasAppKey = Boolean(env.APP_KEY);
const enabled = Boolean(user?.twoFactorConfirmedAt);
const pending = Boolean(user?.twoFactorSecret && !user?.twoFactorConfirmedAt);
const hotelName = (await siteSettings.get("hotel_name", "Atom")) ?? "Atom";
let secret = "";
let uri = "";
if (pending && hasAppKey && user?.twoFactorSecret) {
try {
secret = new LaravelEncrypter(env.APP_KEY as string).decrypt(user.twoFactorSecret);
uri = totpKeyUri(secret, session.user.name ?? "user", hotelName);
} catch {
secret = "";
}
}
return (
<main style={{ maxWidth: 520 }}>
<p className="muted">
<Link href="/settings">← Settings</Link>
</p>
<h1>Two-factor authentication</h1>
{sp.enabled ? <p style={{ color: "var(--color-accent)" }}>2FA is now enabled. 🔒</p> : null}
{sp.disabled ? <p className="muted">2FA has been disabled.</p> : null}
{sp.error === "badcode" ? (
<p style={{ color: "var(--color-danger)" }}>That code wasn't valid — try again.</p>
) : null}
{!hasAppKey ? (
<div className="card">
<p style={{ margin: 0 }}>
2FA is unavailable until <code>APP_KEY</code> is configured (the same Laravel
<code> APP_KEY</code> as your AtomCMS install, so existing secrets stay readable).
</p>
</div>
) : enabled ? (
<div className="card">
<p>
<strong>2FA is enabled</strong> on your account.
</p>
<form action={disableTwoFactor}>
<button type="submit" className="btn btn-danger">
Disable 2FA
</button>
</form>
</div>
) : pending ? (
<div className="card">
<h3 style={{ marginTop: 0 }}>Scan or enter this key</h3>
<p className="muted" style={{ marginTop: 0 }}>
Add this to Google Authenticator / Authy, then enter the 6-digit code to confirm.
</p>
<p>
Manual key: <code style={{ userSelect: "all" }}>{secret}</code>
</p>
<p className="muted" style={{ wordBreak: "break-all", fontSize: "0.8rem" }}>
{uri}
</p>
<form action={confirmTwoFactor} style={{ display: "flex", gap: "0.5rem", marginTop: "0.5rem" }}>
<input name="code" placeholder="6-digit code" inputMode="numeric" required />
<button type="submit" className="btn btn-primary">
Confirm
</button>
</form>
</div>
) : (
<div className="card">
<p style={{ marginTop: 0 }}>
Add a second layer of security with an authenticator app.
</p>
<form action={beginTwoFactor}>
<button type="submit" className="btn btn-primary">
Enable 2FA
</button>
</form>
</div>
)}
</main>
);
}
+11
View File
@@ -1,3 +1,4 @@
import Link from "next/link";
import { redirect } from "next/navigation";
import { updateMotto } from "@/actions/user-settings";
import { avatarImageUrl } from "@/lib/format";
@@ -81,6 +82,16 @@ export default async function SettingsPage() {
Updates instantly in-game if you are online.
</p>
</div>
<div className="card" style={{ maxWidth: 520, marginTop: "1.5rem" }}>
<h3 style={{ marginTop: 0 }}>Security</h3>
<p className="muted" style={{ marginTop: 0 }}>
Protect your account with two-factor authentication.
</p>
<Link href="/settings/2fa" className="btn btn-outline">
Two-factor authentication
</Link>
</div>
</main>
);
}