Files
Epicnabbo-Catalogus-Updated…/src/lib/auth/sso-ticket.ts
T
Simo ec2d46e583 Add byte-compatible Auth & SSO core primitives
Pure, unit-tested primitives the AtomCMS->Next.js login must reproduce exactly
(verified now with round-trip + known vectors; full end-to-end check deferred
until a real DB + APP_KEY + live emulator are available):

- password.ts: argon2id (m=65536,t=4,p=1 via hash-wasm) + bcrypt ($2y$ accepted)
  verify, and the md5->argon2id on-login upgrade gated by convert_passwords
  (mirrors RedirectIfTwoFactorAuthenticatable).
- sso-ticket.ts: '{hotel_name without spaces}-{uuidv4}' written to auth_ticket +
  ip_current (mirrors User::ssoTicket()).
- laravel-encrypter.ts: AES-256-CBC + HMAC-SHA256 payload compatible with
  Laravel encrypt()/encryptString (for existing 2FA secrets) incl. PHP string
  (de)serialization.
- totp.ts: otplib Google2FA-compatible TOTP verify (SHA1/6/30).

Libs: hash-wasm + bcryptjs + otplib (pure JS/WASM, no native build). 28 tests.
2026-06-27 16:00:25 +02:00

42 lines
1.2 KiB
TypeScript

import { randomUUID } from "node:crypto";
/**
* Build the SSO ticket exactly like AtomCMS's User::ssoTicket():
* $hotelName = Str::replace(' ', '', setting('hotel_name'));
* sprintf('%s-%s', $hotelName, Str::uuid());
* i.e. the hotel name with ALL spaces removed, a dash, then a v4 UUID.
* The emulator validates this exact value when the Nitro/Flash client connects.
*/
export function generateSsoTicket(hotelName: string): string {
const normalized = hotelName.replace(/ /g, "");
return `${normalized}-${randomUUID()}`;
}
/** Minimal shape of the Prisma client this needs (keeps it unit-testable). */
export interface SsoUserUpdater {
user: {
update(args: {
where: { id: number };
data: { authTicket: string; ipCurrent: string };
}): Promise<unknown>;
};
}
/**
* Generate a ticket and persist it like AtomCMS: writes auth_ticket AND
* ip_current on the user, then returns the ticket for the client launcher.
*/
export async function issueSsoTicket(
db: SsoUserUpdater,
userId: number,
hotelName: string,
ip: string,
): Promise<string> {
const ticket = generateSsoTicket(hotelName);
await db.user.update({
where: { id: userId },
data: { authTicket: ticket, ipCurrent: ip },
});
return ticket;
}