Pure, unit-tested primitives the AtomCMS->Next.js login must reproduce exactly
(verified now with round-trip + known vectors; full end-to-end check deferred
until a real DB + APP_KEY + live emulator are available):
- password.ts: argon2id (m=65536,t=4,p=1 via hash-wasm) + bcrypt ($2y$ accepted)
verify, and the md5->argon2id on-login upgrade gated by convert_passwords
(mirrors RedirectIfTwoFactorAuthenticatable).
- sso-ticket.ts: '{hotel_name without spaces}-{uuidv4}' written to auth_ticket +
ip_current (mirrors User::ssoTicket()).
- laravel-encrypter.ts: AES-256-CBC + HMAC-SHA256 payload compatible with
Laravel encrypt()/encryptString (for existing 2FA secrets) incl. PHP string
(de)serialization.
- totp.ts: otplib Google2FA-compatible TOTP verify (SHA1/6/30).
Libs: hash-wasm + bcryptjs + otplib (pure JS/WASM, no native build). 28 tests.
34 lines
863 B
JSON
34 lines
863 B
JSON
{
|
|
"name": "atomcms-next",
|
|
"private": true,
|
|
"type": "module",
|
|
"engines": { "node": ">=22" },
|
|
"packageManager": "[email protected]",
|
|
"scripts": {
|
|
"prisma:generate": "prisma generate",
|
|
"typecheck": "tsc --noEmit",
|
|
"test": "vitest run",
|
|
"db:migrate": "tsx scripts/apply-migrations.ts",
|
|
"db:migrate:status": "tsx scripts/apply-migrations.ts --status"
|
|
},
|
|
"dependencies": {
|
|
"@prisma/adapter-mariadb": "^7.8.0",
|
|
"@prisma/client": "^7.8.0",
|
|
"bcryptjs": "^3.0.2",
|
|
"hash-wasm": "^4.12.0",
|
|
"otplib": "^12.0.1",
|
|
"zod": "^3.24.0"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "^22.10.0",
|
|
"dotenv": "^16.4.0",
|
|
"prisma": "^7.8.0",
|
|
"tsx": "^4.19.0",
|
|
"typescript": "^5.7.0",
|
|
"vitest": "^2.1.0"
|
|
},
|
|
"pnpm": {
|
|
"onlyBuiltDependencies": ["esbuild", "prisma", "@prisma/client", "@prisma/engines"]
|
|
}
|
|
}
|