feat(auth): password change (self + admin reset) with rate limiting; dedupe watchlist to user menu
Build & Push Docker Image / build (push) Successful in 2m19s
Build & Push Docker Image / build (push) Successful in 2m19s
This commit is contained in:
@@ -5,6 +5,8 @@ import { eq, and, inArray, isNull } from "drizzle-orm";
|
||||
import { z } from "zod";
|
||||
import { db, usersTable, toolsTable, ratingsTable } from "@workspace/db";
|
||||
import { logger } from "../lib/logger";
|
||||
import { writeAuditLog } from "../lib/audit";
|
||||
import { loginRateLimit, passwordRateLimit } from "../lib/rate-limit";
|
||||
import { getEntitlements, requireFeature } from "../middleware/feature";
|
||||
|
||||
const router: IRouter = Router();
|
||||
@@ -107,7 +109,7 @@ router.get("/auth/mode", (_req, res): void => {
|
||||
res.json({ mode: isOidcConfigured() ? "oidc" : "local" });
|
||||
});
|
||||
|
||||
router.post("/auth/login", async (req, res): Promise<void> => {
|
||||
router.post("/auth/login", loginRateLimit, async (req, res): Promise<void> => {
|
||||
if (isOidcConfigured()) {
|
||||
res.status(400).json({ error: "Use OIDC login when Keycloak is configured." });
|
||||
return;
|
||||
@@ -279,6 +281,58 @@ router.get("/auth/me", async (req, res): Promise<void> => {
|
||||
});
|
||||
});
|
||||
|
||||
router.get("/auth/password-redirect", async (req, res): Promise<void> => {
|
||||
const client = await getClient();
|
||||
if (!client) {
|
||||
res.json({ url: null });
|
||||
return;
|
||||
}
|
||||
const realm = client.issuer.metadata.issuer ?? "";
|
||||
res.json({ url: `${realm}/account/password` });
|
||||
});
|
||||
|
||||
const ChangePasswordSchema = z.object({
|
||||
currentPassword: z.string().min(1),
|
||||
newPassword: z.string().min(8),
|
||||
});
|
||||
|
||||
router.post("/auth/me/password", passwordRateLimit, async (req, res): Promise<void> => {
|
||||
if (!req.session.user) {
|
||||
res.status(401).json({ error: "Not authenticated" });
|
||||
return;
|
||||
}
|
||||
const dbUser = await resolveDbUser(req.session.user);
|
||||
if (!dbUser) {
|
||||
res.status(401).json({ error: "User not found" });
|
||||
return;
|
||||
}
|
||||
if (dbUser.authProvider !== "local") {
|
||||
res.status(422).json({ error: "oidc" });
|
||||
return;
|
||||
}
|
||||
const parsed = ChangePasswordSchema.safeParse(req.body);
|
||||
if (!parsed.success) {
|
||||
res.status(400).json({ error: parsed.error.message });
|
||||
return;
|
||||
}
|
||||
const { currentPassword, newPassword } = parsed.data;
|
||||
if (currentPassword === newPassword) {
|
||||
res.status(400).json({ error: "New password must differ from current password" });
|
||||
return;
|
||||
}
|
||||
if (!dbUser.passwordHash || !(await bcrypt.compare(currentPassword, dbUser.passwordHash))) {
|
||||
res.status(400).json({ error: "Current password is incorrect" });
|
||||
return;
|
||||
}
|
||||
const passwordHash = await bcrypt.hash(newPassword, 12);
|
||||
await db.update(usersTable).set({ passwordHash }).where(eq(usersTable.id, dbUser.id));
|
||||
await writeAuditLog(req, "user", dbUser.id, "change_password", {});
|
||||
await new Promise<void>((resolve, reject) => {
|
||||
req.session.regenerate((err) => (err ? reject(err) : resolve()));
|
||||
});
|
||||
res.sendStatus(204);
|
||||
});
|
||||
|
||||
type SessionUser = NonNullable<import("express-session").SessionData["user"]>;
|
||||
|
||||
async function resolveDbUser(u: SessionUser) {
|
||||
|
||||
Reference in New Issue
Block a user