Files
top-tickets/src/lib/auth/totp.ts
T
ogrechkoandClaude Sonnet 5 4ecb0e7698 Add opt-in TOTP 2FA for local accounts
New card in Настройки → Аккаунт: scan a QR code (otplib + qrcode), confirm
with a live code, get 8 one-time recovery codes shown once. Only offered
for authSource="local" — LDAP accounts already have their own MFA story at
the directory level and are turned away with a clear message if they somehow
hit the setup endpoint directly.

Login flow: a 2FA account's password check now creates a short-lived
"login challenge" (separate table from `sessions`, 5-minute TTL, capped at
6 verify attempts) instead of a real session, and the login page swaps to a
second screen asking for a code — TOTP or a recovery code, either works.
The LDAP branch of the login route is untouched; it returns before ever
reaching the 2FA check.

totpSecret is encrypted at rest via the existing lib/crypto/credentials.ts
helper (same one already used for mailbox/LDAP bind passwords) rather than
adding a second encryption scheme. Recovery codes are hashed, not stored
plaintext, and each is single-use (marked usedAt, not deleted).

Verified against the real deployment end-to-end with Playwright against a
throwaway test account (created via the real admin-users API, fully
deleted after): setup → confirm → recovery-code issuance → second login
correctly prompted for a code → wrong code rejected → correct code and a
recovery code both worked → a reused recovery code was correctly rejected
→ disable (password-gated) → subsequent login went straight through again.
Also added unit tests for the TOTP/recovery-code helpers.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GteWhnWKTmnXcsd5jx6H7u
2026-08-20 08:25:15 +00:00

44 lines
1.4 KiB
TypeScript

import crypto from "node:crypto";
import { generateSecret, verify, generateURI } from "otplib";
import QRCode from "qrcode";
import { encryptCredential, decryptCredential } from "@/lib/crypto/credentials";
const ISSUER = "top-tickets";
const RECOVERY_CODE_COUNT = 8;
export function generateTotpSecret(): string {
return generateSecret();
}
export function encryptTotpSecret(secret: string): string {
return encryptCredential(secret);
}
export function decryptTotpSecret(encrypted: string): string {
return decryptCredential(encrypted);
}
export async function buildTotpQrCode(secret: string, email: string): Promise<string> {
const uri = generateURI({ issuer: ISSUER, label: email, secret });
return QRCode.toDataURL(uri);
}
export async function verifyTotpCode(secret: string, code: string): Promise<boolean> {
const result = await verify({ secret, token: code.trim() });
return result.valid;
}
/** Human-typeable: groups of 5 lowercase hex chars, e.g. "a1b2c-d3e4f". */
function formatRecoveryCode(): string {
const raw = crypto.randomBytes(5).toString("hex");
return `${raw.slice(0, 5)}-${raw.slice(5, 10)}`;
}
export function generateRecoveryCodes(count = RECOVERY_CODE_COUNT): string[] {
return Array.from({ length: count }, formatRecoveryCode);
}
export function hashRecoveryCode(code: string): string {
return crypto.createHash("sha256").update(code.trim().toLowerCase()).digest("hex");
}