New card in Настройки → Аккаунт: scan a QR code (otplib + qrcode), confirm with a live code, get 8 one-time recovery codes shown once. Only offered for authSource="local" — LDAP accounts already have their own MFA story at the directory level and are turned away with a clear message if they somehow hit the setup endpoint directly. Login flow: a 2FA account's password check now creates a short-lived "login challenge" (separate table from `sessions`, 5-minute TTL, capped at 6 verify attempts) instead of a real session, and the login page swaps to a second screen asking for a code — TOTP or a recovery code, either works. The LDAP branch of the login route is untouched; it returns before ever reaching the 2FA check. totpSecret is encrypted at rest via the existing lib/crypto/credentials.ts helper (same one already used for mailbox/LDAP bind passwords) rather than adding a second encryption scheme. Recovery codes are hashed, not stored plaintext, and each is single-use (marked usedAt, not deleted). Verified against the real deployment end-to-end with Playwright against a throwaway test account (created via the real admin-users API, fully deleted after): setup → confirm → recovery-code issuance → second login correctly prompted for a code → wrong code rejected → correct code and a recovery code both worked → a reused recovery code was correctly rejected → disable (password-gated) → subsequent login went straight through again. Also added unit tests for the TOTP/recovery-code helpers. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GteWhnWKTmnXcsd5jx6H7u
44 lines
1.4 KiB
TypeScript
44 lines
1.4 KiB
TypeScript
import crypto from "node:crypto";
|
|
import { generateSecret, verify, generateURI } from "otplib";
|
|
import QRCode from "qrcode";
|
|
import { encryptCredential, decryptCredential } from "@/lib/crypto/credentials";
|
|
|
|
const ISSUER = "top-tickets";
|
|
const RECOVERY_CODE_COUNT = 8;
|
|
|
|
export function generateTotpSecret(): string {
|
|
return generateSecret();
|
|
}
|
|
|
|
export function encryptTotpSecret(secret: string): string {
|
|
return encryptCredential(secret);
|
|
}
|
|
|
|
export function decryptTotpSecret(encrypted: string): string {
|
|
return decryptCredential(encrypted);
|
|
}
|
|
|
|
export async function buildTotpQrCode(secret: string, email: string): Promise<string> {
|
|
const uri = generateURI({ issuer: ISSUER, label: email, secret });
|
|
return QRCode.toDataURL(uri);
|
|
}
|
|
|
|
export async function verifyTotpCode(secret: string, code: string): Promise<boolean> {
|
|
const result = await verify({ secret, token: code.trim() });
|
|
return result.valid;
|
|
}
|
|
|
|
/** Human-typeable: groups of 5 lowercase hex chars, e.g. "a1b2c-d3e4f". */
|
|
function formatRecoveryCode(): string {
|
|
const raw = crypto.randomBytes(5).toString("hex");
|
|
return `${raw.slice(0, 5)}-${raw.slice(5, 10)}`;
|
|
}
|
|
|
|
export function generateRecoveryCodes(count = RECOVERY_CODE_COUNT): string[] {
|
|
return Array.from({ length: count }, formatRecoveryCode);
|
|
}
|
|
|
|
export function hashRecoveryCode(code: string): string {
|
|
return crypto.createHash("sha256").update(code.trim().toLowerCase()).digest("hex");
|
|
}
|