mirror of
https://github.com/fluxerapp/fluxer
synced 2026-10-07 19:22:14 +09:00
fix(auth): check the TOTP setup code before asking for sudo (#3146)
This commit is contained in:
@@ -0,0 +1,57 @@
|
||||
// SPDX-License-Identifier: AGPL-3.0-or-later
|
||||
|
||||
import {createAuthHarness, createTestAccount, createTotpSecret, totpCodeNow} from '@app/api/auth/tests/AuthTestUtils';
|
||||
import type {ApiTestHarness} from '@app/api/test/ApiTestHarness';
|
||||
import {HTTP_STATUS} from '@app/api/test/TestConstants';
|
||||
import {createBuilder} from '@app/api/test/TestRequestBuilder';
|
||||
import {ValidationErrorCodes} from '@fluxer/constants/src/ValidationErrorCodes';
|
||||
import {afterAll, beforeAll, beforeEach, describe, expect, it} from 'vitest';
|
||||
|
||||
interface ValidationErrorBody {
|
||||
code: string;
|
||||
errors: Array<{path: string; code: string}>;
|
||||
}
|
||||
|
||||
function wrongCodeFor(code: string): string {
|
||||
return ((Number(code) + 500_000) % 1_000_000).toString().padStart(6, '0');
|
||||
}
|
||||
|
||||
describe('Enabling TOTP checks the setup code before sudo', () => {
|
||||
let harness: ApiTestHarness;
|
||||
beforeAll(async () => {
|
||||
harness = await createAuthHarness();
|
||||
});
|
||||
beforeEach(async () => {
|
||||
await harness.reset();
|
||||
});
|
||||
afterAll(async () => {
|
||||
await harness?.shutdown();
|
||||
});
|
||||
it('rejects a wrong setup code on the code field without asking for a password', async () => {
|
||||
const account = await createTestAccount(harness);
|
||||
const secret = createTotpSecret();
|
||||
const error = await createBuilder<ValidationErrorBody>(harness, account.token)
|
||||
.post('/users/@me/mfa/totp/enable')
|
||||
.body({secret, code: wrongCodeFor(totpCodeNow(secret))})
|
||||
.expect(HTTP_STATUS.BAD_REQUEST, 'INVALID_FORM_BODY')
|
||||
.execute();
|
||||
expect(error.errors[0]?.path).toBe('code');
|
||||
expect(error.errors[0]?.code).toBe(ValidationErrorCodes.INVALID_CODE);
|
||||
});
|
||||
it('asks for sudo for a valid setup code, then enables with the password', async () => {
|
||||
const account = await createTestAccount(harness);
|
||||
const secret = createTotpSecret();
|
||||
const code = totpCodeNow(secret);
|
||||
await createBuilder(harness, account.token)
|
||||
.post('/users/@me/mfa/totp/enable')
|
||||
.body({secret, code})
|
||||
.expect(HTTP_STATUS.FORBIDDEN, 'SUDO_MODE_REQUIRED')
|
||||
.execute();
|
||||
const enabled = await createBuilder<{backup_codes: Array<{code: string}>}>(harness, account.token)
|
||||
.post('/users/@me/mfa/totp/enable')
|
||||
.body({secret, code, password: account.password})
|
||||
.expect(HTTP_STATUS.OK)
|
||||
.execute();
|
||||
expect(enabled.backup_codes.length).toBeGreaterThan(0);
|
||||
});
|
||||
});
|
||||
@@ -12,6 +12,7 @@ import {OpenAPI} from '@app/api/middleware/ResponseTypeMiddleware';
|
||||
import {SudoModeMiddleware} from '@app/api/middleware/SudoModeMiddleware';
|
||||
import {RateLimitConfigs} from '@app/api/RateLimitConfig';
|
||||
import type {HonoApp} from '@app/api/types/HonoEnv';
|
||||
import {assertValidTotpSetupCode} from '@app/api/user/services/UserAuth';
|
||||
import {Validator} from '@app/api/Validator';
|
||||
import {
|
||||
DisableTotpRequest,
|
||||
@@ -60,6 +61,7 @@ export function UserAuthController(app: HonoApp) {
|
||||
async (ctx) => {
|
||||
const body = ctx.req.valid('json');
|
||||
const user = ctx.get('user');
|
||||
await assertValidTotpSetupCode(body.secret, body.code);
|
||||
const sudoResult = await requireSudoMode(ctx, user, body);
|
||||
return ctx.json(
|
||||
await ctx.get('userAuthRequestService').enableTotp({
|
||||
|
||||
@@ -8,6 +8,7 @@ import type {SudoVerificationResult} from '@app/api/auth/services/SudoVerificati
|
||||
import type {MfaBackupCode} from '@app/api/models/MfaBackupCode';
|
||||
import type {User} from '@app/api/models/User';
|
||||
import {mapUserToPrivateResponse} from '@app/api/user/UserMappers';
|
||||
import {TotpGenerator} from '@app/api/utils/TotpGenerator';
|
||||
import {UserAuthenticatorTypes} from '@fluxer/constants/src/UserConstants';
|
||||
import {ValidationErrorCodes} from '@fluxer/constants/src/ValidationErrorCodes';
|
||||
import {MfaNotDisabledError} from '@fluxer/errors/src/domains/auth/MfaNotDisabledError';
|
||||
@@ -55,6 +56,20 @@ async function assertSudoVerifiedForMfa(
|
||||
);
|
||||
}
|
||||
|
||||
async function isValidTotpSetupCode(secret: string, code: string): Promise<boolean> {
|
||||
try {
|
||||
return await new TotpGenerator(secret).validateTotp(code);
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
export async function assertValidTotpSetupCode(secret: string, code: string): Promise<void> {
|
||||
if (!(await isValidTotpSetupCode(secret, code))) {
|
||||
throw InputValidationError.fromCode('code', ValidationErrorCodes.INVALID_CODE);
|
||||
}
|
||||
}
|
||||
|
||||
export async function enableMfaTotp(
|
||||
ctx: ApiContext,
|
||||
{user, secret, code, sudoContext}: EnableMfaTotpParams,
|
||||
|
||||
Reference in New Issue
Block a user