fix(auth): check the TOTP setup code before asking for sudo (#3146)

This commit is contained in:
Hampus
2026-10-03 02:11:14 +02:00
committed by GitHub
parent db9ec0605e
commit 706c41aad9
3 changed files with 74 additions and 0 deletions
@@ -0,0 +1,57 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
import {createAuthHarness, createTestAccount, createTotpSecret, totpCodeNow} from '@app/api/auth/tests/AuthTestUtils';
import type {ApiTestHarness} from '@app/api/test/ApiTestHarness';
import {HTTP_STATUS} from '@app/api/test/TestConstants';
import {createBuilder} from '@app/api/test/TestRequestBuilder';
import {ValidationErrorCodes} from '@fluxer/constants/src/ValidationErrorCodes';
import {afterAll, beforeAll, beforeEach, describe, expect, it} from 'vitest';
interface ValidationErrorBody {
code: string;
errors: Array<{path: string; code: string}>;
}
function wrongCodeFor(code: string): string {
return ((Number(code) + 500_000) % 1_000_000).toString().padStart(6, '0');
}
describe('Enabling TOTP checks the setup code before sudo', () => {
let harness: ApiTestHarness;
beforeAll(async () => {
harness = await createAuthHarness();
});
beforeEach(async () => {
await harness.reset();
});
afterAll(async () => {
await harness?.shutdown();
});
it('rejects a wrong setup code on the code field without asking for a password', async () => {
const account = await createTestAccount(harness);
const secret = createTotpSecret();
const error = await createBuilder<ValidationErrorBody>(harness, account.token)
.post('/users/@me/mfa/totp/enable')
.body({secret, code: wrongCodeFor(totpCodeNow(secret))})
.expect(HTTP_STATUS.BAD_REQUEST, 'INVALID_FORM_BODY')
.execute();
expect(error.errors[0]?.path).toBe('code');
expect(error.errors[0]?.code).toBe(ValidationErrorCodes.INVALID_CODE);
});
it('asks for sudo for a valid setup code, then enables with the password', async () => {
const account = await createTestAccount(harness);
const secret = createTotpSecret();
const code = totpCodeNow(secret);
await createBuilder(harness, account.token)
.post('/users/@me/mfa/totp/enable')
.body({secret, code})
.expect(HTTP_STATUS.FORBIDDEN, 'SUDO_MODE_REQUIRED')
.execute();
const enabled = await createBuilder<{backup_codes: Array<{code: string}>}>(harness, account.token)
.post('/users/@me/mfa/totp/enable')
.body({secret, code, password: account.password})
.expect(HTTP_STATUS.OK)
.execute();
expect(enabled.backup_codes.length).toBeGreaterThan(0);
});
});
@@ -12,6 +12,7 @@ import {OpenAPI} from '@app/api/middleware/ResponseTypeMiddleware';
import {SudoModeMiddleware} from '@app/api/middleware/SudoModeMiddleware';
import {RateLimitConfigs} from '@app/api/RateLimitConfig';
import type {HonoApp} from '@app/api/types/HonoEnv';
import {assertValidTotpSetupCode} from '@app/api/user/services/UserAuth';
import {Validator} from '@app/api/Validator';
import {
DisableTotpRequest,
@@ -60,6 +61,7 @@ export function UserAuthController(app: HonoApp) {
async (ctx) => {
const body = ctx.req.valid('json');
const user = ctx.get('user');
await assertValidTotpSetupCode(body.secret, body.code);
const sudoResult = await requireSudoMode(ctx, user, body);
return ctx.json(
await ctx.get('userAuthRequestService').enableTotp({
@@ -8,6 +8,7 @@ import type {SudoVerificationResult} from '@app/api/auth/services/SudoVerificati
import type {MfaBackupCode} from '@app/api/models/MfaBackupCode';
import type {User} from '@app/api/models/User';
import {mapUserToPrivateResponse} from '@app/api/user/UserMappers';
import {TotpGenerator} from '@app/api/utils/TotpGenerator';
import {UserAuthenticatorTypes} from '@fluxer/constants/src/UserConstants';
import {ValidationErrorCodes} from '@fluxer/constants/src/ValidationErrorCodes';
import {MfaNotDisabledError} from '@fluxer/errors/src/domains/auth/MfaNotDisabledError';
@@ -55,6 +56,20 @@ async function assertSudoVerifiedForMfa(
);
}
async function isValidTotpSetupCode(secret: string, code: string): Promise<boolean> {
try {
return await new TotpGenerator(secret).validateTotp(code);
} catch {
return false;
}
}
export async function assertValidTotpSetupCode(secret: string, code: string): Promise<void> {
if (!(await isValidTotpSetupCode(secret, code))) {
throw InputValidationError.fromCode('code', ValidationErrorCodes.INVALID_CODE);
}
}
export async function enableMfaTotp(
ctx: ApiContext,
{user, secret, code, sudoContext}: EnableMfaTotpParams,