fosrl.pangolin/server/auth/totp.ts

58 lines
1.5 KiB
TypeScript
Raw Normal View History

2024-10-05 15:45:01 -04:00
import { verify } from "@node-rs/argon2";
import db from "@server/db";
import { twoFactorBackupCodes } from "@server/db/schema";
import { eq } from "drizzle-orm";
import { decodeHex } from "oslo/encoding";
import { TOTPController } from "oslo/otp";
2024-12-22 16:59:30 -05:00
import { verifyPassword } from "./password";
2024-10-05 15:45:01 -04:00
export async function verifyTotpCode(
code: string,
secret: string,
2024-12-22 16:59:30 -05:00
userId: string
2024-10-05 15:45:01 -04:00
): Promise<boolean> {
2024-12-22 17:20:24 -05:00
// if code is digits only, it's totp
const isTotp = /^\d+$/.test(code);
if (!isTotp) {
2024-10-05 15:45:01 -04:00
const validBackupCode = await verifyBackUpCode(code, userId);
return validBackupCode;
} else {
const validOTP = await new TOTPController().verify(
code,
2024-12-22 16:59:30 -05:00
decodeHex(secret)
2024-10-05 15:45:01 -04:00
);
return validOTP;
}
}
export async function verifyBackUpCode(
code: string,
2024-12-22 16:59:30 -05:00
userId: string
2024-10-05 15:45:01 -04:00
): Promise<boolean> {
const allHashed = await db
.select()
.from(twoFactorBackupCodes)
.where(eq(twoFactorBackupCodes.userId, userId));
if (!allHashed || !allHashed.length) {
return false;
}
let validId;
for (const hashedCode of allHashed) {
2024-12-22 16:59:30 -05:00
const validCode = await verifyPassword(code, hashedCode.codeHash);
2024-10-05 15:45:01 -04:00
if (validCode) {
2024-10-13 17:13:47 -04:00
validId = hashedCode.codeId;
2024-10-05 15:45:01 -04:00
}
}
if (validId) {
await db
.delete(twoFactorBackupCodes)
2024-10-13 17:13:47 -04:00
.where(eq(twoFactorBackupCodes.codeId, validId));
2024-10-05 15:45:01 -04:00
}
return validId ? true : false;
}