Skip to content
58 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Merge main (membership, two-factor, GitHub repo roles) into tokens1import type { Reauth, Result, TwoFactorSetup, User } from "@g1t/contracts";
2
3import { pendingFields } from "./emails";
4import type { PendingChange } from "./emails.server";
5import { accounts } from "./services.server";
6import { clientOf, sessionTokenOf } from "./session.server";
7
8/** What the two-factor page's forms answer. */
9export type TwoFactorActionData = {
10 error?: string;
11 notice?: string;
12 /** Turning it on: the secret and its QR code, until a code confirms it. */
13 setup?: TwoFactorSetup;
14 /** Recovery codes, shown once. */
15 codes?: string[];
16 reauth?: PendingChange;
17} | null;
18
19export const TWO_FACTOR_INTENTS = ["two-factor-start", "two-factor-enable", "two-factor-disable", "two-factor-codes"] as const;
20
21function proof(request: Request, form: FormData): Reauth {
22 const password = String(form.get("password") ?? "");
23 return { sessionToken: sessionTokenOf(request), password: password || null, client: clientOf(request) };
24}
25
26/** A refusal for want of proof becomes the password prompt, carrying the form's fields. */
27function refused(result: Result<unknown> & { ok: false }, form: FormData, keep?: Partial<NonNullable<TwoFactorActionData>>): TwoFactorActionData {
28 if (result.error.code === "reauth_required") {
29 return { ...keep, reauth: { intent: String(form.get("intent")), fields: pendingFields(form), message: result.error.message } };
30 }
31 return { ...keep, error: result.error.message };
32}
33
34/** Handles the two-factor page's intents; undefined for any other. */
35export async function twoFactorAction(user: User, form: FormData, request: Request): Promise<TwoFactorActionData | undefined> {
36 const code = String(form.get("code") ?? "");
37 switch (form.get("intent")) {
38 case "two-factor-start": {
39 const result = await accounts.twoFactorStart(user, proof(request, form));
40 return result.ok ? { setup: result.value } : refused(result, form);
41 }
42 case "two-factor-enable": {
43 // The setup the form showed, so a wrong code shows it again.
44 const setup = { secret: String(form.get("secret") ?? ""), uri: String(form.get("uri") ?? "") };
45 const result = await accounts.twoFactorEnable(user, code, proof(request, form));
46 return result.ok ? { codes: result.value.codes, notice: "Two-factor authentication is on." } : refused(result, form, { setup });
47 }
48 case "two-factor-disable": {
49 const result = await accounts.twoFactorDisable(user, code, proof(request, form));
50 return result.ok ? { notice: "Two-factor authentication is off." } : refused(result, form);
51 }
52 case "two-factor-codes": {
53 const result = await accounts.twoFactorRecoveryCodes(user, proof(request, form));
54 return result.ok ? { codes: result.value.codes, notice: "New recovery codes. The old ones no longer work." } : refused(result, form);
55 }
56 }
57 return undefined;
58}

This file's history is long; its oldest lines are credited to the oldest commit read.