Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA | 1 | import type { Reauth, Result, TwoFactorSetup, User } from "@g1t/contracts"; |
| 2 | ||
| 3 | import { pendingFields } from "./emails"; | |
| 4 | import type { PendingChange } from "./emails.server"; | |
| 5 | import { accounts } from "./services.server"; | |
| 6 | import { clientOf, sessionTokenOf } from "./session.server"; | |
| 7 | ||
| 8 | /** What the two-factor page's forms answer. */ | |
| 9 | export type TwoFactorActionData = { | |
| 10 | error?: string; | |
| 11 | notice?: string; | |
| 12 | /** Turning it on: the secret and its QR code, until a code confirms it. */ | |
| 13 | setup?: TwoFactorSetup; | |
| 14 | /** Recovery codes, shown once. */ | |
| 15 | codes?: string[]; | |
| 16 | reauth?: PendingChange; | |
| 17 | } | null; | |
| 18 | ||
| 19 | export const TWO_FACTOR_INTENTS = ["two-factor-start", "two-factor-enable", "two-factor-disable", "two-factor-codes"] as const; | |
| 20 | ||
| 21 | function proof(request: Request, form: FormData): Reauth { | |
| 22 | const password = String(form.get("password") ?? ""); | |
| 23 | return { sessionToken: sessionTokenOf(request), password: password || null, client: clientOf(request) }; | |
| 24 | } | |
| 25 | ||
| 26 | /** A refusal for want of proof becomes the password prompt, carrying the form's fields. */ | |
| 27 | function refused(result: Result<unknown> & { ok: false }, form: FormData, keep?: Partial<NonNullable<TwoFactorActionData>>): TwoFactorActionData { | |
| 28 | if (result.error.code === "reauth_required") { | |
| 29 | return { ...keep, reauth: { intent: String(form.get("intent")), fields: pendingFields(form), message: result.error.message } }; | |
| 30 | } | |
| 31 | return { ...keep, error: result.error.message }; | |
| 32 | } | |
| 33 | ||
| 34 | /** Handles the two-factor page's intents; undefined for any other. */ | |
| 35 | export async function twoFactorAction(user: User, form: FormData, request: Request): Promise<TwoFactorActionData | undefined> { | |
| 36 | const code = String(form.get("code") ?? ""); | |
| 37 | switch (form.get("intent")) { | |
| 38 | case "two-factor-start": { | |
| 39 | const result = await accounts.twoFactorStart(user, proof(request, form)); | |
| 40 | return result.ok ? { setup: result.value } : refused(result, form); | |
| 41 | } | |
| 42 | case "two-factor-enable": { | |
| 43 | // The setup the form showed, so a wrong code shows it again. | |
| 44 | const setup = { secret: String(form.get("secret") ?? ""), uri: String(form.get("uri") ?? "") }; | |
| 45 | const result = await accounts.twoFactorEnable(user, code, proof(request, form)); | |
| 46 | return result.ok ? { codes: result.value.codes, notice: "Two-factor authentication is on." } : refused(result, form, { setup }); | |
| 47 | } | |
| 48 | case "two-factor-disable": { | |
| 49 | const result = await accounts.twoFactorDisable(user, code, proof(request, form)); | |
| 50 | return result.ok ? { notice: "Two-factor authentication is off." } : refused(result, form); | |
| 51 | } | |
| 52 | case "two-factor-codes": { | |
| 53 | const result = await accounts.twoFactorRecoveryCodes(user, proof(request, form)); | |
| 54 | return result.ok ? { codes: result.value.codes, notice: "New recovery codes. The old ones no longer work." } : refused(result, form); | |
| 55 | } | |
| 56 | } | |
| 57 | return undefined; | |
| 58 | } |
This file's history is long; its oldest lines are credited to the oldest commit read.