| 1 | import { Form, Link, redirect } from "react-router"; |
| 2 | |
| 3 | import type { Route } from "./+types/login-two-factor"; |
| 4 | import { AuthCard } from "../components/auth-card"; |
| 5 | import { ErrorText, Field, Input, SubmitButton } from "../components/ui"; |
| 6 | import { PENDING_COOKIE, TWO_FACTOR_COOKIE, cookie, readCookie } from "../lib/github"; |
| 7 | import { githubSignIn } from "../lib/github.server"; |
| 8 | import { page } from "../lib/meta"; |
| 9 | import { identity } from "../lib/services.server"; |
| 10 | import { assertSameOrigin, clientOf, getViewer, nextPath, startSession } from "../lib/session.server"; |
| 11 | |
| 12 | export function meta(args: Route.MetaArgs) { |
| 13 | return page(args, { title: "Two-factor authentication · g1t" }); |
| 14 | } |
| 15 | |
| 16 | /** Only reached with a sign-in waiting for its code; anyone else signs in first. */ |
| 17 | export async function loader({ request, context }: Route.LoaderArgs) { |
| 18 | if (getViewer(context)) throw redirect(nextPath(request)); |
| 19 | if (!readCookie(request.headers.get("cookie"), TWO_FACTOR_COOKIE)) { |
| 20 | const next = nextPath(request); |
| 21 | throw redirect(next === "/" ? "/login" : `/login?next=${encodeURIComponent(next)}`); |
| 22 | } |
| 23 | return { next: nextPath(request) }; |
| 24 | } |
| 25 | |
| 26 | export async function action({ request }: Route.ActionArgs) { |
| 27 | assertSameOrigin(request); |
| 28 | const cookies = request.headers.get("cookie"); |
| 29 | const challenge = readCookie(cookies, TWO_FACTOR_COOKIE); |
| 30 | if (!challenge) return { error: "This sign-in has expired. Sign in again.", expired: true }; |
| 31 | const form = await request.formData(); |
| 32 | const result = await identity.twoFactorSignIn(challenge, String(form.get("code") ?? ""), clientOf(request)); |
| 33 | if (!result.ok) { |
| 34 | const expired = result.error.message.includes("expired"); |
| 35 | return { error: result.error.message, expired }; |
| 36 | } |
| 37 | const headers = new Headers({ "set-cookie": startSession(result.value.sessionToken) }); |
| 38 | headers.append("set-cookie", cookie(TWO_FACTOR_COOKIE, "", 0)); |
| 39 | // A GitHub sign-in waiting to be linked links now, as after a password. |
| 40 | const pending = readCookie(cookies, PENDING_COOKIE); |
| 41 | if (pending) { |
| 42 | await githubSignIn.claim(pending, result.value.user).catch(() => null); |
| 43 | headers.append("set-cookie", cookie(PENDING_COOKIE, "", 0)); |
| 44 | } |
| 45 | throw redirect(nextPath(request), { headers }); |
| 46 | } |
| 47 | |
| 48 | export default function LoginTwoFactor({ actionData }: Route.ComponentProps) { |
| 49 | return ( |
| 50 | <AuthCard |
| 51 | title="Two-factor authentication" |
| 52 | subtitle="Enter the code from your authenticator app" |
| 53 | footer={ |
| 54 | <Link to="/login" className="text-fg underline underline-offset-4"> |
| 55 | Sign in again |
| 56 | </Link> |
| 57 | } |
| 58 | > |
| 59 | <Form method="post" className="space-y-4"> |
| 60 | <Field label="Code" hint="Lost your phone? Enter one of your recovery codes instead."> |
| 61 | <Input name="code" required autoFocus autoComplete="one-time-code" inputMode="numeric" maxLength={20} placeholder="123 456" /> |
| 62 | </Field> |
| 63 | <ErrorText>{actionData?.error}</ErrorText> |
| 64 | <div className="pt-2 *:w-full"> |
| 65 | <SubmitButton pending="Checking…">Verify</SubmitButton> |
| 66 | </div> |
| 67 | </Form> |
| 68 | </AuthCard> |
| 69 | ); |
| 70 | } |