mirror of
https://github.com/documenso/documenso.git
synced 2026-10-02 17:54:28 +10:00
Selecting password auth failed with a generic "Unauthorized" for users who signed up via OAuth or passkey, with no way to set one. Detect the missing password and email the existing reset link from the signing dialog and security settings. Require a 2FA code and rate limit update-password.
54 lines
1.4 KiB
TypeScript
54 lines
1.4 KiB
TypeScript
import { type TUserAuthMethod, UserAuthMethod } from '../types/user-auth-method';
|
|
|
|
type DeriveUserAuthMethodsOptions = {
|
|
/**
|
|
* Whether the user has a password hash stored.
|
|
*/
|
|
hasPassword: boolean;
|
|
|
|
/**
|
|
* The number of passkeys registered to the user.
|
|
*/
|
|
passkeyCount: number;
|
|
|
|
/**
|
|
* The `provider` values of the user's linked `Account` rows.
|
|
*/
|
|
accountProviders: string[];
|
|
};
|
|
|
|
const OAUTH_PROVIDER_AUTH_METHODS: Record<string, TUserAuthMethod> = {
|
|
google: UserAuthMethod.GOOGLE,
|
|
microsoft: UserAuthMethod.MICROSOFT,
|
|
oidc: UserAuthMethod.OIDC,
|
|
};
|
|
|
|
/**
|
|
* Derive the distinct set of sign in methods available to a user.
|
|
*
|
|
* Any `Account.provider` value that is not one of the built in OAuth providers
|
|
* is treated as an organisation authentication portal, since those accounts use
|
|
* the organisation ID as the provider.
|
|
*/
|
|
export const deriveUserAuthMethods = ({
|
|
hasPassword,
|
|
passkeyCount,
|
|
accountProviders,
|
|
}: DeriveUserAuthMethodsOptions): TUserAuthMethod[] => {
|
|
const authMethods = new Set<TUserAuthMethod>();
|
|
|
|
if (hasPassword) {
|
|
authMethods.add(UserAuthMethod.PASSWORD);
|
|
}
|
|
|
|
if (passkeyCount > 0) {
|
|
authMethods.add(UserAuthMethod.PASSKEY);
|
|
}
|
|
|
|
for (const provider of accountProviders) {
|
|
authMethods.add(OAUTH_PROVIDER_AUTH_METHODS[provider] ?? UserAuthMethod.ORGANISATION_SSO);
|
|
}
|
|
|
|
return Array.from(authMethods);
|
|
};
|