mirror of
https://github.com/documenso/documenso.git
synced 2026-10-03 02:04:40 +10:00
Selecting password auth failed with a generic "Unauthorized" for users who signed up via OAuth or passkey, with no way to set one. Detect the missing password and email the existing reset link from the signing dialog and security settings. Require a 2FA code and rate limit update-password.
40 lines
981 B
TypeScript
40 lines
981 B
TypeScript
import { prisma } from '@documenso/prisma';
|
|
|
|
import type { TUserAuthMethod } from '../../types/user-auth-method';
|
|
import { deriveUserAuthMethods } from '../../utils/user-auth-methods';
|
|
|
|
export type GetUserAuthMethodsOptions = {
|
|
userId: number;
|
|
};
|
|
|
|
/**
|
|
* Get the distinct sign in methods available to a user, such as password,
|
|
* passkey or linked OAuth providers.
|
|
*/
|
|
export const getUserAuthMethods = async ({ userId }: GetUserAuthMethodsOptions): Promise<TUserAuthMethod[]> => {
|
|
const user = await prisma.user.findFirstOrThrow({
|
|
where: {
|
|
id: userId,
|
|
},
|
|
select: {
|
|
password: true,
|
|
accounts: {
|
|
select: {
|
|
provider: true,
|
|
},
|
|
},
|
|
_count: {
|
|
select: {
|
|
passkeys: true,
|
|
},
|
|
},
|
|
},
|
|
});
|
|
|
|
return deriveUserAuthMethods({
|
|
hasPassword: user.password !== null,
|
|
passkeyCount: user._count.passkeys,
|
|
accountProviders: user.accounts.map((account) => account.provider),
|
|
});
|
|
};
|