Add U2F support

This commit is contained in:
Jonas Lochmann
2022-09-22 08:47:06 +02:00
parent 04aa2ce517
commit 613776cbf9
64 changed files with 2501 additions and 134 deletions
@@ -0,0 +1,56 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { AddParentU2fKeyAction } from '../../../../action'
import { getU2fKeyId } from '../../../../database/u2fkey'
import { Cache } from '../cache'
import { ApplyActionUnacceptableAuthMethodException } from '../exception/auth'
import { LimitReachedException } from '../exception/limit'
import { AuthenticationMethod } from '../types'
export async function dispatchAddU2f ({ action, cache, parentUserId, authentication }: {
action: AddParentU2fKeyAction
cache: Cache
parentUserId: string
authentication: AuthenticationMethod
}) {
if (authentication === 'u2f') {
throw new ApplyActionUnacceptableAuthMethodException()
}
const counter = await cache.database.u2fKey.count({
where: {
familyId: cache.familyId
},
transaction: cache.transaction
})
if (counter >= 16) throw new LimitReachedException({ type: 'u2f keys' })
await cache.database.u2fKey.create({
familyId: cache.familyId,
keyId: getU2fKeyId({ keyHandle: action.keyHandle, publicKey: action.publicKey }),
userId: parentUserId,
addedAt: Date.now().toString(10),
keyHandle: action.keyHandle,
publicKey: action.publicKey,
nextCounter: '0'
}, { transaction: cache.transaction })
cache.invalidateU2fList = true
cache.areChangesImportant = true
}