Add support for encrypted second password hashes

This commit is contained in:
Jonas Lochmann
2022-09-12 02:00:00 +02:00
parent f725a7bda3
commit a86a0abb05
50 changed files with 1067 additions and 185 deletions
@@ -1,6 +1,6 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2020 Jonas Lochmann
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
@@ -16,21 +16,27 @@
*/
import { AddUserAction } from '../../../../action'
import { decryptParentPassword } from '../../../dh'
import { Cache } from '../cache'
export async function dispatchAddUser ({ action, cache }: {
action: AddUserAction
cache: Cache
}) {
const password =
action.password ?
await decryptParentPassword({ cache, password: action.password }) :
null
await cache.database.user.create({
familyId: cache.familyId,
userId: action.userId,
type: action.userType,
name: action.name,
timeZone: action.timeZone,
passwordHash: action.password ? action.password.hash : '',
secondPasswordHash: action.password ? action.password.secondHash : '',
secondPasswordSalt: action.password ? action.password.secondSalt : '',
passwordHash: password ? password.hash : '',
secondPasswordHash: password ? password.secondHash : '',
secondPasswordSalt: password ? password.secondSalt : '',
mail: '',
disableTimelimitsUntil: '0',
currentDevice: '',
@@ -1,6 +1,6 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2021 Jonas Lochmann
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
@@ -18,6 +18,7 @@
import { SetChildPasswordAction } from '../../../../action'
import { Cache } from '../cache'
import { MissingUserException } from '../exception/missing-item'
import { decryptParentPassword } from '../../../dh'
export async function dispatchSetChildPassword ({ action, cache }: {
action: SetChildPasswordAction
@@ -36,9 +37,11 @@ export async function dispatchSetChildPassword ({ action, cache }: {
throw new MissingUserException()
}
childEntry.passwordHash = action.newPassword.hash
childEntry.secondPasswordSalt = action.newPassword.secondSalt
childEntry.secondPasswordHash = action.newPassword.secondHash
const newPassword = await decryptParentPassword({ cache, password: action.newPassword })
childEntry.passwordHash = newPassword.hash
childEntry.secondPasswordSalt = newPassword.secondSalt
childEntry.secondPasswordHash = newPassword.secondHash
await childEntry.save({ transaction: cache.transaction })