mirror of
https://github.com/standardnotes/server
synced 2026-10-06 06:13:12 -04:00
fix(auth): remove mfa settings after recovery sign in
This commit is contained in:
@@ -619,20 +619,6 @@ export class ContainerConfigLoader {
|
||||
container.bind<VerifyMFA>(TYPES.VerifyMFA).to(VerifyMFA)
|
||||
container.bind<ClearLoginAttempts>(TYPES.ClearLoginAttempts).to(ClearLoginAttempts)
|
||||
container.bind<IncreaseLoginAttempts>(TYPES.IncreaseLoginAttempts).to(IncreaseLoginAttempts)
|
||||
container
|
||||
.bind<SignInWithRecoveryCodes>(TYPES.SignInWithRecoveryCodes)
|
||||
.toConstantValue(
|
||||
new SignInWithRecoveryCodes(
|
||||
container.get(TYPES.UserRepository),
|
||||
container.get(TYPES.AuthResponseFactory20200115),
|
||||
container.get(TYPES.PKCERepository),
|
||||
container.get(TYPES.Crypter),
|
||||
container.get(TYPES.SettingService),
|
||||
container.get(TYPES.GenerateRecoveryCodes),
|
||||
container.get(TYPES.IncreaseLoginAttempts),
|
||||
container.get(TYPES.ClearLoginAttempts),
|
||||
),
|
||||
)
|
||||
container
|
||||
.bind<GetUserKeyParamsRecovery>(TYPES.GetUserKeyParamsRecovery)
|
||||
.toConstantValue(
|
||||
@@ -655,6 +641,21 @@ export class ContainerConfigLoader {
|
||||
container.bind<GetUserFeatures>(TYPES.GetUserFeatures).to(GetUserFeatures)
|
||||
container.bind<UpdateSetting>(TYPES.UpdateSetting).to(UpdateSetting)
|
||||
container.bind<DeleteSetting>(TYPES.DeleteSetting).to(DeleteSetting)
|
||||
container
|
||||
.bind<SignInWithRecoveryCodes>(TYPES.SignInWithRecoveryCodes)
|
||||
.toConstantValue(
|
||||
new SignInWithRecoveryCodes(
|
||||
container.get(TYPES.UserRepository),
|
||||
container.get(TYPES.AuthResponseFactory20200115),
|
||||
container.get(TYPES.PKCERepository),
|
||||
container.get(TYPES.Crypter),
|
||||
container.get(TYPES.SettingService),
|
||||
container.get(TYPES.GenerateRecoveryCodes),
|
||||
container.get(TYPES.IncreaseLoginAttempts),
|
||||
container.get(TYPES.ClearLoginAttempts),
|
||||
container.get(TYPES.DeleteSetting),
|
||||
),
|
||||
)
|
||||
container.bind<DeleteAccount>(TYPES.DeleteAccount).to(DeleteAccount)
|
||||
container.bind<GetUserSubscription>(TYPES.GetUserSubscription).to(GetUserSubscription)
|
||||
container.bind<GetUserOfflineSubscription>(TYPES.GetUserOfflineSubscription).to(GetUserOfflineSubscription)
|
||||
|
||||
+7
@@ -9,6 +9,7 @@ import { PKCERepositoryInterface } from '../../User/PKCERepositoryInterface'
|
||||
import { User } from '../../User/User'
|
||||
import { UserRepositoryInterface } from '../../User/UserRepositoryInterface'
|
||||
import { ClearLoginAttempts } from '../ClearLoginAttempts'
|
||||
import { DeleteSetting } from '../DeleteSetting/DeleteSetting'
|
||||
import { GenerateRecoveryCodes } from '../GenerateRecoveryCodes/GenerateRecoveryCodes'
|
||||
import { IncreaseLoginAttempts } from '../IncreaseLoginAttempts'
|
||||
import { SignInWithRecoveryCodes } from './SignInWithRecoveryCodes'
|
||||
@@ -22,6 +23,7 @@ describe('SignInWithRecoveryCodes', () => {
|
||||
let generateRecoveryCodes: GenerateRecoveryCodes
|
||||
let increaseLoginAttempts: IncreaseLoginAttempts
|
||||
let clearLoginAttempts: ClearLoginAttempts
|
||||
let deleteSetting: DeleteSetting
|
||||
|
||||
const createUseCase = () =>
|
||||
new SignInWithRecoveryCodes(
|
||||
@@ -33,6 +35,7 @@ describe('SignInWithRecoveryCodes', () => {
|
||||
generateRecoveryCodes,
|
||||
increaseLoginAttempts,
|
||||
clearLoginAttempts,
|
||||
deleteSetting,
|
||||
)
|
||||
|
||||
beforeEach(() => {
|
||||
@@ -63,6 +66,9 @@ describe('SignInWithRecoveryCodes', () => {
|
||||
|
||||
clearLoginAttempts = {} as jest.Mocked<ClearLoginAttempts>
|
||||
clearLoginAttempts.execute = jest.fn()
|
||||
|
||||
deleteSetting = {} as jest.Mocked<DeleteSetting>
|
||||
deleteSetting.execute = jest.fn()
|
||||
})
|
||||
|
||||
it('should return error if password is not provided', async () => {
|
||||
@@ -213,6 +219,7 @@ describe('SignInWithRecoveryCodes', () => {
|
||||
})
|
||||
|
||||
expect(clearLoginAttempts.execute).toHaveBeenCalled()
|
||||
expect(deleteSetting.execute).toHaveBeenCalled()
|
||||
expect(result.isFailed()).toBe(false)
|
||||
})
|
||||
})
|
||||
|
||||
@@ -14,6 +14,7 @@ import { SignInWithRecoveryCodesDTO } from './SignInWithRecoveryCodesDTO'
|
||||
import { AuthResponseFactory20200115 } from '../../Auth/AuthResponseFactory20200115'
|
||||
import { IncreaseLoginAttempts } from '../IncreaseLoginAttempts'
|
||||
import { ClearLoginAttempts } from '../ClearLoginAttempts'
|
||||
import { DeleteSetting } from '../DeleteSetting/DeleteSetting'
|
||||
|
||||
export class SignInWithRecoveryCodes implements UseCaseInterface<AuthResponse20200115> {
|
||||
constructor(
|
||||
@@ -25,6 +26,7 @@ export class SignInWithRecoveryCodes implements UseCaseInterface<AuthResponse202
|
||||
private generateRecoveryCodes: GenerateRecoveryCodes,
|
||||
private increaseLoginAttempts: IncreaseLoginAttempts,
|
||||
private clearLoginAttempts: ClearLoginAttempts,
|
||||
private deleteSetting: DeleteSetting,
|
||||
) {}
|
||||
|
||||
async execute(dto: SignInWithRecoveryCodesDTO): Promise<Result<AuthResponse20200115>> {
|
||||
@@ -103,6 +105,11 @@ export class SignInWithRecoveryCodes implements UseCaseInterface<AuthResponse202
|
||||
return Result.fail(`Could not sign in with recovery codes: ${generateNewRecoveryCodesResult.getError()}`)
|
||||
}
|
||||
|
||||
await this.deleteSetting.execute({
|
||||
settingName: SettingName.MfaSecret,
|
||||
userUuid: user.uuid,
|
||||
})
|
||||
|
||||
await this.clearLoginAttempts.execute({ email: username.value })
|
||||
|
||||
return Result.ok(authResponse as AuthResponse20200115)
|
||||
|
||||
Reference in New Issue
Block a user