464343f5ab
* WIP * WIP * Type and migration fixes * Adds missing default import * Fixes import * Fixes tRPC imports in App Store * Migrate stripe helpers * WIP * Type fixes * Type fix? * WIP * WIP * Update index.ts * Fixes * Update workflow.tsx * Moved queries to lib * Moves QueryCell * Migrates MultiSelectCheckboxes * WIP * CryptoSection type fixes * WIP * Import fixes * Build fixes * Update app-providers.tsx * Build fixes * Upgrades hookform zod resolvers * Build fixes * Cleanup * Build fixes * Relocates QueryCell to ui * Moved List and SkeletonLoader * Revert QueryCell migration * Can't use QueryCell here * oops * CryptoSection cleanup * Update app-providers.tsx * Moved ee to features * ee to features/ee * Removes @calcom/ee * Adds possible feature locations * Build fixes * Migrates stripe to app-store lib * Colocates stripe imports * Update subscription.ts * Submodule sync Co-authored-by: kodiakhq[bot] <49736102+kodiakhq[bot]@users.noreply.github.com>
74 lines
2.4 KiB
TypeScript
74 lines
2.4 KiB
TypeScript
import { IdentityProvider } from "@prisma/client";
|
|
import { NextApiRequest, NextApiResponse } from "next";
|
|
import { authenticator } from "otplib";
|
|
import qrcode from "qrcode";
|
|
|
|
import { symmetricEncrypt } from "@calcom/lib/crypto";
|
|
import prisma from "@calcom/prisma";
|
|
|
|
import { ErrorCode, getSession, verifyPassword } from "@lib/auth";
|
|
|
|
export default async function handler(req: NextApiRequest, res: NextApiResponse) {
|
|
if (req.method !== "POST") {
|
|
return res.status(405).json({ message: "Method not allowed" });
|
|
}
|
|
|
|
const session = await getSession({ req });
|
|
if (!session) {
|
|
return res.status(401).json({ message: "Not authenticated" });
|
|
}
|
|
|
|
if (!session.user?.id) {
|
|
console.error("Session is missing a user id.");
|
|
return res.status(500).json({ error: ErrorCode.InternalServerError });
|
|
}
|
|
|
|
const user = await prisma.user.findUnique({ where: { id: session.user.id } });
|
|
if (!user) {
|
|
console.error(`Session references user that no longer exists.`);
|
|
return res.status(401).json({ message: "Not authenticated" });
|
|
}
|
|
|
|
if (user.identityProvider !== IdentityProvider.CAL) {
|
|
return res.status(400).json({ error: ErrorCode.ThirdPartyIdentityProviderEnabled });
|
|
}
|
|
|
|
if (!user.password) {
|
|
return res.status(400).json({ error: ErrorCode.UserMissingPassword });
|
|
}
|
|
|
|
if (user.twoFactorEnabled) {
|
|
return res.status(400).json({ error: ErrorCode.TwoFactorAlreadyEnabled });
|
|
}
|
|
|
|
if (!process.env.CALENDSO_ENCRYPTION_KEY) {
|
|
console.error("Missing encryption key; cannot proceed with two factor setup.");
|
|
return res.status(500).json({ error: ErrorCode.InternalServerError });
|
|
}
|
|
|
|
const isCorrectPassword = await verifyPassword(req.body.password, user.password);
|
|
if (!isCorrectPassword) {
|
|
return res.status(400).json({ error: ErrorCode.IncorrectPassword });
|
|
}
|
|
|
|
// This generates a secret 32 characters in length. Do not modify the number of
|
|
// bytes without updating the sanity checks in the enable and login endpoints.
|
|
const secret = authenticator.generateSecret(20);
|
|
|
|
await prisma.user.update({
|
|
where: {
|
|
id: session.user.id,
|
|
},
|
|
data: {
|
|
twoFactorEnabled: false,
|
|
twoFactorSecret: symmetricEncrypt(secret, process.env.CALENDSO_ENCRYPTION_KEY),
|
|
},
|
|
});
|
|
|
|
const name = user.email || user.username || user.id.toString();
|
|
const keyUri = authenticator.keyuri(name, "Cal", secret);
|
|
const dataUri = await qrcode.toDataURL(keyUri);
|
|
|
|
return res.json({ secret, keyUri, dataUri });
|
|
}
|