Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5b203ed248 | ||
|
|
b787d48665 | ||
|
|
e138fb6579 | ||
|
|
3da840c0c9 | ||
|
|
0310f2d2f4 |
116
Cargo.lock
generated
116
Cargo.lock
generated
@@ -572,6 +572,12 @@ dependencies = [
|
||||
"thiserror 1.0.69",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "base32"
|
||||
version = "0.5.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "022dfe9eb35f19ebbcb51e0b40a5ab759f46ad60cadf7297e0bd085afb50e076"
|
||||
|
||||
[[package]]
|
||||
name = "base64"
|
||||
version = "0.22.1"
|
||||
@@ -755,12 +761,24 @@ version = "0.6.9"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "175812e0be2bccb6abe50bb8d566126198344f707e304f45c648fd8f2cc0365e"
|
||||
|
||||
[[package]]
|
||||
name = "bytemuck"
|
||||
version = "1.25.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c8efb64bd706a16a1bdde310ae86b351e4d21550d98d056f22f8a7f7a2183fec"
|
||||
|
||||
[[package]]
|
||||
name = "byteorder"
|
||||
version = "1.5.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1fd0f2584146f6f2ef48085050886acf353beff7305ebd1ae69500e27c67f64b"
|
||||
|
||||
[[package]]
|
||||
name = "byteorder-lite"
|
||||
version = "0.1.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8f1fe948ff07f4bd06c30984e69f5b4899c516a3ef74f34df92a2df2ab535495"
|
||||
|
||||
[[package]]
|
||||
name = "bytes"
|
||||
version = "1.12.0"
|
||||
@@ -1059,6 +1077,12 @@ dependencies = [
|
||||
"tiny-keccak",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "constant_time_eq"
|
||||
version = "0.3.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7c74b8349d32d297c9134b8c88677813a227df8f779daa29bfc29c183fe3dca6"
|
||||
|
||||
[[package]]
|
||||
name = "cookie"
|
||||
version = "0.18.1"
|
||||
@@ -1581,6 +1605,15 @@ version = "2.4.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9f1f227452a390804cdb637b74a86990f2a7d7ba4b7d5693aac9b4dd6defd8d6"
|
||||
|
||||
[[package]]
|
||||
name = "fdeflate"
|
||||
version = "0.3.7"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1e6853b52649d4ac5c0bd02320cddc5ba956bdb407c4b75a2c6b75bf51500f8c"
|
||||
dependencies = [
|
||||
"simd-adler32",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "find-msvc-tools"
|
||||
version = "0.1.9"
|
||||
@@ -2424,6 +2457,19 @@ dependencies = [
|
||||
"winapi-util",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "image"
|
||||
version = "0.25.10"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "85ab80394333c02fe689eaf900ab500fbd0c2213da414687ebf995a65d5a6104"
|
||||
dependencies = [
|
||||
"bytemuck",
|
||||
"byteorder-lite",
|
||||
"moxcms",
|
||||
"num-traits",
|
||||
"png",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "include_dir"
|
||||
version = "0.7.4"
|
||||
@@ -2619,6 +2665,7 @@ dependencies = [
|
||||
"serial_test",
|
||||
"time",
|
||||
"tokio",
|
||||
"totp-rs",
|
||||
"tower-sessions",
|
||||
"tracing",
|
||||
"tracing-subscriber",
|
||||
@@ -3052,6 +3099,16 @@ dependencies = [
|
||||
"uuid",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "moxcms"
|
||||
version = "0.8.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "bb85c154ba489f01b25c0d36ae69a87e4a1c73a72631fc6c0eb6dde34a73e44b"
|
||||
dependencies = [
|
||||
"num-traits",
|
||||
"pxfm",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "multer"
|
||||
version = "3.1.0"
|
||||
@@ -3654,6 +3711,19 @@ version = "0.2.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b4596b6d070b27117e987119b4dac604f3c58cfb0b191112e24771b2faeac1a6"
|
||||
|
||||
[[package]]
|
||||
name = "png"
|
||||
version = "0.18.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "60769b8b31b2a9f263dae2776c37b1b28ae246943cf719eb6946a1db05128a61"
|
||||
dependencies = [
|
||||
"bitflags",
|
||||
"crc32fast",
|
||||
"fdeflate",
|
||||
"flate2",
|
||||
"miniz_oxide",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "polling"
|
||||
version = "3.11.0"
|
||||
@@ -3816,6 +3886,29 @@ dependencies = [
|
||||
"unicase",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "pxfm"
|
||||
version = "0.1.29"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e0c5ccf5294c6ccd63a74f1565028353830a9c2f5eb0c682c355c471726a6e3f"
|
||||
|
||||
[[package]]
|
||||
name = "qrcodegen"
|
||||
version = "1.8.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4339fc7a1021c9c1621d87f5e3505f2805c8c105420ba2f2a4df86814590c142"
|
||||
|
||||
[[package]]
|
||||
name = "qrcodegen-image"
|
||||
version = "1.5.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "99530e45ded4640c0eab5420fc60f9a0ec1be51a22e49cc8578b9a0d8be70712"
|
||||
dependencies = [
|
||||
"base64",
|
||||
"image",
|
||||
"qrcodegen",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "quick-xml"
|
||||
version = "0.38.4"
|
||||
@@ -5739,6 +5832,23 @@ version = "0.1.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5d99f8c9a7727884afe522e9bd5edbfc91a3312b36a77b5fb8926e4c31a41801"
|
||||
|
||||
[[package]]
|
||||
name = "totp-rs"
|
||||
version = "5.7.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "a2b36a9dd327e9f401320a2cb4572cc76ff43742bcfc3291f871691050f140ba"
|
||||
dependencies = [
|
||||
"base32",
|
||||
"constant_time_eq",
|
||||
"hmac",
|
||||
"qrcodegen-image",
|
||||
"rand 0.9.4",
|
||||
"sha1",
|
||||
"sha2",
|
||||
"url",
|
||||
"urlencoding",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tower"
|
||||
version = "0.4.13"
|
||||
@@ -6144,6 +6254,12 @@ dependencies = [
|
||||
"serde_derive",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "urlencoding"
|
||||
version = "2.1.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "daf8dba3b7eb870caf1ddeed7bc9d2a049f3cfdfae7cb521b087cc33ae4c49da"
|
||||
|
||||
[[package]]
|
||||
name = "utf-8"
|
||||
version = "0.7.6"
|
||||
|
||||
@@ -49,6 +49,8 @@ axum-casbin = "1.3.0"
|
||||
loco-oauth2 = "0.5.0"
|
||||
passwords = "3.1.16"
|
||||
tower-sessions = "0.14"
|
||||
# TOTP (Google Authenticator) for optional two-factor auth
|
||||
totp-rs = { version = "5", features = ["qr", "gen_secret"] }
|
||||
|
||||
[[bin]]
|
||||
name = "kompress-eshop-cli"
|
||||
|
||||
@@ -289,6 +289,34 @@ password-change-title = Change password
|
||||
password-current = Current password
|
||||
password-current-wrong = Your current password is incorrect.
|
||||
password-changed = Your password has been changed.
|
||||
|
||||
# Two-factor authentication (TOTP / Google Authenticator)
|
||||
security-title = Security
|
||||
security-2fa-intro = Two-factor authentication (2FA) adds a one-time code from an app like Google Authenticator to your sign-in.
|
||||
security-2fa-on = 2FA is on
|
||||
security-2fa-off = 2FA is off
|
||||
security-2fa-enable = Enable two-factor authentication
|
||||
security-2fa-scan = Scan this QR code in Google Authenticator (or any compatible app).
|
||||
security-2fa-manual = Or enter the key manually:
|
||||
security-2fa-enter-code = Enter the 6-digit code from the app
|
||||
security-2fa-confirm = Confirm and enable
|
||||
security-2fa-code-wrong = That code is wrong or expired. Please try again.
|
||||
security-2fa-enroll-error = Could not start 2FA setup. Please try again.
|
||||
security-2fa-enabled-ok = Two-factor authentication is enabled.
|
||||
security-2fa-backup-intro = Save these backup codes somewhere safe. Each can be used once if you lose access to your app.
|
||||
security-2fa-backup-remaining = Backup codes remaining
|
||||
security-2fa-regenerate = Generate new backup codes
|
||||
security-2fa-disable = Disable two-factor authentication
|
||||
security-2fa-disable-hint = Enter your current password to confirm.
|
||||
|
||||
# Second login step (after password)
|
||||
login-totp-title = Two-factor authentication
|
||||
login-totp-intro = Enter the code from your authenticator app.
|
||||
login-totp-error = That code is wrong or expired.
|
||||
login-totp-code = Verification code
|
||||
login-totp-submit = Verify
|
||||
login-totp-backup-hint = No access to your app? Enter one of your backup codes.
|
||||
|
||||
account-type-locked = Account type can't be changed after registration.
|
||||
checkout-create-account = Create an account from this order
|
||||
checkout-create-account-hint = We'll email you a link to set your password. This order will be linked to your account.
|
||||
|
||||
@@ -289,6 +289,34 @@ password-change-title = Zmeniť heslo
|
||||
password-current = Súčasné heslo
|
||||
password-current-wrong = Vaše súčasné heslo je nesprávne.
|
||||
password-changed = Vaše heslo bolo zmenené.
|
||||
|
||||
# Two-factor authentication (TOTP / Google Authenticator)
|
||||
security-title = Zabezpečenie
|
||||
security-2fa-intro = Dvojfaktorové overenie (2FA) pridáva k prihláseniu jednorazový kód z aplikácie ako Google Authenticator.
|
||||
security-2fa-on = 2FA je zapnuté
|
||||
security-2fa-off = 2FA je vypnuté
|
||||
security-2fa-enable = Zapnúť dvojfaktorové overenie
|
||||
security-2fa-scan = Naskenujte tento QR kód v aplikácii Google Authenticator (alebo inej kompatibilnej).
|
||||
security-2fa-manual = Alebo zadajte kľúč ručne:
|
||||
security-2fa-enter-code = Zadajte 6-miestny kód z aplikácie
|
||||
security-2fa-confirm = Potvrdiť a zapnúť
|
||||
security-2fa-code-wrong = Kód je nesprávny alebo vypršal. Skúste to znova.
|
||||
security-2fa-enroll-error = Nepodarilo sa pripraviť 2FA. Skúste to znova.
|
||||
security-2fa-enabled-ok = Dvojfaktorové overenie je zapnuté.
|
||||
security-2fa-backup-intro = Uložte si tieto záložné kódy na bezpečné miesto. Každý sa dá použiť iba raz, ak nemáte prístup k aplikácii.
|
||||
security-2fa-backup-remaining = Zostávajúce záložné kódy
|
||||
security-2fa-regenerate = Vygenerovať nové záložné kódy
|
||||
security-2fa-disable = Vypnúť dvojfaktorové overenie
|
||||
security-2fa-disable-hint = Na potvrdenie zadajte svoje súčasné heslo.
|
||||
|
||||
# Second login step (after password)
|
||||
login-totp-title = Dvojfaktorové overenie
|
||||
login-totp-intro = Zadajte kód z vašej autentifikačnej aplikácie.
|
||||
login-totp-error = Kód je nesprávny alebo vypršal.
|
||||
login-totp-code = Overovací kód
|
||||
login-totp-submit = Overiť
|
||||
login-totp-backup-hint = Nemáte prístup k aplikácii? Zadajte jeden zo svojich záložných kódov.
|
||||
|
||||
account-type-locked = Typ účtu sa po registrácii nedá zmeniť.
|
||||
checkout-create-account = Vytvoriť účet z tejto objednávky
|
||||
checkout-create-account-hint = Pošleme vám e-mail na nastavenie hesla. Objednávka sa priradí k vášmu účtu.
|
||||
|
||||
File diff suppressed because one or more lines are too long
80
assets/views/account/security.html
Normal file
80
assets/views/account/security.html
Normal file
@@ -0,0 +1,80 @@
|
||||
{% extends "base.html" %}
|
||||
{% import "macros/ui.html" as ui %}
|
||||
|
||||
{% block title %}{{ t(key="security-title", lang=lang | default(value='sk')) }}{% endblock title %}
|
||||
|
||||
{% block content %}
|
||||
<div class="mx-auto max-w-md">
|
||||
<h1 class="text-3xl font-bold text-on-surface-strong dark:text-on-surface-dark-strong">{{ t(key="security-title", lang=lang | default(value='sk')) }}</h1>
|
||||
<p class="mt-2 text-sm text-on-surface dark:text-on-surface-dark">{{ t(key="security-2fa-intro", lang=lang | default(value='sk')) }}</p>
|
||||
|
||||
{% if error == "password" %}
|
||||
{{ ui::alert_danger(message=t(key="password-current-wrong", lang=lang | default(value='sk')), extra="mt-4") }}
|
||||
{% elif error == "code" %}
|
||||
{{ ui::alert_danger(message=t(key="security-2fa-code-wrong", lang=lang | default(value='sk')), extra="mt-4") }}
|
||||
{% elif error == "enroll" %}
|
||||
{{ ui::alert_danger(message=t(key="security-2fa-enroll-error", lang=lang | default(value='sk')), extra="mt-4") }}
|
||||
{% endif %}
|
||||
|
||||
{# --- One-time backup codes, shown right after enabling / regenerating --- #}
|
||||
{% if backup_codes and backup_codes | length > 0 %}
|
||||
<div class="mt-6 rounded-radius border border-success bg-success/10 px-4 py-3" role="status">
|
||||
<p class="text-sm font-medium text-success">{{ t(key="security-2fa-enabled-ok", lang=lang | default(value='sk')) }}</p>
|
||||
<p class="mt-2 text-sm text-on-surface dark:text-on-surface-dark">{{ t(key="security-2fa-backup-intro", lang=lang | default(value='sk')) }}</p>
|
||||
<ul class="mt-3 grid grid-cols-2 gap-2 font-mono text-sm text-on-surface-strong dark:text-on-surface-dark-strong">
|
||||
{% for code in backup_codes %}
|
||||
<li class="rounded-radius bg-surface px-3 py-1.5 text-center tracking-wider dark:bg-surface-dark">{{ code }}</li>
|
||||
{% endfor %}
|
||||
</ul>
|
||||
</div>
|
||||
{% endif %}
|
||||
|
||||
{% if enrolling %}
|
||||
{# --- Step 2: scan the QR and confirm a code --- #}
|
||||
<div class="mt-6 flex flex-col gap-4 rounded-radius border border-outline bg-surface-alt p-5 dark:border-outline-dark dark:bg-surface-dark-alt">
|
||||
<p class="text-sm text-on-surface dark:text-on-surface-dark">{{ t(key="security-2fa-scan", lang=lang | default(value='sk')) }}</p>
|
||||
<img src="{{ qr }}" alt="TOTP QR" class="mx-auto size-48 rounded-radius bg-white p-2" />
|
||||
<div class="text-center">
|
||||
<p class="text-xs text-on-surface dark:text-on-surface-dark">{{ t(key="security-2fa-manual", lang=lang | default(value='sk')) }}</p>
|
||||
<code class="mt-1 inline-block break-all font-mono text-sm text-on-surface-strong dark:text-on-surface-dark-strong">{{ secret }}</code>
|
||||
</div>
|
||||
<form method="post" action="/account/security/confirm" hx-boost="false" class="flex flex-col gap-3">
|
||||
<label for="code" class="text-sm font-medium text-on-surface-strong dark:text-on-surface-dark-strong">{{ t(key="security-2fa-enter-code", lang=lang | default(value='sk')) }}</label>
|
||||
{{ ui::input(name="code", id="code", type="text", required=true, autocomplete="one-time-code", attrs='inputmode="numeric" pattern="[0-9]*" maxlength="6" autofocus') }}
|
||||
{{ ui::button(label=t(key="security-2fa-confirm", lang=lang | default(value='sk')), type="submit", extra="w-full") }}
|
||||
</form>
|
||||
</div>
|
||||
|
||||
{% elif totp_enabled %}
|
||||
{# --- Enabled: status + remaining backup codes + disable / regenerate --- #}
|
||||
<div class="mt-6 flex items-center gap-2">
|
||||
{{ ui::badge(label=t(key="security-2fa-on", lang=lang | default(value='sk')), variant="success") }}
|
||||
<span class="text-sm text-on-surface dark:text-on-surface-dark">{{ t(key="security-2fa-backup-remaining", lang=lang | default(value='sk')) }}: {{ backup_remaining }}</span>
|
||||
</div>
|
||||
|
||||
<form method="post" action="/account/security/backup-codes" hx-boost="false" class="mt-6 flex flex-col gap-3 rounded-radius border border-outline bg-surface-alt p-5 dark:border-outline-dark dark:bg-surface-dark-alt">
|
||||
<p class="text-sm font-medium text-on-surface-strong dark:text-on-surface-dark-strong">{{ t(key="security-2fa-regenerate", lang=lang | default(value='sk')) }}</p>
|
||||
<label for="regen_pw" class="text-sm text-on-surface dark:text-on-surface-dark">{{ t(key="password-current", lang=lang | default(value='sk')) }}</label>
|
||||
{{ ui::input(name="current_password", id="regen_pw", type="password", required=true, autocomplete="current-password") }}
|
||||
{{ ui::button(label=t(key="security-2fa-regenerate", lang=lang | default(value='sk')), type="submit", variant="outline-secondary", extra="w-full") }}
|
||||
</form>
|
||||
|
||||
<form method="post" action="/account/security/disable" hx-boost="false" class="mt-4 flex flex-col gap-3 rounded-radius border border-danger/40 bg-danger/5 p-5">
|
||||
<p class="text-sm font-medium text-danger">{{ t(key="security-2fa-disable", lang=lang | default(value='sk')) }}</p>
|
||||
<p class="text-xs text-on-surface dark:text-on-surface-dark">{{ t(key="security-2fa-disable-hint", lang=lang | default(value='sk')) }}</p>
|
||||
<label for="disable_pw" class="text-sm text-on-surface dark:text-on-surface-dark">{{ t(key="password-current", lang=lang | default(value='sk')) }}</label>
|
||||
{{ ui::input(name="current_password", id="disable_pw", type="password", required=true, autocomplete="current-password") }}
|
||||
{{ ui::button(label=t(key="security-2fa-disable", lang=lang | default(value='sk')), type="submit", variant="danger", extra="w-full") }}
|
||||
</form>
|
||||
|
||||
{% else %}
|
||||
{# --- Disabled: offer to enable --- #}
|
||||
<form method="post" action="/account/security/enable" hx-boost="false" class="mt-6">
|
||||
<div class="flex items-center gap-2">
|
||||
{{ ui::badge(label=t(key="security-2fa-off", lang=lang | default(value='sk')), variant="neutral") }}
|
||||
</div>
|
||||
{{ ui::button(label=t(key="security-2fa-enable", lang=lang | default(value='sk')), type="submit", extra="mt-4 w-full") }}
|
||||
</form>
|
||||
{% endif %}
|
||||
</div>
|
||||
{% endblock content %}
|
||||
47
assets/views/auth/login_totp.html
Normal file
47
assets/views/auth/login_totp.html
Normal file
@@ -0,0 +1,47 @@
|
||||
{% extends "base.html" %}
|
||||
{% import "macros/ui.html" as ui %}
|
||||
|
||||
{% block title %}{{ t(key="login-totp-title", lang=lang | default(value='sk')) }}{% endblock title %}
|
||||
|
||||
{% block content %}
|
||||
<div class="mx-auto mt-8 max-w-sm">
|
||||
<div
|
||||
class="rounded-radius border border-outline bg-surface-alt shadow-sm dark:border-outline-dark dark:bg-surface-dark-alt">
|
||||
<div
|
||||
class="flex items-center justify-between border-b border-outline px-5 py-3 dark:border-outline-dark">
|
||||
<span class="text-sm font-medium text-on-surface-strong dark:text-on-surface-dark-strong">
|
||||
{{ t(key="brand", lang=lang | default(value='sk')) }}
|
||||
</span>
|
||||
{{ ui::badge(label=t(key="auth", lang=lang | default(value='sk')), variant="primary") }}
|
||||
</div>
|
||||
|
||||
<div class="p-5">
|
||||
<h1 class="text-xl font-bold text-on-surface-strong dark:text-on-surface-dark-strong">
|
||||
{{ t(key="login-totp-title", lang=lang | default(value='sk')) }}
|
||||
</h1>
|
||||
<p class="mt-2 text-sm text-on-surface dark:text-on-surface-dark">
|
||||
{{ t(key="login-totp-intro", lang=lang | default(value='sk')) }}
|
||||
</p>
|
||||
|
||||
{% if error %}
|
||||
{{ ui::alert_danger(message=t(key="login-totp-error", lang=lang | default(value='sk')), extra="mt-3") }}
|
||||
{% endif %}
|
||||
|
||||
<form method="post" action="/login/totp" hx-boost="false" class="mt-4 flex flex-col gap-4">
|
||||
<div class="flex flex-col gap-1">
|
||||
<label for="code"
|
||||
class="text-sm font-medium text-on-surface-strong dark:text-on-surface-dark-strong">
|
||||
{{ t(key="login-totp-code", lang=lang | default(value='sk')) }}
|
||||
</label>
|
||||
{{ ui::input(name="code", id="code", type="text", required=true, autocomplete="one-time-code", attrs='inputmode="numeric" autofocus') }}
|
||||
</div>
|
||||
{{ ui::button(label=t(key="login-totp-submit", lang=lang | default(value='sk')), type="submit", extra="mt-1 w-full") }}
|
||||
</form>
|
||||
|
||||
<p class="mt-4 text-xs text-on-surface dark:text-on-surface-dark">
|
||||
{{ t(key="login-totp-backup-hint", lang=lang | default(value='sk')) }}
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
{% endblock content %}
|
||||
@@ -48,6 +48,12 @@
|
||||
if (!v) return 0;
|
||||
return v.split(',').reduce(function (s, e) { return s + (parseInt(e.split(':')[1]) || 0) }, 0);
|
||||
}
|
||||
// True while any other navbar menu (profile / settings / mobile / category
|
||||
// toggle) is open — those triggers expose aria-expanded="true". Used to
|
||||
// suppress the cart hover preview so menus don't stack/overlap.
|
||||
function anyMenuOpen() {
|
||||
return !!document.querySelector('header [aria-expanded="true"]');
|
||||
}
|
||||
// Show a floating toast notification. Usage: toast('Saved').
|
||||
// Bridges to the vendored Penguin UI toast component, which listens for a
|
||||
// `notify` event with { variant, title, message }.
|
||||
@@ -97,23 +103,43 @@
|
||||
</ul>
|
||||
|
||||
<!-- right side: cart + settings + mobile toggle -->
|
||||
<div class="ml-auto flex items-center gap-2">
|
||||
<div class="ml-auto flex items-center gap-3">
|
||||
<!-- customer profile dropdown (avatar + name + account type) -->
|
||||
{% if logged_in_customer %}
|
||||
{% include "partials/profile_menu.html" %}
|
||||
{% endif %}
|
||||
<!-- cart with live item-count badge read from the `cart` cookie.
|
||||
hx-boost=false: a plain full-page navigation to /cart, no SPA swap. -->
|
||||
<a href="/cart" data-nav="/cart" hx-boost="false"
|
||||
x-data="{ count: 0 }"
|
||||
x-init="count = cartCount(); ['htmx:afterSwap', 'htmx:afterRequest'].forEach(function (e) { window.addEventListener(e, function () { count = cartCount() }) })"
|
||||
aria-label="{{ t(key='cart-title', lang=lang | default(value='sk')) }}"
|
||||
title="{{ t(key='cart-title', lang=lang | default(value='sk')) }}"
|
||||
class="relative inline-flex size-9 shrink-0 items-center justify-center rounded-radius bg-transparent text-secondary transition hover:opacity-75 focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-secondary active:opacity-100 active:outline-offset-0 dark:text-secondary-dark dark:focus-visible:outline-secondary-dark">
|
||||
{{ ui::icon(name="cart") }}
|
||||
<span x-show="count > 0" x-cloak x-text="count"
|
||||
class="absolute -right-1 -top-1 inline-flex min-w-4 items-center justify-center rounded-full bg-primary px-1 text-[10px] font-semibold leading-4 text-on-primary dark:bg-primary-dark dark:text-on-primary-dark"></span>
|
||||
</a>
|
||||
<!-- cart: hover opens an Alza-style mini-cart preview (Penguin
|
||||
dropdown-with-hover), lazy-loaded from /partials/cart on each hover
|
||||
so it's always fresh. Click still does a full navigation to /cart
|
||||
(hx-boost=false; the explicit hx-trigger is mouseenter, so click is
|
||||
not an htmx trigger). The badge reads the `cart` cookie client-side. -->
|
||||
<div x-data="{ isOpen: false, leaveTimeout: null }"
|
||||
x-on:mouseleave="leaveTimeout = setTimeout(() => isOpen = false, 250)"
|
||||
x-on:mouseenter="leaveTimeout && clearTimeout(leaveTimeout)"
|
||||
x-on:keydown.esc.window="isOpen = false"
|
||||
class="relative">
|
||||
<a href="/cart" data-nav="/cart" hx-boost="false"
|
||||
x-on:mouseenter="if (!anyMenuOpen()) isOpen = true"
|
||||
x-data="{ count: 0 }"
|
||||
x-init="count = cartCount(); ['htmx:afterSwap', 'htmx:afterRequest'].forEach(function (e) { window.addEventListener(e, function () { count = cartCount() }) })"
|
||||
hx-get="/partials/cart" hx-trigger="mouseenter delay:150ms" hx-target="#cart-preview-body" hx-swap="innerHTML"
|
||||
aria-label="{{ t(key='cart-title', lang=lang | default(value='sk')) }}"
|
||||
title="{{ t(key='cart-title', lang=lang | default(value='sk')) }}"
|
||||
class="relative inline-flex size-9 shrink-0 items-center justify-center rounded-radius bg-transparent text-secondary transition hover:opacity-75 focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-secondary active:opacity-100 active:outline-offset-0 dark:text-secondary-dark dark:focus-visible:outline-secondary-dark">
|
||||
{{ ui::icon(name="cart") }}
|
||||
<span x-show="count > 0" x-cloak x-text="count"
|
||||
class="absolute -right-1 -top-1 inline-flex min-w-4 items-center justify-center rounded-full bg-primary px-1 text-[10px] font-semibold leading-4 text-on-primary dark:bg-primary-dark dark:text-on-primary-dark"></span>
|
||||
</a>
|
||||
<!-- hover preview panel (no id on the panel → not htmx-settled on boosted nav) -->
|
||||
<div x-cloak x-show="isOpen" x-transition
|
||||
x-on:mouseenter="isOpen = true"
|
||||
class="absolute right-0 mt-2 w-80 overflow-hidden rounded-radius border border-outline bg-surface-alt shadow-lg dark:border-outline-dark dark:bg-surface-dark-alt"
|
||||
role="dialog" aria-label="{{ t(key='cart-title', lang=lang | default(value='sk')) }}">
|
||||
<div id="cart-preview-body">
|
||||
<div class="px-4 py-10 text-center text-sm text-on-surface dark:text-on-surface-dark">…</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- settings (language + theme) dropdown (self-contained Alpine state) -->
|
||||
{% include "partials/settings_dropdown.html" %}
|
||||
@@ -170,6 +196,7 @@
|
||||
<li><a href="/account/orders" data-nav="/account/orders" class="block rounded-radius px-3 py-2 text-sm font-medium text-on-surface underline-offset-2 transition hover:bg-primary/5 hover:text-primary focus:outline-hidden focus-visible:underline aria-[current=page]:font-semibold aria-[current=page]:bg-primary/10 aria-[current=page]:text-primary dark:text-on-surface-dark dark:hover:text-primary-dark dark:aria-[current=page]:text-primary-dark">{{ t(key="account-orders", lang=lang | default(value='sk')) }}</a></li>
|
||||
<li><a href="/account/profile" data-nav="/account/profile" class="block rounded-radius px-3 py-2 text-sm font-medium text-on-surface underline-offset-2 transition hover:bg-primary/5 hover:text-primary focus:outline-hidden focus-visible:underline aria-[current=page]:font-semibold aria-[current=page]:bg-primary/10 aria-[current=page]:text-primary dark:text-on-surface-dark dark:hover:text-primary-dark dark:aria-[current=page]:text-primary-dark">{{ t(key="profile-title", lang=lang | default(value='sk')) }}</a></li>
|
||||
<li><a href="/account/password" data-nav="/account/password" class="block rounded-radius px-3 py-2 text-sm font-medium text-on-surface underline-offset-2 transition hover:bg-primary/5 hover:text-primary focus:outline-hidden focus-visible:underline aria-[current=page]:font-semibold aria-[current=page]:bg-primary/10 aria-[current=page]:text-primary dark:text-on-surface-dark dark:hover:text-primary-dark dark:aria-[current=page]:text-primary-dark">{{ t(key="account-change-password", lang=lang | default(value='sk')) }}</a></li>
|
||||
<li><a href="/account/security" data-nav="/account/security" class="block rounded-radius px-3 py-2 text-sm font-medium text-on-surface underline-offset-2 transition hover:bg-primary/5 hover:text-primary focus:outline-hidden focus-visible:underline aria-[current=page]:font-semibold aria-[current=page]:bg-primary/10 aria-[current=page]:text-primary dark:text-on-surface-dark dark:hover:text-primary-dark dark:aria-[current=page]:text-primary-dark">{{ t(key="security-title", lang=lang | default(value='sk')) }}</a></li>
|
||||
</ul>
|
||||
<form method="post" action="/logout" hx-boost="false" class="mt-4 border-t border-outline pt-3 dark:border-outline-dark">
|
||||
<button type="submit" class="block w-full rounded-radius px-3 py-2 text-left text-sm font-medium text-danger underline-offset-2 transition hover:bg-primary/5 focus:outline-hidden focus-visible:underline">{{ t(key="logout", lang=lang | default(value='sk')) }}</button>
|
||||
|
||||
@@ -61,6 +61,10 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" aria-hidden="true" fill="currentColor" class="size-4 shrink-0"><path fill-rule="evenodd" d="M15.75 1.5a6.75 6.75 0 00-6.651 7.906c.067.39-.032.717-.221.906l-6.5 6.499a3 3 0 00-.878 2.121v2.818c0 .414.336.75.75.75H6a.75.75 0 00.75-.75v-1.5h1.5A.75.75 0 009 21v-1.5h1.5a.75.75 0 00.53-.22l2.658-2.658c.19-.189.517-.288.906-.22A6.75 6.75 0 1015.75 1.5zm0 3a.75.75 0 000 1.5A2.25 2.25 0 0118 8.25a.75.75 0 001.5 0 3.75 3.75 0 00-3.75-3.75z" clip-rule="evenodd"/></svg>
|
||||
{{ t(key="account-change-password", lang=lang | default(value='sk')) }}
|
||||
</a>
|
||||
<a href="/account/security" data-nav="/account/security" role="menuitem" class="flex items-center gap-2 bg-surface-alt px-4 py-2 text-sm text-on-surface hover:bg-surface-dark-alt/5 hover:text-on-surface-strong focus-visible:bg-surface-dark-alt/10 focus-visible:text-on-surface-strong focus-visible:outline-hidden dark:bg-surface-dark-alt dark:text-on-surface-dark dark:hover:bg-surface-alt/5 dark:hover:text-on-surface-dark-strong dark:focus-visible:bg-surface-alt/10 dark:focus-visible:text-on-surface-dark-strong">
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" aria-hidden="true" fill="currentColor" class="size-4 shrink-0"><path fill-rule="evenodd" d="M12 1.5a5.25 5.25 0 00-5.25 5.25v3a3 3 0 00-3 3v6.75a3 3 0 003 3h10.5a3 3 0 003-3v-6.75a3 3 0 00-3-3v-3c0-2.9-2.35-5.25-5.25-5.25zm3.75 8.25v-3a3.75 3.75 0 10-7.5 0v3h7.5z" clip-rule="evenodd"/></svg>
|
||||
{{ t(key="security-title", lang=lang | default(value='sk')) }}
|
||||
</a>
|
||||
</div>
|
||||
<!-- logout -->
|
||||
<div class="flex flex-col py-1.5">
|
||||
|
||||
@@ -62,7 +62,7 @@
|
||||
|
||||
<div class="mt-6 flex flex-wrap justify-between gap-3">
|
||||
{{ ui::button(variant="outline-secondary", label=t(key="cart-continue", lang=lang | default(value='sk')), href="/shop") }}
|
||||
{{ ui::button(label=t(key="cart-checkout", lang=lang | default(value='sk')), href="/checkout", size="px-5 py-2 text-sm") }}
|
||||
{{ ui::button(label=t(key="cart-checkout", lang=lang | default(value='sk')), href="/checkout", size="px-5 py-2 text-sm", attrs='hx-boost="false"') }}
|
||||
</div>
|
||||
{% else %}
|
||||
<div class="rounded-radius border border-outline px-6 py-16 text-center dark:border-outline-dark">
|
||||
|
||||
31
assets/views/shop/_cart_preview.html
Normal file
31
assets/views/shop/_cart_preview.html
Normal file
@@ -0,0 +1,31 @@
|
||||
{# Mini-cart preview shown on hover over the navbar cart (Alza-style).
|
||||
Lazy-loaded via htmx from /partials/cart into the hover dropdown panel in
|
||||
base.html. Receives: items[], total, currency, lang. #}
|
||||
{% import "macros/ui.html" as ui %}
|
||||
{% if items | length > 0 %}
|
||||
<div class="max-h-80 divide-y divide-outline overflow-y-auto dark:divide-outline-dark">
|
||||
{% for item in items %}
|
||||
<div class="flex items-start gap-3 px-4 py-3">
|
||||
<div class="min-w-0 flex-1">
|
||||
<a href="/shop/{{ item.slug }}" class="block truncate text-sm font-medium text-on-surface-strong hover:text-primary dark:text-on-surface-dark-strong dark:hover:text-primary-dark">{{ item.name }}</a>
|
||||
<p class="mt-0.5 text-xs tabular-nums text-on-surface dark:text-on-surface-dark">{{ item.quantity }} × {{ item.price }} {{ item.currency }}</p>
|
||||
</div>
|
||||
<span class="shrink-0 text-sm font-semibold tabular-nums text-on-surface-strong dark:text-on-surface-dark-strong">{{ item.line_total }} {{ item.currency }}</span>
|
||||
</div>
|
||||
{% endfor %}
|
||||
</div>
|
||||
<div class="border-t border-outline px-4 py-3 dark:border-outline-dark">
|
||||
<div class="mb-3 flex items-center justify-between">
|
||||
<span class="text-sm text-on-surface dark:text-on-surface-dark">{{ t(key="cart-total", lang=lang | default(value='sk')) }}</span>
|
||||
<span class="text-base font-bold tabular-nums text-primary dark:text-primary-dark">{{ total }} {{ currency }}</span>
|
||||
</div>
|
||||
<div class="flex gap-2">
|
||||
{{ ui::button(href="/cart", variant="outline-primary", label=t(key="cart-title", lang=lang | default(value='sk')), extra="flex-1", attrs='hx-boost="false"') }}
|
||||
{{ ui::button(href="/checkout", variant="primary", label=t(key="cart-checkout", lang=lang | default(value='sk')), extra="flex-1", attrs='hx-boost="false"') }}
|
||||
</div>
|
||||
</div>
|
||||
{% else %}
|
||||
<div class="px-4 py-10 text-center text-sm text-on-surface dark:text-on-surface-dark">
|
||||
{{ t(key="cart-empty", lang=lang | default(value='sk')) }}
|
||||
</div>
|
||||
{% endif %}
|
||||
@@ -34,6 +34,7 @@ mod m20260618_000001_o_auth2_sessions;
|
||||
mod m20260618_000002_customer_profiles;
|
||||
mod m20260618_000003_account_type;
|
||||
mod m20260618_000004_account_ownership;
|
||||
mod m20260620_000001_add_totp_to_users;
|
||||
pub struct Migrator;
|
||||
|
||||
#[async_trait::async_trait]
|
||||
@@ -72,6 +73,7 @@ impl MigratorTrait for Migrator {
|
||||
Box::new(m20260618_000002_customer_profiles::Migration),
|
||||
Box::new(m20260618_000003_account_type::Migration),
|
||||
Box::new(m20260618_000004_account_ownership::Migration),
|
||||
Box::new(m20260620_000001_add_totp_to_users::Migration),
|
||||
// inject-above (do not remove this comment)
|
||||
]
|
||||
}
|
||||
|
||||
32
migration/src/m20260620_000001_add_totp_to_users.rs
Normal file
32
migration/src/m20260620_000001_add_totp_to_users.rs
Normal file
@@ -0,0 +1,32 @@
|
||||
use loco_rs::schema::*;
|
||||
use sea_orm_migration::prelude::*;
|
||||
|
||||
#[derive(DeriveMigrationName)]
|
||||
pub struct Migration;
|
||||
|
||||
// Optional TOTP (Google Authenticator) two-factor auth. All three columns are
|
||||
// nullable and only populated once a user opts in:
|
||||
// - `totp_secret` base32 shared secret; present while enrolling/enabled.
|
||||
// TODO(security): stored PLAINTEXT and is password-
|
||||
// equivalent (must stay reversible to recompute codes).
|
||||
// Encrypt at rest later with an out-of-DB key. See the
|
||||
// TODO(security) block in src/models/users.rs.
|
||||
// - `totp_enabled_at` NULL = 2FA off. Set only after the user confirms a
|
||||
// code, so a half-finished enrollment never gates login.
|
||||
// - `totp_backup_codes` JSON array of hashed one-time recovery codes.
|
||||
#[async_trait::async_trait]
|
||||
impl MigrationTrait for Migration {
|
||||
async fn up(&self, m: &SchemaManager) -> Result<(), DbErr> {
|
||||
add_column(m, "users", "totp_secret", ColType::TextNull).await?;
|
||||
add_column(m, "users", "totp_enabled_at", ColType::TimestampWithTimeZoneNull).await?;
|
||||
add_column(m, "users", "totp_backup_codes", ColType::TextNull).await?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn down(&self, m: &SchemaManager) -> Result<(), DbErr> {
|
||||
remove_column(m, "users", "totp_backup_codes").await?;
|
||||
remove_column(m, "users", "totp_enabled_at").await?;
|
||||
remove_column(m, "users", "totp_secret").await?;
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
@@ -363,6 +363,177 @@ async fn change_password(
|
||||
password_view(&v, &jar, &user, true, None)
|
||||
}
|
||||
|
||||
// ---- Two-factor authentication (TOTP / Google Authenticator) -------------
|
||||
//
|
||||
// Entirely opt-in. The security page has three shapes, all rendered from
|
||||
// `security.html`:
|
||||
// * disabled -> an "enable" button,
|
||||
// * enrolling -> the QR + a confirm-code field (secret staged, not yet on),
|
||||
// * enabled -> status, remaining backup codes, disable/regenerate forms.
|
||||
// Both turning 2FA off and regenerating backup codes require re-entering the
|
||||
// account password, so a walk-up attacker on an open session can't weaken it.
|
||||
|
||||
#[derive(Debug, Deserialize)]
|
||||
struct ConfirmTotpForm {
|
||||
code: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize)]
|
||||
struct PasswordConfirmForm {
|
||||
current_password: String,
|
||||
}
|
||||
|
||||
/// Render the security page. Exactly one of (`enrolling`, plain status) applies;
|
||||
/// `backup_codes` is non-empty only on the one render right after enabling or
|
||||
/// regenerating, where the plaintext codes are shown once.
|
||||
#[allow(clippy::too_many_arguments)]
|
||||
fn security_view(
|
||||
v: &TeraView,
|
||||
jar: &CookieJar,
|
||||
user: &users::Model,
|
||||
enrolling: bool,
|
||||
qr: Option<&str>,
|
||||
secret: Option<&str>,
|
||||
backup_codes: &[String],
|
||||
error: Option<&str>,
|
||||
) -> Result<Response> {
|
||||
format::view(
|
||||
v,
|
||||
"account/security.html",
|
||||
json!({
|
||||
"logged_in_admin": false,
|
||||
"logged_in_customer": true,
|
||||
"account_nav": true,
|
||||
"customer_name": user.name,
|
||||
"customer_account_type": user.account_type,
|
||||
"totp_enabled": user.totp_enabled(),
|
||||
"enrolling": enrolling,
|
||||
"qr": qr,
|
||||
"secret": secret,
|
||||
"backup_codes": backup_codes,
|
||||
"backup_remaining": user.backup_codes_remaining(),
|
||||
"error": error,
|
||||
"lang": current_lang(jar),
|
||||
}),
|
||||
)
|
||||
}
|
||||
|
||||
/// Common guard for every security handler: a signed-in, non-admin customer.
|
||||
async fn require_customer(ctx: &AppContext, jar: &CookieJar) -> Result<users::Model> {
|
||||
match guard::current_user(ctx, jar).await {
|
||||
Some(user) if guard::is_admin(ctx, &user) => Err(Error::string("admin")),
|
||||
Some(user) => Ok(user),
|
||||
None => Err(Error::Unauthorized("login required".into())),
|
||||
}
|
||||
}
|
||||
|
||||
#[debug_handler]
|
||||
async fn security_page(
|
||||
jar: CookieJar,
|
||||
ViewEngine(v): ViewEngine<TeraView>,
|
||||
State(ctx): State<AppContext>,
|
||||
) -> Result<Response> {
|
||||
let Some(user) = guard::current_user(&ctx, &jar).await else {
|
||||
return format::redirect("/login");
|
||||
};
|
||||
if guard::is_admin(&ctx, &user) {
|
||||
return format::redirect("/admin/dashboard");
|
||||
}
|
||||
security_view(&v, &jar, &user, false, None, None, &[], None)
|
||||
}
|
||||
|
||||
/// Stage a fresh secret and show the QR + confirm-code field.
|
||||
#[debug_handler]
|
||||
async fn enable_totp(
|
||||
jar: CookieJar,
|
||||
ViewEngine(v): ViewEngine<TeraView>,
|
||||
State(ctx): State<AppContext>,
|
||||
) -> Result<Response> {
|
||||
let Ok(user) = require_customer(&ctx, &jar).await else {
|
||||
return format::redirect("/login");
|
||||
};
|
||||
// Already on — nothing to enroll.
|
||||
if user.totp_enabled() {
|
||||
return security_view(&v, &jar, &user, false, None, None, &[], None);
|
||||
}
|
||||
let user = user.into_active_model().begin_totp_enrollment(&ctx.db).await?;
|
||||
let Some((qr, secret)) = user.totp_provisioning() else {
|
||||
return security_view(&v, &jar, &user, false, None, None, &[], Some("enroll"));
|
||||
};
|
||||
security_view(&v, &jar, &user, true, Some(&qr), Some(&secret), &[], None)
|
||||
}
|
||||
|
||||
/// Verify the first code against the staged secret; on success flip 2FA on and
|
||||
/// show the one-time backup codes. On a wrong code, re-show the QR to retry.
|
||||
#[debug_handler]
|
||||
async fn confirm_totp(
|
||||
jar: CookieJar,
|
||||
ViewEngine(v): ViewEngine<TeraView>,
|
||||
State(ctx): State<AppContext>,
|
||||
Form(form): Form<ConfirmTotpForm>,
|
||||
) -> Result<Response> {
|
||||
let Ok(user) = require_customer(&ctx, &jar).await else {
|
||||
return format::redirect("/login");
|
||||
};
|
||||
if user.totp_enabled() {
|
||||
return security_view(&v, &jar, &user, false, None, None, &[], None);
|
||||
}
|
||||
if !user.verify_totp_code(&form.code) {
|
||||
let qr = user.totp_provisioning();
|
||||
let (qr, secret) = match &qr {
|
||||
Some((q, s)) => (Some(q.as_str()), Some(s.as_str())),
|
||||
None => (None, None),
|
||||
};
|
||||
return security_view(&v, &jar, &user, true, qr, secret, &[], Some("code"));
|
||||
}
|
||||
let (user, backup_codes) = user.into_active_model().enable_totp(&ctx.db).await?;
|
||||
security_view(&v, &jar, &user, false, None, None, &backup_codes, None)
|
||||
}
|
||||
|
||||
/// Turn 2FA off — requires the account password as confirmation.
|
||||
#[debug_handler]
|
||||
async fn disable_totp(
|
||||
jar: CookieJar,
|
||||
ViewEngine(v): ViewEngine<TeraView>,
|
||||
State(ctx): State<AppContext>,
|
||||
Form(form): Form<PasswordConfirmForm>,
|
||||
) -> Result<Response> {
|
||||
let Ok(user) = require_customer(&ctx, &jar).await else {
|
||||
return format::redirect("/login");
|
||||
};
|
||||
if !user.totp_enabled() {
|
||||
return security_view(&v, &jar, &user, false, None, None, &[], None);
|
||||
}
|
||||
if !user.verify_password(&form.current_password) {
|
||||
return security_view(&v, &jar, &user, false, None, None, &[], Some("password"));
|
||||
}
|
||||
let user = user.into_active_model().disable_totp(&ctx.db).await?;
|
||||
security_view(&v, &jar, &user, false, None, None, &[], None)
|
||||
}
|
||||
|
||||
/// Issue a fresh set of backup codes (invalidating the old ones) — also gated by
|
||||
/// the account password.
|
||||
#[debug_handler]
|
||||
async fn regenerate_backup_codes(
|
||||
jar: CookieJar,
|
||||
ViewEngine(v): ViewEngine<TeraView>,
|
||||
State(ctx): State<AppContext>,
|
||||
Form(form): Form<PasswordConfirmForm>,
|
||||
) -> Result<Response> {
|
||||
let Ok(user) = require_customer(&ctx, &jar).await else {
|
||||
return format::redirect("/login");
|
||||
};
|
||||
if !user.totp_enabled() {
|
||||
return security_view(&v, &jar, &user, false, None, None, &[], None);
|
||||
}
|
||||
if !user.verify_password(&form.current_password) {
|
||||
return security_view(&v, &jar, &user, false, None, None, &[], Some("password"));
|
||||
}
|
||||
let (user, backup_codes) =
|
||||
user.into_active_model().regenerate_backup_codes(&ctx.db).await?;
|
||||
security_view(&v, &jar, &user, false, None, None, &backup_codes, None)
|
||||
}
|
||||
|
||||
pub fn routes() -> Routes {
|
||||
Routes::new()
|
||||
.add("/account/profile", get(profile_page))
|
||||
@@ -371,4 +542,9 @@ pub fn routes() -> Routes {
|
||||
.add("/account/orders/{order_number}", get(order_detail_page))
|
||||
.add("/account/password", get(change_password_page))
|
||||
.add("/account/password", post(change_password))
|
||||
.add("/account/security", get(security_page))
|
||||
.add("/account/security/enable", post(enable_totp))
|
||||
.add("/account/security/confirm", post(confirm_totp))
|
||||
.add("/account/security/disable", post(disable_totp))
|
||||
.add("/account/security/backup-codes", post(regenerate_backup_codes))
|
||||
}
|
||||
|
||||
@@ -13,6 +13,13 @@ use time::Duration as TimeDuration;
|
||||
|
||||
pub static EMAIL_DOMAIN_RE: OnceLock<Regex> = OnceLock::new();
|
||||
pub(crate) const AUTH_COOKIE: &str = "auth_token";
|
||||
/// Short-lived cookie that carries a half-authenticated session between the
|
||||
/// password step and the TOTP step. It is a *separate* name from `auth_token`
|
||||
/// on purpose: the auth guards only read `auth_token`, so this cookie can never
|
||||
/// authenticate a request on its own — it only proves the password step passed.
|
||||
pub(crate) const TOTP_PENDING_COOKIE: &str = "totp_pending";
|
||||
/// How long the user has to enter their 2FA code after the password step.
|
||||
pub(crate) const TOTP_PENDING_TTL_SECS: u64 = 300;
|
||||
|
||||
fn get_allow_email_domain_re() -> &'static Regex {
|
||||
EMAIL_DOMAIN_RE.get_or_init(|| {
|
||||
@@ -38,6 +45,24 @@ pub(crate) fn clear_auth_cookie() -> Cookie<'static> {
|
||||
.build()
|
||||
}
|
||||
|
||||
pub(crate) fn totp_pending_cookie(token: &str, max_age_seconds: u64) -> Cookie<'static> {
|
||||
Cookie::build((TOTP_PENDING_COOKIE, token.to_string()))
|
||||
.path("/")
|
||||
.http_only(true)
|
||||
.same_site(SameSite::Lax)
|
||||
.max_age(TimeDuration::seconds(max_age_seconds as i64))
|
||||
.build()
|
||||
}
|
||||
|
||||
pub(crate) fn clear_totp_pending_cookie() -> Cookie<'static> {
|
||||
Cookie::build((TOTP_PENDING_COOKIE, ""))
|
||||
.path("/")
|
||||
.http_only(true)
|
||||
.same_site(SameSite::Lax)
|
||||
.max_age(TimeDuration::seconds(0))
|
||||
.build()
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize, Serialize)]
|
||||
pub struct ForgotParams {
|
||||
pub email: String,
|
||||
|
||||
@@ -85,6 +85,23 @@ async fn login(
|
||||
}
|
||||
|
||||
let jwt_secret = ctx.config.get_jwt_config()?;
|
||||
|
||||
// If the user opted into 2FA, the password is only the first factor: don't
|
||||
// issue the real auth cookie yet. Hand out a short-lived, separate "pending"
|
||||
// cookie and send them to the code-entry page. Everyone without 2FA logs in
|
||||
// in a single step exactly as before.
|
||||
if user.totp_enabled() {
|
||||
let pending = user
|
||||
.generate_jwt(&jwt_secret.secret, auth_controller::TOTP_PENDING_TTL_SECS)
|
||||
.or_else(|_| unauthorized("unauthorized!"))?;
|
||||
return format::render()
|
||||
.cookies(&[auth_controller::totp_pending_cookie(
|
||||
&pending,
|
||||
auth_controller::TOTP_PENDING_TTL_SECS,
|
||||
)])?
|
||||
.redirect("/login/totp");
|
||||
}
|
||||
|
||||
let token = user
|
||||
.generate_jwt(&jwt_secret.secret, jwt_secret.expiration)
|
||||
.or_else(|_| unauthorized("unauthorized!"))?;
|
||||
@@ -94,6 +111,89 @@ async fn login(
|
||||
.redirect(home_for(&ctx, &user))
|
||||
}
|
||||
|
||||
/// Resolve the user behind a valid, unexpired `totp_pending` cookie. Returns
|
||||
/// `None` (never errors) when the cookie is missing, malformed, or expired —
|
||||
/// the caller bounces such requests back to `/login`.
|
||||
async fn user_from_pending(ctx: &AppContext, jar: &CookieJar) -> Option<users::Model> {
|
||||
let cookie = jar.get(auth_controller::TOTP_PENDING_COOKIE)?;
|
||||
let jwt_config = ctx.config.get_jwt_config().ok()?;
|
||||
let claims = loco_rs::auth::jwt::JWT::new(&jwt_config.secret)
|
||||
.validate(cookie.value())
|
||||
.ok()?;
|
||||
let user = users::Model::find_by_pid(&ctx.db, &claims.claims.pid).await.ok()?;
|
||||
// Defend against a stale pending cookie outliving a 2FA disable.
|
||||
user.totp_enabled().then_some(user)
|
||||
}
|
||||
|
||||
fn login_totp_view(v: &TeraView, jar: &CookieJar, error: Option<&str>) -> Result<Response> {
|
||||
format::view(
|
||||
v,
|
||||
"auth/login_totp.html",
|
||||
json!({
|
||||
"error": error,
|
||||
"logged_in_admin": false,
|
||||
"lang": current_lang(jar),
|
||||
}),
|
||||
)
|
||||
}
|
||||
|
||||
#[debug_handler]
|
||||
async fn login_totp_page(
|
||||
jar: CookieJar,
|
||||
ViewEngine(v): ViewEngine<TeraView>,
|
||||
State(ctx): State<AppContext>,
|
||||
) -> Result<Response> {
|
||||
if user_from_pending(&ctx, &jar).await.is_none() {
|
||||
return format::redirect("/login");
|
||||
}
|
||||
login_totp_view(&v, &jar, None)
|
||||
}
|
||||
|
||||
/// Second login factor. Accepts either a 6-digit authenticator code or one of
|
||||
/// the one-time backup codes (auto-detected by length). On success the pending
|
||||
/// cookie is cleared and the real `auth_token` is issued.
|
||||
#[derive(Debug, serde::Deserialize)]
|
||||
struct TotpLoginForm {
|
||||
code: String,
|
||||
}
|
||||
|
||||
#[debug_handler]
|
||||
async fn login_totp(
|
||||
jar: CookieJar,
|
||||
ViewEngine(v): ViewEngine<TeraView>,
|
||||
State(ctx): State<AppContext>,
|
||||
Form(form): Form<TotpLoginForm>,
|
||||
) -> Result<Response> {
|
||||
let Some(user) = user_from_pending(&ctx, &jar).await else {
|
||||
return format::redirect("/login");
|
||||
};
|
||||
|
||||
let code = form.code.trim();
|
||||
let via_totp = user.verify_totp_code(code);
|
||||
let via_backup = !via_totp && user.matches_backup_code(code);
|
||||
|
||||
if !via_totp && !via_backup {
|
||||
return login_totp_view(&v, &jar, Some("invalid"));
|
||||
}
|
||||
|
||||
// A used backup code must be burned so it can't be replayed.
|
||||
if via_backup {
|
||||
user.clone().into_active_model().consume_backup_code(&ctx.db, code).await?;
|
||||
}
|
||||
|
||||
let jwt_secret = ctx.config.get_jwt_config()?;
|
||||
let token = user
|
||||
.generate_jwt(&jwt_secret.secret, jwt_secret.expiration)
|
||||
.or_else(|_| unauthorized("unauthorized!"))?;
|
||||
|
||||
format::render()
|
||||
.cookies(&[
|
||||
auth_controller::auth_cookie(&token, jwt_secret.expiration),
|
||||
auth_controller::clear_totp_pending_cookie(),
|
||||
])?
|
||||
.redirect(home_for(&ctx, &user))
|
||||
}
|
||||
|
||||
#[debug_handler]
|
||||
async fn register_page(
|
||||
jar: CookieJar,
|
||||
@@ -366,6 +466,8 @@ pub fn routes() -> Routes {
|
||||
Routes::new()
|
||||
.add("/login", get(login_page))
|
||||
.add("/login", post(login))
|
||||
.add("/login/totp", get(login_totp_page))
|
||||
.add("/login/totp", post(login_totp))
|
||||
.add("/register", get(register_page))
|
||||
.add("/register", post(register))
|
||||
.add("/verify/{token}", get(verify))
|
||||
|
||||
@@ -253,10 +253,39 @@ async fn show(
|
||||
Ok((jar.add(cart_cookie(rebuilt)), response).into_response())
|
||||
}
|
||||
|
||||
/// Mini-cart preview for the navbar hover dropdown. Lazy-loaded via htmx from
|
||||
/// the header; returns just the `shop/_cart_preview.html` fragment.
|
||||
#[debug_handler]
|
||||
async fn preview(
|
||||
jar: CookieJar,
|
||||
ViewEngine(v): ViewEngine<TeraView>,
|
||||
State(ctx): State<AppContext>,
|
||||
) -> Result<Response> {
|
||||
let (lines, valid, total) = resolve_cart(&ctx, &jar).await?;
|
||||
let currency = lines
|
||||
.first()
|
||||
.and_then(|line| line["currency"].as_str())
|
||||
.unwrap_or("EUR")
|
||||
.to_string();
|
||||
let rebuilt = serialize_cart(&valid);
|
||||
let response = format::view(
|
||||
&v,
|
||||
"shop/_cart_preview.html",
|
||||
json!({
|
||||
"items": lines,
|
||||
"total": format_price(total),
|
||||
"currency": currency,
|
||||
"lang": current_lang(&jar),
|
||||
}),
|
||||
)?;
|
||||
Ok((jar.add(cart_cookie(rebuilt)), response).into_response())
|
||||
}
|
||||
|
||||
pub fn routes() -> Routes {
|
||||
Routes::new()
|
||||
.add("/cart", get(show))
|
||||
.add("/cart/add", post(add))
|
||||
.add("/cart/update", post(update))
|
||||
.add("/cart/remove", post(remove))
|
||||
.add("/partials/cart", get(preview))
|
||||
}
|
||||
|
||||
@@ -132,6 +132,10 @@ async fn checkout_page(
|
||||
"packeta_api_key": settings::get(&ctx, "packeta_api_key").unwrap_or(""),
|
||||
"logged_in_admin": is_admin,
|
||||
"logged_in_customer": is_customer,
|
||||
// Required by the navbar profile menu (base.html includes it whenever
|
||||
// logged_in_customer is true); None for admins/guests.
|
||||
"customer_name": user.as_ref().filter(|_| is_customer).map(|u| u.name.clone()),
|
||||
"customer_account_type": user.as_ref().filter(|_| is_customer).map(|u| u.account_type.clone()),
|
||||
"profile_filled": profile_filled,
|
||||
// A logged-in customer's account type is fixed; only guests pick it
|
||||
// and may opt to create an account from the order.
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
api_key: lo-95ec80d7-cb60-4b70-9b4b-9ef74cb88758
|
||||
name: user1
|
||||
theme: light
|
||||
account_type: personal
|
||||
created_at: "2023-11-12T12:34:56.789Z"
|
||||
updated_at: "2023-11-12T12:34:56.789Z"
|
||||
- id: 3
|
||||
@@ -15,5 +16,6 @@
|
||||
api_key: lo-153561ca-fa84-4e1b-813a-c62526d0a77e
|
||||
name: user2
|
||||
theme: light
|
||||
account_type: personal
|
||||
created_at: "2023-11-12T12:34:56.789Z"
|
||||
updated_at: "2023-11-12T12:34:56.789Z"
|
||||
|
||||
@@ -26,6 +26,9 @@ pub struct Model {
|
||||
pub magic_link_expiration: Option<DateTimeWithTimeZone>,
|
||||
pub theme: String,
|
||||
pub account_type: String,
|
||||
pub totp_secret: Option<String>,
|
||||
pub totp_enabled_at: Option<DateTimeWithTimeZone>,
|
||||
pub totp_backup_codes: Option<String>,
|
||||
}
|
||||
|
||||
#[derive(Copy, Clone, Debug, EnumIter, DeriveRelation)]
|
||||
|
||||
@@ -5,6 +5,7 @@ use loco_rs::{auth::jwt, hash, prelude::*};
|
||||
use passwords::PasswordGenerator;
|
||||
use serde::{Deserialize, Serialize};
|
||||
use serde_json::Map;
|
||||
use totp_rs::{Algorithm, Secret, TOTP};
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::models::_entities::o_auth2_sessions;
|
||||
@@ -16,6 +17,45 @@ pub const MAGIC_LINK_EXPIRATION_MIN: i8 = 5;
|
||||
/// Minimum gap between verification-email resends for one account, in seconds.
|
||||
pub const VERIFICATION_RESEND_COOLDOWN_SECS: i64 = 60;
|
||||
|
||||
// TODO(security): `users.totp_secret` is stored as a PLAINTEXT base32 string.
|
||||
// Unlike `password` (a one-way hash) the TOTP secret must be kept in reversible
|
||||
// form — the server needs the original value to recompute codes — so it is
|
||||
// effectively password-equivalent: anyone who can read this column can mint
|
||||
// valid 2FA codes for that user. It is deliberately left in plaintext for now
|
||||
// and treated like the app's other server-side secrets (e.g. the SMTP password,
|
||||
// kept out of the DB entirely). When secrets get a proper at-rest story, encrypt
|
||||
// this column with a key held OUTSIDE the database (env / `pass`), decrypting
|
||||
// only in memory. The single read/write site is `build_totp` +
|
||||
// `begin_totp_enrollment` below; `totp_backup_codes` are already hashed and need
|
||||
// no change. Grep `TODO(security)` to find this.
|
||||
|
||||
/// TOTP (Google Authenticator) parameters. These are the values Google
|
||||
/// Authenticator assumes; it ignores anything else encoded in the otpauth URL,
|
||||
/// so they must stay SHA1 / 6 digits / 30s or codes won't match.
|
||||
const TOTP_ISSUER: &str = "Kompress";
|
||||
const TOTP_DIGITS: usize = 6;
|
||||
/// Accept codes ±1 time-step (~30s) to tolerate client/server clock drift.
|
||||
const TOTP_SKEW: u8 = 1;
|
||||
const TOTP_STEP: u64 = 30;
|
||||
/// Number of one-time recovery codes generated when 2FA is enabled.
|
||||
pub const TOTP_BACKUP_CODE_COUNT: usize = 8;
|
||||
|
||||
/// Build a [`TOTP`] from a stored base32 secret and the account label (email).
|
||||
/// Returns `None` if the secret can't be decoded.
|
||||
fn build_totp(secret_base32: &str, account: &str) -> Option<TOTP> {
|
||||
let bytes = Secret::Encoded(secret_base32.to_string()).to_bytes().ok()?;
|
||||
TOTP::new(
|
||||
Algorithm::SHA1,
|
||||
TOTP_DIGITS,
|
||||
TOTP_SKEW,
|
||||
TOTP_STEP,
|
||||
bytes,
|
||||
Some(TOTP_ISSUER.to_string()),
|
||||
account.to_string(),
|
||||
)
|
||||
.ok()
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize, Serialize)]
|
||||
pub struct LoginParams {
|
||||
pub email: String,
|
||||
@@ -241,6 +281,68 @@ impl Model {
|
||||
self.account_type == "company"
|
||||
}
|
||||
|
||||
/// Whether two-factor auth is active for this account. This is the single
|
||||
/// source of truth used by the login flow: a secret may be present during a
|
||||
/// half-finished enrollment, but 2FA only gates login once it is *confirmed*
|
||||
/// (which is what sets `totp_enabled_at`).
|
||||
#[must_use]
|
||||
pub fn totp_enabled(&self) -> bool {
|
||||
self.totp_enabled_at.is_some()
|
||||
}
|
||||
|
||||
/// Build the [`TOTP`] for this user from its stored secret, if any.
|
||||
fn totp(&self) -> Option<TOTP> {
|
||||
let secret = self.totp_secret.as_deref()?;
|
||||
build_totp(secret, &self.email)
|
||||
}
|
||||
|
||||
/// A `data:image/png;base64,...` QR for the *pending* secret plus the secret
|
||||
/// itself (shown as a manual-entry fallback). Used on the enrollment page.
|
||||
/// Returns `None` if no secret is staged or QR rendering fails.
|
||||
#[must_use]
|
||||
pub fn totp_provisioning(&self) -> Option<(String, String)> {
|
||||
let totp = self.totp()?;
|
||||
let qr = totp.get_qr_base64().ok()?;
|
||||
Some((
|
||||
format!("data:image/png;base64,{qr}"),
|
||||
self.totp_secret.clone()?,
|
||||
))
|
||||
}
|
||||
|
||||
/// Verify a 6-digit authenticator code against the stored secret. Returns
|
||||
/// false if no secret is staged or the code is wrong. Works both during
|
||||
/// enrollment confirmation and at login.
|
||||
#[must_use]
|
||||
pub fn verify_totp_code(&self, code: &str) -> bool {
|
||||
let code = code.trim().replace(' ', "");
|
||||
self.totp()
|
||||
.and_then(|t| t.check_current(&code).ok())
|
||||
.unwrap_or(false)
|
||||
}
|
||||
|
||||
/// Whether `code` matches one of the still-unused backup codes.
|
||||
#[must_use]
|
||||
pub fn matches_backup_code(&self, code: &str) -> bool {
|
||||
let code = code.trim().replace([' ', '-'], "");
|
||||
self.backup_code_hashes()
|
||||
.iter()
|
||||
.any(|h| hash::verify_password(&code, h))
|
||||
}
|
||||
|
||||
/// The stored hashed backup codes (empty if none).
|
||||
fn backup_code_hashes(&self) -> Vec<String> {
|
||||
self.totp_backup_codes
|
||||
.as_deref()
|
||||
.and_then(|s| serde_json::from_str::<Vec<String>>(s).ok())
|
||||
.unwrap_or_default()
|
||||
}
|
||||
|
||||
/// How many unused backup codes remain.
|
||||
#[must_use]
|
||||
pub fn backup_codes_remaining(&self) -> usize {
|
||||
self.backup_code_hashes().len()
|
||||
}
|
||||
|
||||
/// Seconds the user must still wait before another verification email may be
|
||||
/// sent — 0 means a resend is allowed now. Throttling resends off the last
|
||||
/// `email_verification_sent_at` keeps the endpoint from being an easy way to
|
||||
@@ -446,6 +548,96 @@ impl ActiveModel {
|
||||
self.magic_link_expiration = ActiveValue::set(None);
|
||||
self.update(db).await.map_err(ModelError::from)
|
||||
}
|
||||
|
||||
/// Stage a fresh TOTP secret for enrollment. This does **not** turn 2FA on —
|
||||
/// `totp_enabled_at` stays null until the user proves they scanned it by
|
||||
/// confirming a code (see [`Self::enable_totp`]). Any previously staged
|
||||
/// secret/backup codes are discarded so re-enrolling always starts clean.
|
||||
pub async fn begin_totp_enrollment(mut self, db: &DatabaseConnection) -> ModelResult<Model> {
|
||||
let secret = match Secret::generate_secret().to_encoded() {
|
||||
Secret::Encoded(s) => s,
|
||||
// generate_secret() always yields raw bytes that encode cleanly.
|
||||
Secret::Raw(_) => unreachable!("to_encoded() returns Encoded"),
|
||||
};
|
||||
self.totp_secret = ActiveValue::set(Some(secret));
|
||||
self.totp_enabled_at = ActiveValue::set(None);
|
||||
self.totp_backup_codes = ActiveValue::set(None);
|
||||
self.update(db).await.map_err(ModelError::from)
|
||||
}
|
||||
|
||||
/// Confirm enrollment and switch 2FA on. The caller must have already
|
||||
/// verified a code against the staged secret. Generates and stores hashed
|
||||
/// one-time backup codes and returns the plaintext codes to display **once**.
|
||||
pub async fn enable_totp(
|
||||
mut self,
|
||||
db: &DatabaseConnection,
|
||||
) -> ModelResult<(Model, Vec<String>)> {
|
||||
let (plain, hashes) = generate_backup_codes()?;
|
||||
let encoded = serde_json::to_string(&hashes).map_err(|e| ModelError::Any(e.into()))?;
|
||||
self.totp_enabled_at = ActiveValue::set(Some(Local::now().into()));
|
||||
self.totp_backup_codes = ActiveValue::set(Some(encoded));
|
||||
let model = self.update(db).await.map_err(ModelError::from)?;
|
||||
Ok((model, plain))
|
||||
}
|
||||
|
||||
/// Turn 2FA off and wipe all TOTP state. Callers gate this behind a fresh
|
||||
/// confirmation (password or a current code).
|
||||
pub async fn disable_totp(mut self, db: &DatabaseConnection) -> ModelResult<Model> {
|
||||
self.totp_secret = ActiveValue::set(None);
|
||||
self.totp_enabled_at = ActiveValue::set(None);
|
||||
self.totp_backup_codes = ActiveValue::set(None);
|
||||
self.update(db).await.map_err(ModelError::from)
|
||||
}
|
||||
|
||||
/// Remove a used backup code from the stored set so it can't be reused.
|
||||
/// `code` is matched against the remaining hashes; a no-op if it doesn't
|
||||
/// match (the caller decides whether a match was required).
|
||||
pub async fn consume_backup_code(
|
||||
mut self,
|
||||
db: &DatabaseConnection,
|
||||
code: &str,
|
||||
) -> ModelResult<Model> {
|
||||
let code = code.trim().replace([' ', '-'], "");
|
||||
let current: Vec<String> = match self.totp_backup_codes.as_ref() {
|
||||
Some(s) => serde_json::from_str(s.as_str()).unwrap_or_default(),
|
||||
None => Vec::new(),
|
||||
};
|
||||
let remaining: Vec<String> = current
|
||||
.into_iter()
|
||||
.filter(|h| !hash::verify_password(&code, h))
|
||||
.collect();
|
||||
let encoded = serde_json::to_string(&remaining).map_err(|e| ModelError::Any(e.into()))?;
|
||||
self.totp_backup_codes = ActiveValue::set(Some(encoded));
|
||||
self.update(db).await.map_err(ModelError::from)
|
||||
}
|
||||
|
||||
/// Replace the backup codes with a fresh set (e.g. after the user used some).
|
||||
/// Only meaningful while 2FA is enabled; returns the new plaintext codes.
|
||||
pub async fn regenerate_backup_codes(
|
||||
mut self,
|
||||
db: &DatabaseConnection,
|
||||
) -> ModelResult<(Model, Vec<String>)> {
|
||||
let (plain, hashes) = generate_backup_codes()?;
|
||||
let encoded = serde_json::to_string(&hashes).map_err(|e| ModelError::Any(e.into()))?;
|
||||
self.totp_backup_codes = ActiveValue::set(Some(encoded));
|
||||
let model = self.update(db).await.map_err(ModelError::from)?;
|
||||
Ok((model, plain))
|
||||
}
|
||||
}
|
||||
|
||||
/// Generate `TOTP_BACKUP_CODE_COUNT` recovery codes, returning
|
||||
/// `(plaintext, hashes)`. Only the hashes are persisted; the plaintext is shown
|
||||
/// to the user once and never stored.
|
||||
fn generate_backup_codes() -> ModelResult<(Vec<String>, Vec<String>)> {
|
||||
let mut plain = Vec::with_capacity(TOTP_BACKUP_CODE_COUNT);
|
||||
let mut hashes = Vec::with_capacity(TOTP_BACKUP_CODE_COUNT);
|
||||
for _ in 0..TOTP_BACKUP_CODE_COUNT {
|
||||
let code = hash::random_string(10).to_lowercase();
|
||||
let hashed = hash::hash_password(&code).map_err(|e| ModelError::Any(e.into()))?;
|
||||
plain.push(code);
|
||||
hashes.push(hashed);
|
||||
}
|
||||
Ok((plain, hashes))
|
||||
}
|
||||
|
||||
/// Google OpenID Connect user profile (the fields our scopes request).
|
||||
|
||||
Reference in New Issue
Block a user