Implement email change
This commit is contained in:
@@ -0,0 +1,133 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { prisma } from "../../../../../lib/server/db";
|
||||
import {
|
||||
getSessionPepper,
|
||||
isDatabaseConfigured,
|
||||
} from "../../../../../lib/server/env";
|
||||
import {
|
||||
hashSessionToken,
|
||||
newSessionToken,
|
||||
} from "../../../../../lib/server/hash";
|
||||
import { sendEmailChangeEmail } from "../../../../../lib/server/mail";
|
||||
import { rateLimitKey } from "../../../../../lib/server/rateLimit";
|
||||
import { apiRoute } from "../../../../../lib/server/apiRoute";
|
||||
import { logRouteError } from "../../../../../lib/server/requestId";
|
||||
import {
|
||||
dbUnavailable,
|
||||
errorJson,
|
||||
rateLimited,
|
||||
serverMisconfigured,
|
||||
unauthorized,
|
||||
} from "../../../../../lib/server/responses";
|
||||
import { getSessionUser } from "../../../../../lib/server/session";
|
||||
import { readLimitedJson } from "../../../../../lib/server/validation/requestBody";
|
||||
import { emailChangeRequestBodySchema } from "../../../../../lib/server/validation/userEmailChangeSchemas";
|
||||
import { jsonFromZodError } from "../../../../../lib/server/validation/zodHttp";
|
||||
|
||||
const EMAIL_CHANGE_TTL_MS = 15 * 60 * 1000;
|
||||
const EMAIL_MIN_INTERVAL_MS = 60 * 1000;
|
||||
const IP_MIN_INTERVAL_MS = 20 * 1000;
|
||||
const SCOPE = "user.emailChange.request";
|
||||
|
||||
export const POST = apiRoute(SCOPE, async (request: NextRequest, _ctx, { requestId }) => {
|
||||
if (!isDatabaseConfigured()) {
|
||||
return dbUnavailable();
|
||||
}
|
||||
|
||||
const user = await getSessionUser();
|
||||
if (!user) {
|
||||
return unauthorized();
|
||||
}
|
||||
|
||||
const limited = await readLimitedJson(request);
|
||||
if (limited.ok === false) {
|
||||
return limited.response;
|
||||
}
|
||||
|
||||
const parsed = emailChangeRequestBodySchema.safeParse(limited.value);
|
||||
if (!parsed.success) {
|
||||
return jsonFromZodError(parsed.error);
|
||||
}
|
||||
|
||||
const { newEmail } = parsed.data;
|
||||
if (newEmail === user.email) {
|
||||
return errorJson(
|
||||
"validation_error",
|
||||
"New email must be different from your current email",
|
||||
400,
|
||||
);
|
||||
}
|
||||
|
||||
const ip =
|
||||
request.headers.get("x-forwarded-for")?.split(",")[0]?.trim() ??
|
||||
request.headers.get("x-real-ip") ??
|
||||
"unknown";
|
||||
|
||||
const rlEmail = rateLimitKey(
|
||||
`email-change-email:${newEmail}`,
|
||||
EMAIL_MIN_INTERVAL_MS,
|
||||
);
|
||||
if (rlEmail.ok === false) {
|
||||
return rateLimited(rlEmail.retryAfterMs);
|
||||
}
|
||||
|
||||
const rlIp = rateLimitKey(`email-change-ip:${ip}`, IP_MIN_INTERVAL_MS);
|
||||
if (rlIp.ok === false) {
|
||||
return rateLimited(rlIp.retryAfterMs);
|
||||
}
|
||||
|
||||
const rlUser = rateLimitKey(
|
||||
`email-change-user:${user.id}`,
|
||||
EMAIL_MIN_INTERVAL_MS,
|
||||
);
|
||||
if (rlUser.ok === false) {
|
||||
return rateLimited(rlUser.retryAfterMs);
|
||||
}
|
||||
|
||||
const existing = await prisma.user.findUnique({ where: { email: newEmail } });
|
||||
if (existing && existing.id !== user.id) {
|
||||
return errorJson(
|
||||
"validation_error",
|
||||
"That email is already used by another account",
|
||||
400,
|
||||
{ details: { field: "newEmail" } },
|
||||
);
|
||||
}
|
||||
|
||||
let pepper: string;
|
||||
try {
|
||||
pepper = getSessionPepper();
|
||||
} catch {
|
||||
return serverMisconfigured();
|
||||
}
|
||||
|
||||
const token = newSessionToken();
|
||||
const tokenHash = hashSessionToken(token, pepper);
|
||||
const expiresAt = new Date(Date.now() + EMAIL_CHANGE_TTL_MS);
|
||||
|
||||
await prisma.emailChangeToken.deleteMany({ where: { userId: user.id } });
|
||||
await prisma.emailChangeToken.create({
|
||||
data: {
|
||||
userId: user.id,
|
||||
newEmail,
|
||||
tokenHash,
|
||||
expiresAt,
|
||||
},
|
||||
});
|
||||
|
||||
const origin = request.nextUrl.origin;
|
||||
const verifyUrl = `${origin}/api/user/email-change/verify?token=${encodeURIComponent(token)}`;
|
||||
|
||||
try {
|
||||
await sendEmailChangeEmail(newEmail, verifyUrl);
|
||||
} catch (err) {
|
||||
logRouteError(SCOPE, requestId, err, {
|
||||
phase: "sendEmailChangeEmail",
|
||||
newEmail,
|
||||
});
|
||||
await prisma.emailChangeToken.deleteMany({ where: { userId: user.id } });
|
||||
return errorJson("mail_failed", "Could not send email", 502);
|
||||
}
|
||||
|
||||
return NextResponse.json({ ok: true });
|
||||
});
|
||||
@@ -0,0 +1,172 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { prisma } from "../../../../../lib/server/db";
|
||||
import {
|
||||
getSessionPepper,
|
||||
isDatabaseConfigured,
|
||||
} from "../../../../../lib/server/env";
|
||||
import { hashSessionToken } from "../../../../../lib/server/hash";
|
||||
import {
|
||||
createSessionForUser,
|
||||
getValidatedSessionTokenHashForUser,
|
||||
setSessionCookie,
|
||||
} from "../../../../../lib/server/session";
|
||||
import { dbUnavailable } from "../../../../../lib/server/responses";
|
||||
import {
|
||||
REQUEST_ID_HEADER,
|
||||
getOrCreateRequestId,
|
||||
logRouteError,
|
||||
} from "../../../../../lib/server/requestId";
|
||||
|
||||
const SCOPE = "user.emailChange.verify";
|
||||
|
||||
export async function GET(request: NextRequest) {
|
||||
const requestId = getOrCreateRequestId(request);
|
||||
|
||||
if (!isDatabaseConfigured()) {
|
||||
const res = dbUnavailable();
|
||||
res.headers.set(REQUEST_ID_HEADER, requestId);
|
||||
return res;
|
||||
}
|
||||
|
||||
try {
|
||||
const token = request.nextUrl.searchParams.get("token");
|
||||
if (!token || token.length < 10) {
|
||||
return redirectWithRequestId(
|
||||
request,
|
||||
"/profile?error=email_change_invalid",
|
||||
requestId,
|
||||
);
|
||||
}
|
||||
|
||||
let pepper: string;
|
||||
try {
|
||||
pepper = getSessionPepper();
|
||||
} catch (err) {
|
||||
logRouteError(SCOPE, requestId, err, { phase: "getSessionPepper" });
|
||||
return redirectWithRequestId(
|
||||
request,
|
||||
"/profile?error=email_change_server",
|
||||
requestId,
|
||||
);
|
||||
}
|
||||
|
||||
const tokenHash = hashSessionToken(token, pepper);
|
||||
const row = await prisma.emailChangeToken.findUnique({
|
||||
where: { tokenHash },
|
||||
});
|
||||
|
||||
if (!row || row.expiresAt < new Date()) {
|
||||
return redirectWithRequestId(
|
||||
request,
|
||||
"/profile?error=email_change_expired",
|
||||
requestId,
|
||||
);
|
||||
}
|
||||
|
||||
const keepSessionTokenHash = await getValidatedSessionTokenHashForUser(
|
||||
row.userId,
|
||||
);
|
||||
|
||||
try {
|
||||
await prisma.$transaction(async (tx) => {
|
||||
const claim = await tx.emailChangeToken.findUnique({
|
||||
where: { id: row.id },
|
||||
});
|
||||
if (!claim || claim.expiresAt < new Date()) {
|
||||
throw Object.assign(new Error("expired"), { __expired: true });
|
||||
}
|
||||
|
||||
const taken = await tx.user.findFirst({
|
||||
where: {
|
||||
email: claim.newEmail,
|
||||
NOT: { id: claim.userId },
|
||||
},
|
||||
});
|
||||
if (taken) {
|
||||
await tx.emailChangeToken.delete({ where: { id: claim.id } });
|
||||
throw Object.assign(new Error("taken"), { __taken: true });
|
||||
}
|
||||
|
||||
await tx.user.update({
|
||||
where: { id: claim.userId },
|
||||
data: { email: claim.newEmail },
|
||||
});
|
||||
await tx.emailChangeToken.delete({ where: { id: claim.id } });
|
||||
|
||||
if (keepSessionTokenHash) {
|
||||
await tx.session.deleteMany({
|
||||
where: {
|
||||
userId: claim.userId,
|
||||
tokenHash: { not: keepSessionTokenHash },
|
||||
},
|
||||
});
|
||||
} else {
|
||||
await tx.session.deleteMany({
|
||||
where: { userId: claim.userId },
|
||||
});
|
||||
}
|
||||
});
|
||||
} catch (err: unknown) {
|
||||
if (
|
||||
err &&
|
||||
typeof err === "object" &&
|
||||
"__taken" in err &&
|
||||
(err as { __taken?: boolean }).__taken
|
||||
) {
|
||||
return redirectWithRequestId(
|
||||
request,
|
||||
"/profile?error=email_change_taken",
|
||||
requestId,
|
||||
);
|
||||
}
|
||||
if (
|
||||
err &&
|
||||
typeof err === "object" &&
|
||||
"__expired" in err &&
|
||||
(err as { __expired?: boolean }).__expired
|
||||
) {
|
||||
return redirectWithRequestId(
|
||||
request,
|
||||
"/profile?error=email_change_expired",
|
||||
requestId,
|
||||
);
|
||||
}
|
||||
logRouteError(SCOPE, requestId, err, { phase: "transaction" });
|
||||
return redirectWithRequestId(
|
||||
request,
|
||||
"/profile?error=email_change_server",
|
||||
requestId,
|
||||
);
|
||||
}
|
||||
|
||||
if (!keepSessionTokenHash) {
|
||||
const { token: sessionToken, expiresAt } = await createSessionForUser(
|
||||
row.userId,
|
||||
);
|
||||
await setSessionCookie(sessionToken, expiresAt);
|
||||
}
|
||||
|
||||
return redirectWithRequestId(
|
||||
request,
|
||||
"/profile?email_change=ok",
|
||||
requestId,
|
||||
);
|
||||
} catch (err) {
|
||||
logRouteError(SCOPE, requestId, err);
|
||||
return redirectWithRequestId(
|
||||
request,
|
||||
"/profile?error=email_change_server",
|
||||
requestId,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
function redirectWithRequestId(
|
||||
request: NextRequest,
|
||||
path: string,
|
||||
requestId: string,
|
||||
): NextResponse {
|
||||
const res = NextResponse.redirect(new URL(path, request.url));
|
||||
res.headers.set(REQUEST_ID_HEADER, requestId);
|
||||
return res;
|
||||
}
|
||||
Reference in New Issue
Block a user