Files
nlcc-itinerary/server/api/auth/register.post.ts
Joshua Ryder 2ff493d804 feat: Implement comprehensive security hardening
Security Improvements:
- Auto-generate AUTH_SECRET and admin credentials on first launch
  - Cryptographically secure random generation
  - Stored in database for persistence
  - Logged once to container logs for admin retrieval

- Implement CSRF protection with double-submit cookie pattern
  - Three-way validation: cookie, header, and session database
  - Automatic client-side injection via plugin
  - Server middleware for automatic validation
  - Zero frontend code changes required

- Add session fixation prevention with automatic invalidation
  - Regenerate sessions on password changes
  - Keep current session active, invalidate others on profile password change
  - Invalidate ALL sessions on forgot-password reset
  - Invalidate ALL sessions on admin password reset

- Upgrade password reset codes to 8-char alphanumeric
  - Increased from 1M to 1.8 trillion combinations
  - Uses crypto.randomInt() for cryptographic randomness
  - Excluded confusing characters (I, O) for better UX
  - Case-insensitive verification

- Implement dual-layer account lockout
  - IP-based rate limiting (existing)
  - Per-account lockout: 10 attempts = 30 min lock
  - Automatic unlock after expiration
  - Admin manual unlock via UI
  - Visual status indicators in users table

Database Changes:
- Add csrf_token column to sessions table
- Add failed_login_attempts and locked_until columns to users table
- Add settings table for persistent AUTH_SECRET storage
- All migrations backward-compatible with try-catch

New Files:
- server/utils/csrf.ts - CSRF protection utilities
- server/middleware/csrf.ts - Automatic CSRF validation middleware
- plugins/csrf.client.ts - Automatic CSRF header injection
- server/api/users/unlock/[id].post.ts - Admin unlock endpoint

Modified Files:
- server/utils/database.ts - Core security functions and schema updates
- server/utils/email.ts - Enhanced reset code generation
- server/api/auth/login.post.ts - CSRF + account lockout logic
- server/api/auth/register.post.ts - CSRF token generation
- server/api/auth/logout.post.ts - CSRF cookie cleanup
- server/api/auth/reset-password.post.ts - Session invalidation
- server/api/auth/verify-reset-code.post.ts - Case-insensitive codes
- server/api/profile/update.put.ts - Session invalidation on password change
- server/api/users/password/[id].put.ts - Session invalidation on admin reset
- pages/users.vue - Lock status display and unlock functionality
- docker-compose.yml - Removed default credentials
- nuxt.config.ts - Support auto-generation

All changes follow OWASP best practices and are production-ready.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-05 17:36:31 -05:00

140 lines
4.0 KiB
TypeScript

import { createUser, getUserByUsername, getUserByEmail, checkRateLimit, createSession } from '~/server/utils/database'
import { setAuthCookie, generateSessionToken } from '~/server/utils/auth'
import { generateCsrfToken, setCsrfCookie } from '~/server/utils/csrf'
export default defineEventHandler(async (event) => {
// Get real client IP from proxy headers (prioritize x-real-ip for NPM)
const xRealIp = getHeader(event, 'x-real-ip')
const xForwardedFor = getHeader(event, 'x-forwarded-for')
const cfConnectingIp = getHeader(event, 'cf-connecting-ip')
// Use x-real-ip first (set by NPM), then x-forwarded-for, then cf-connecting-ip, then fallback
const clientIp = xRealIp ||
(xForwardedFor ? xForwardedFor.split(',')[0].trim() : null) ||
cfConnectingIp ||
getRequestIP(event) ||
'unknown'
// Log IP for verification
console.log(`[REGISTER ATTEMPT] IP: ${clientIp}, Headers:`, {
'x-forwarded-for': xForwardedFor,
'x-real-ip': xRealIp,
'cf-connecting-ip': cfConnectingIp,
'getRequestIP': getRequestIP(event)
})
// Check rate limit: 3 attempts per hour
if (!checkRateLimit(clientIp, 'register', 3, 60)) {
throw createError({
statusCode: 429,
message: 'Too many registration attempts. Please try again in 1 hour.'
})
}
const body = await readBody(event)
const { username, password, email, firstName, lastName } = body
if (!username || !password || !email || !firstName || !lastName) {
throw createError({
statusCode: 400,
message: 'All fields are required'
})
}
// Validate email format
const emailRegex = /^[^\s@]+@[^\s@]+\.[^\s@]+$/
if (!emailRegex.test(email)) {
throw createError({
statusCode: 400,
message: 'Invalid email format'
})
}
// Validate username format
if (username.length < 3) {
throw createError({
statusCode: 400,
message: 'Username must be at least 3 characters long'
})
}
// Validate password strength
if (password.length < 8) {
throw createError({
statusCode: 400,
message: 'Password must be at least 8 characters long'
})
}
if (!/[A-Z]/.test(password)) {
throw createError({
statusCode: 400,
message: 'Password must contain at least one uppercase letter'
})
}
if (!/[a-z]/.test(password)) {
throw createError({
statusCode: 400,
message: 'Password must contain at least one lowercase letter'
})
}
if (!/[0-9!@#$%^&*()_+\-=\[\]{};':"\\|,.<>\/?]/.test(password)) {
throw createError({
statusCode: 400,
message: 'Password must contain at least one number or symbol'
})
}
// Check if username already exists
const existingUser = getUserByUsername(username.toLowerCase())
if (existingUser) {
throw createError({
statusCode: 409,
message: 'Username already exists'
})
}
// Check if email already exists
const existingEmail = getUserByEmail(email.toLowerCase())
if (existingEmail) {
throw createError({
statusCode: 409,
message: 'Email already exists'
})
}
try {
// Create the new user with all fields
createUser(username.toLowerCase(), password, email.toLowerCase(), firstName, lastName)
// Generate session token and CSRF token for auto-login
const sessionToken = generateSessionToken()
const csrfToken = generateCsrfToken()
const expiresAt = new Date(Date.now() + 24 * 60 * 60 * 1000).toISOString() // 24 hours
// Create session with CSRF token
createSession(sessionToken, username.toLowerCase(), expiresAt, csrfToken)
// Set session cookie
setAuthCookie(event, sessionToken)
// Set CSRF cookie
setCsrfCookie(event, csrfToken)
// Log successful registration
console.log(`[REGISTER SUCCESS] User: ${username.toLowerCase()}, IP: ${clientIp}`)
return {
success: true,
username: username.toLowerCase()
}
} catch (error) {
throw createError({
statusCode: 500,
message: 'Failed to create user account'
})
}
})