Conversation
…sign-in hardening Pages: first launch is "Create your account"; sign-in adds Forgot password? and "Have an invite or reset code?". New passwords are checked as you type against the server's rules (shared package), with a Caps Lock warning. Accounts: Add user without a password sends a one-time invite code and the person chooses their own password; admins can resend an invite or send a reset code from a user's row. Forgot password issues a 30-minute single-use code by email, or, with no email configured, to the server log and via `foxschema reset-password`. Redeeming ends every other session. Admin -> Access control -> Sign-in configures Google, Microsoft and GitHub (with the redirect URL to register), the SMTP relay (Hostinger / Gmail / Microsoft 365 presets, test email) and the public URL. Env vars still win. The SMTP client moved to @foxschema/db/mail so the server can use it. Security: - SSO trusted unverified emails. Microsoft via `common` accepted any tenant's typed email (nOAuth account takeover); now only personal accounts, xms_edov-verified domains or the configured tenant. Google requires email_verified; GitHub uses only the verified primary address. PKCE added; state compared in constant time. - X-Forwarded-For was trusted from any peer, so rate limits could be skipped; now only loopback/private proxies (FOX_TRUST_PROXY). - Per-email lockout after 5 failures (also for emails with no account); unknown emails cost the same scrypt time. - Session tokens and codes stored as SHA-256 (migration 20 clears sessions). Reset links use the configured public URL only, never Host, and carry the code in the URL fragment. - Password policy: 10+ chars, not common, not the email name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_29121fd1-d5e2-44e8-b313-608b98f65b15) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
Pages
passwordProblemin@foxschema/shared).Accounts
foxschema reset-password [email]. Redeeming ends every other session. The reply is identical whether or not the account exists, and the code is sent after the response, so timing doesn't reveal it either.Admin → Access control → Sign-in (new tab)
Secrets are write-only and encrypted with the install key. Env vars (
SSO_*,SMTP_*,APP_PUBLIC_URL) still win and show read-only. The SMTP client moved from workflow-engine to@foxschema/db/mail, with a re-export at its old path, so the server can send without depending on the engine.Security fixes found along the way
common, theemailclaim is whatever any tenant's admin typedxms_edov-verified domains, or the configured single tenantemail_verified; GitHub could use an unverified public email!==trustProxy: truelet any client setX-Forwarded-Forand skip every per-address limitFOX_TRUST_PROXYto override)Hostheader would let a requester choose where a link pointsPassword policy for new passwords: 10+ characters, not a common password, and not containing the email name. Existing passwords keep working.
Verification
apps/web/ cli / e2e tsc clean.lintandlint:securityclean.buildpasses.npx vitest run: 432 files, 5119 passed.auth.recovery.test.ts: reset, invite, lockout, hashes-only storage.sso.service.test.ts: per-provider email trust and PKCE. A mutation check confirmed the Microsoft and Google guards are each caught.sign-in-settings.service.test.ts.recovery.routes.test.ts, on a real listener: identical forgot replies, 429 + Retry-After, invite once-only, 403 for viewers, secrets never returned.password-policy.test.ts.AuthPage(sign-up rules, forgot, emailed invite link, wrong code),AdminAccessPanel(invite, resend),SignInSettingsPanel.auth-recovery.test.ts, in a real browser: invite link → sign up → forgot password → reset code → old password refused → sign in with the new one. 4/4.🤖 Generated with Claude Code
Note
High Risk
Touches authentication, session storage, SSO/email configuration, and proxy trust; upgrading invalidates all sessions and changes sign-in abuse controls.
Overview
Adds end-to-end account recovery and invites without open registration: admins can invite users (empty starting password → one-time code), users get forgot password and redeem invite/reset code flows in the UI, and
foxschema reset-password [email]prints a reset code when SMTP is not configured.Backend grows one-time
auth_codes(hashed), public/api/auth/password/*routes, adminPOST /api/admin/users/:id/code, and/api/admin/sign-infor public URL, OAuth providers, and SMTP. Codes and session cookies are stored hashed (migration 20 clears old sessions). Per-email lockout after failed sign-ins, stricter new password rules (10+ chars via@foxschema/shared), andFOX_TRUST_PROXYdefaults so rate limits are not bypassed viaX-Forwarded-For. Email delivery uses a new@foxschema/db/mailSMTP client.Admin UI adds Sign-in settings (SSO redirect URLs, mail presets, test email), IssuedCodeNotice when codes are logged instead of emailed, and Invited / resend-invite / send-reset on user rows. E2e adds
auth-recovery.test.tsand optional unsigned Playwright sessions for sign-in pages.Reviewed by Cursor Bugbot for commit 002a0c7. Bugbot is set up for automated code reviews on this repo. Configure here.