Feature: Settings-Tabs, Login-Redesign und Security-Tests
Some checks are pending
CI / Lint, Typecheck, Test, Build (push) Waiting to run
Some checks are pending
CI / Lint, Typecheck, Test, Build (push) Waiting to run
- Einstellungen-Seite in fokussierte Komponenten aufgeteilt (settings-tabs, status-banner, section-card) - Login-Seite ueberarbeitet - Neue security.test.ts fuer 2FA-Verlust-/Recovery-Logik - health.test.ts erweitert - next-env.d.ts auf Next.js dev-types-Pfad aktualisiert Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
8ed7c083c4
commit
e42a8109bf
8 changed files with 1165 additions and 556 deletions
|
|
@ -0,0 +1,24 @@
|
||||||
|
import type { ReactNode } from "react";
|
||||||
|
|
||||||
|
export function SectionCard({
|
||||||
|
title,
|
||||||
|
description,
|
||||||
|
children,
|
||||||
|
footer,
|
||||||
|
}: {
|
||||||
|
title: string;
|
||||||
|
description?: string;
|
||||||
|
children: ReactNode;
|
||||||
|
footer?: ReactNode;
|
||||||
|
}) {
|
||||||
|
return (
|
||||||
|
<section className="rounded-2xl bg-white shadow-sm ring-1 ring-gray-100">
|
||||||
|
<header className="border-b border-gray-100 px-6 py-5">
|
||||||
|
<h2 className="text-lg font-semibold text-gray-900">{title}</h2>
|
||||||
|
{description ? <p className="mt-1 text-sm text-gray-500">{description}</p> : null}
|
||||||
|
</header>
|
||||||
|
<div className="space-y-5 px-6 py-6">{children}</div>
|
||||||
|
{footer ? <div className="border-t border-gray-100 px-6 py-4">{footer}</div> : null}
|
||||||
|
</section>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
@ -0,0 +1,83 @@
|
||||||
|
"use client";
|
||||||
|
|
||||||
|
import { useRouter, useSearchParams } from "next/navigation";
|
||||||
|
import { useCallback } from "react";
|
||||||
|
|
||||||
|
export type SettingsTabId =
|
||||||
|
| "profil"
|
||||||
|
| "ernaehrung"
|
||||||
|
| "ziele"
|
||||||
|
| "sicherheit"
|
||||||
|
| "anwendung";
|
||||||
|
|
||||||
|
const tabs: { id: SettingsTabId; label: string; description: string }[] = [
|
||||||
|
{ id: "profil", label: "Profil", description: "Persoenliche Daten und Kontakt" },
|
||||||
|
{ id: "ernaehrung", label: "Ernaehrung", description: "Rezept- und Mahlzeiten-Praeferenzen" },
|
||||||
|
{ id: "ziele", label: "Ziele", description: "Kalorien, Makros, Gewicht, Fasten" },
|
||||||
|
{ id: "sicherheit", label: "Sicherheit", description: "2FA, Passkeys, Passwort" },
|
||||||
|
{ id: "anwendung", label: "Anwendung", description: "Erscheinungsbild und Erinnerungen" },
|
||||||
|
];
|
||||||
|
|
||||||
|
export function useSettingsTab(): {
|
||||||
|
active: SettingsTabId;
|
||||||
|
setActive: (id: SettingsTabId) => void;
|
||||||
|
} {
|
||||||
|
const router = useRouter();
|
||||||
|
const search = useSearchParams();
|
||||||
|
const tabParam = search.get("tab");
|
||||||
|
const active: SettingsTabId =
|
||||||
|
tabs.find((tab) => tab.id === tabParam)?.id ?? "profil";
|
||||||
|
|
||||||
|
const setActive = useCallback(
|
||||||
|
(id: SettingsTabId) => {
|
||||||
|
const params = new URLSearchParams(search.toString());
|
||||||
|
params.set("tab", id);
|
||||||
|
router.replace(`/einstellungen?${params.toString()}`, { scroll: false });
|
||||||
|
},
|
||||||
|
[router, search],
|
||||||
|
);
|
||||||
|
|
||||||
|
return { active, setActive };
|
||||||
|
}
|
||||||
|
|
||||||
|
export function SettingsTabs({
|
||||||
|
active,
|
||||||
|
onChange,
|
||||||
|
}: {
|
||||||
|
active: SettingsTabId;
|
||||||
|
onChange: (id: SettingsTabId) => void;
|
||||||
|
}) {
|
||||||
|
const activeMeta = tabs.find((tab) => tab.id === active);
|
||||||
|
return (
|
||||||
|
<div className="space-y-3">
|
||||||
|
<div
|
||||||
|
role="tablist"
|
||||||
|
aria-label="Einstellungs-Kategorien"
|
||||||
|
className="-mx-1 flex gap-2 overflow-x-auto px-1 pb-1"
|
||||||
|
>
|
||||||
|
{tabs.map((tab) => {
|
||||||
|
const isActive = tab.id === active;
|
||||||
|
return (
|
||||||
|
<button
|
||||||
|
key={tab.id}
|
||||||
|
type="button"
|
||||||
|
role="tab"
|
||||||
|
aria-selected={isActive}
|
||||||
|
onClick={() => onChange(tab.id)}
|
||||||
|
className={`shrink-0 rounded-full px-4 py-2 text-sm font-semibold transition-colors ${
|
||||||
|
isActive
|
||||||
|
? "bg-[#0F766E] text-white shadow-sm"
|
||||||
|
: "bg-white text-gray-600 ring-1 ring-gray-200 hover:bg-gray-50"
|
||||||
|
}`}
|
||||||
|
>
|
||||||
|
{tab.label}
|
||||||
|
</button>
|
||||||
|
);
|
||||||
|
})}
|
||||||
|
</div>
|
||||||
|
{activeMeta?.description ? (
|
||||||
|
<p className="px-1 text-sm text-gray-500">{activeMeta.description}</p>
|
||||||
|
) : null}
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
"use client";
|
||||||
|
|
||||||
|
export function StatusBanner({
|
||||||
|
status,
|
||||||
|
error,
|
||||||
|
}: {
|
||||||
|
status: string | null;
|
||||||
|
error: string | null;
|
||||||
|
}) {
|
||||||
|
if (!status && !error) return null;
|
||||||
|
if (error) {
|
||||||
|
return (
|
||||||
|
<div
|
||||||
|
role="alert"
|
||||||
|
className="rounded-xl border border-red-200 bg-red-50 px-4 py-3 text-sm text-red-700"
|
||||||
|
>
|
||||||
|
{error}
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return (
|
||||||
|
<div
|
||||||
|
role="status"
|
||||||
|
className="rounded-xl border border-emerald-200 bg-emerald-50 px-4 py-3 text-sm text-emerald-700"
|
||||||
|
>
|
||||||
|
{status}
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
File diff suppressed because it is too large
Load diff
|
|
@ -194,79 +194,130 @@ export default function LoginPage() {
|
||||||
}
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="min-h-screen flex items-center justify-center bg-[#F9F9F9]">
|
<div className="relative min-h-screen overflow-hidden bg-gradient-to-br from-[#F5F9F8] via-[#F9FAFB] to-[#ECFDF5]">
|
||||||
|
<div
|
||||||
|
aria-hidden="true"
|
||||||
|
className="pointer-events-none absolute -top-32 -left-32 h-96 w-96 rounded-full bg-[#0F766E]/15 blur-3xl"
|
||||||
|
/>
|
||||||
|
<div
|
||||||
|
aria-hidden="true"
|
||||||
|
className="pointer-events-none absolute -bottom-40 -right-32 h-[28rem] w-[28rem] rounded-full bg-emerald-200/40 blur-3xl"
|
||||||
|
/>
|
||||||
|
|
||||||
|
<div className="relative flex min-h-screen items-center justify-center px-4 py-12 sm:px-6">
|
||||||
{!otpStepChecked ? (
|
{!otpStepChecked ? (
|
||||||
<div className="w-8 h-8 rounded-full border-2 border-[#0F766E] border-t-transparent animate-spin" />
|
<div className="h-10 w-10 animate-spin rounded-full border-2 border-[#0F766E] border-t-transparent" />
|
||||||
) : (
|
) : (
|
||||||
<div className="w-full max-w-sm">
|
<div className="w-full max-w-sm">
|
||||||
<div className="flex flex-col items-center mb-8">
|
<div className="mb-8 flex flex-col items-center text-center">
|
||||||
<div className="mb-4 flex h-14 w-14 items-center justify-center rounded-xl bg-[#0F766E] text-lg font-bold text-white shadow-sm">
|
<div className="mb-5 flex h-16 w-16 items-center justify-center rounded-2xl bg-gradient-to-br from-[#0F766E] to-[#0d9488] text-xl font-bold text-white shadow-lg shadow-[#0F766E]/25 ring-1 ring-white/40">
|
||||||
HH
|
HH
|
||||||
</div>
|
</div>
|
||||||
<h1 className="text-xl font-bold text-[#333333]">Hellth Hub</h1>
|
<h1 className="text-2xl font-bold tracking-tight text-gray-900">Hellth Hub</h1>
|
||||||
<p className="mt-2 text-sm text-gray-500">Health-Tracking für dein Home-Lab</p>
|
<p className="mt-1.5 text-sm text-gray-500">
|
||||||
|
Health-Tracking fuer dein Home-Lab
|
||||||
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<form
|
<div className="rounded-2xl border border-gray-100 bg-white/90 p-6 shadow-xl shadow-gray-900/5 backdrop-blur sm:p-7">
|
||||||
onSubmit={handleSubmit}
|
<form onSubmit={handleSubmit} className="space-y-4">
|
||||||
className="bg-white rounded-xl shadow-sm border border-gray-100 p-6 space-y-4"
|
|
||||||
>
|
|
||||||
{error && (
|
{error && (
|
||||||
<div className="flex items-center gap-2 text-sm text-red-600 bg-[#ECFDF5] border border-red-100 px-3 py-2.5 rounded-lg">
|
<div
|
||||||
<span className="w-4 h-4 text-[#0F766E] shrink-0">!</span>
|
role="alert"
|
||||||
{error}
|
className="flex items-start gap-2 rounded-lg border border-red-100 bg-red-50 px-3 py-2.5 text-sm text-red-700"
|
||||||
|
>
|
||||||
|
<span aria-hidden="true" className="mt-0.5 font-bold text-red-500">
|
||||||
|
!
|
||||||
|
</span>
|
||||||
|
<span>{error}</span>
|
||||||
</div>
|
</div>
|
||||||
)}
|
)}
|
||||||
|
|
||||||
<div>
|
<div>
|
||||||
<label className="block text-sm font-medium text-[#333333] mb-1.5">
|
<label htmlFor="login-email" className="mb-1.5 block text-sm font-medium text-gray-700">
|
||||||
E-Mail
|
E-Mail
|
||||||
</label>
|
</label>
|
||||||
<input
|
<input
|
||||||
|
id="login-email"
|
||||||
type="email"
|
type="email"
|
||||||
required
|
required
|
||||||
autoComplete="username webauthn"
|
autoComplete="username webauthn"
|
||||||
value={email}
|
value={email}
|
||||||
onChange={(e) => setEmail(e.target.value)}
|
onChange={(e) => setEmail(e.target.value)}
|
||||||
placeholder="admin@example.com"
|
placeholder="du@example.com"
|
||||||
className="w-full px-3 py-2.5 border border-gray-200 rounded-lg text-sm text-[#333333] placeholder-gray-300 focus:outline-none focus:ring-2 focus:ring-[#0F766E] focus:border-transparent transition-shadow"
|
className="w-full rounded-lg border border-gray-200 bg-white px-3.5 py-2.5 text-sm text-gray-900 placeholder-gray-400 transition-shadow focus:border-[#0F766E] focus:outline-none focus:ring-2 focus:ring-[#0F766E]/20"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div>
|
<div>
|
||||||
<label className="block text-sm font-medium text-[#333333] mb-1.5">
|
<label htmlFor="login-password" className="mb-1.5 block text-sm font-medium text-gray-700">
|
||||||
Passwort
|
Passwort
|
||||||
</label>
|
</label>
|
||||||
<input
|
<input
|
||||||
|
id="login-password"
|
||||||
type="password"
|
type="password"
|
||||||
required
|
required
|
||||||
autoComplete="current-password"
|
autoComplete="current-password"
|
||||||
value={password}
|
value={password}
|
||||||
onChange={(e) => setPassword(e.target.value)}
|
onChange={(e) => setPassword(e.target.value)}
|
||||||
placeholder="************"
|
placeholder="••••••••••••"
|
||||||
className="w-full px-3 py-2.5 border border-gray-200 rounded-lg text-sm text-[#333333] placeholder-gray-300 focus:outline-none focus:ring-2 focus:ring-[#0F766E] focus:border-transparent transition-shadow"
|
className="w-full rounded-lg border border-gray-200 bg-white px-3.5 py-2.5 text-sm text-gray-900 placeholder-gray-400 transition-shadow focus:border-[#0F766E] focus:outline-none focus:ring-2 focus:ring-[#0F766E]/20"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<button
|
<button
|
||||||
type="submit"
|
type="submit"
|
||||||
disabled={loading}
|
disabled={loading}
|
||||||
className="w-full py-2.5 bg-[#0F766E] text-white text-sm font-semibold rounded-lg hover:bg-[#115E59] transition-colors disabled:opacity-50 disabled:cursor-not-allowed mt-2"
|
className="mt-1 inline-flex w-full items-center justify-center gap-2 rounded-lg bg-[#0F766E] py-2.5 text-sm font-semibold text-white shadow-sm transition-colors hover:bg-[#115E59] disabled:cursor-not-allowed disabled:opacity-50"
|
||||||
>
|
>
|
||||||
|
{loading ? (
|
||||||
|
<span className="inline-block h-4 w-4 animate-spin rounded-full border-2 border-white/40 border-t-white" />
|
||||||
|
) : null}
|
||||||
{loading ? "Anmelden..." : "Anmelden"}
|
{loading ? "Anmelden..." : "Anmelden"}
|
||||||
</button>
|
</button>
|
||||||
|
|
||||||
|
<div className="relative pt-1">
|
||||||
|
<div aria-hidden="true" className="absolute inset-0 flex items-center">
|
||||||
|
<div className="w-full border-t border-gray-200" />
|
||||||
|
</div>
|
||||||
|
<div className="relative flex justify-center">
|
||||||
|
<span className="bg-white px-3 text-xs uppercase tracking-wider text-gray-400">
|
||||||
|
oder
|
||||||
|
</span>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
<button
|
<button
|
||||||
type="button"
|
type="button"
|
||||||
onClick={handlePasskeyLogin}
|
onClick={handlePasskeyLogin}
|
||||||
disabled={loading}
|
disabled={loading}
|
||||||
className="w-full py-2.5 bg-white text-[#333333] text-sm font-semibold rounded-lg border border-gray-200 hover:bg-gray-50 transition-colors disabled:opacity-50 disabled:cursor-not-allowed"
|
className="inline-flex w-full items-center justify-center gap-2 rounded-lg border border-gray-200 bg-white py-2.5 text-sm font-semibold text-gray-800 transition-colors hover:bg-gray-50 disabled:cursor-not-allowed disabled:opacity-50"
|
||||||
>
|
>
|
||||||
|
<svg
|
||||||
|
aria-hidden="true"
|
||||||
|
viewBox="0 0 24 24"
|
||||||
|
fill="none"
|
||||||
|
stroke="currentColor"
|
||||||
|
strokeWidth="1.8"
|
||||||
|
className="h-4 w-4 text-[#0F766E]"
|
||||||
|
>
|
||||||
|
<path
|
||||||
|
strokeLinecap="round"
|
||||||
|
strokeLinejoin="round"
|
||||||
|
d="M15.75 5.25a3 3 0 11-6 0 3 3 0 016 0zM4.5 19.5l4.5-7.5h6l4.5 7.5"
|
||||||
|
/>
|
||||||
|
</svg>
|
||||||
Mit Passkey anmelden
|
Mit Passkey anmelden
|
||||||
</button>
|
</button>
|
||||||
</form>
|
</form>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<p className="mt-6 text-center text-xs text-gray-400">
|
||||||
|
Geschuetzt durch 2FA, Passkeys und verschluesselte Verbindungen.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
)}
|
)}
|
||||||
</div>
|
</div>
|
||||||
|
</div>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
|
||||||
2
apps/admin/next-env.d.ts
vendored
2
apps/admin/next-env.d.ts
vendored
|
|
@ -1,6 +1,6 @@
|
||||||
/// <reference types="next" />
|
/// <reference types="next" />
|
||||||
/// <reference types="next/image-types/global" />
|
/// <reference types="next/image-types/global" />
|
||||||
import "./.next/types/routes.d.ts";
|
import "./.next/dev/types/routes.d.ts";
|
||||||
|
|
||||||
// NOTE: This file should not be edited
|
// NOTE: This file should not be edited
|
||||||
// see https://nextjs.org/docs/app/api-reference/config/typescript for more information.
|
// see https://nextjs.org/docs/app/api-reference/config/typescript for more information.
|
||||||
|
|
|
||||||
|
|
@ -589,3 +589,85 @@ test("health.statsSummary uses database logs for weekly and projection data", as
|
||||||
assert.equal(summary.projection?.trendKgPerWeek, -1.1);
|
assert.equal(summary.projection?.trendKgPerWeek, -1.1);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("health.upsertWeeklyCaloriePlan speichert Tageskalorien pro Nutzer und Datum", async () => {
|
||||||
|
const { db, calls } = createHealthDbMock();
|
||||||
|
const caller = appRouter.createCaller(createContext({ db }) as never);
|
||||||
|
|
||||||
|
const result = await caller.health.upsertWeeklyCaloriePlan({
|
||||||
|
date: "2026-05-30",
|
||||||
|
plannedCalories: 1800,
|
||||||
|
note: "Refeed-Tag",
|
||||||
|
});
|
||||||
|
|
||||||
|
assert.deepEqual(result, { ok: true });
|
||||||
|
const values = calls.find((call) => call.op === "insert.values")?.payload as {
|
||||||
|
userId?: string;
|
||||||
|
date?: string;
|
||||||
|
plannedCalories?: number;
|
||||||
|
note?: string | null;
|
||||||
|
};
|
||||||
|
assert.equal(values.userId, "user-health");
|
||||||
|
assert.equal(values.date, "2026-05-30");
|
||||||
|
assert.equal(values.plannedCalories, 1800);
|
||||||
|
assert.equal(values.note, "Refeed-Tag");
|
||||||
|
|
||||||
|
const conflict = calls.find((call) => call.op === "insert.values.result.onConflictDoUpdate")?.payload as {
|
||||||
|
set?: { plannedCalories?: number; note?: string | null };
|
||||||
|
};
|
||||||
|
assert.equal(conflict.set?.plannedCalories, 1800);
|
||||||
|
assert.equal(conflict.set?.note, "Refeed-Tag");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("health.upsertWeeklyCaloriePlan lehnt unrealistische Kalorienwerte ab", async () => {
|
||||||
|
const caller = appRouter.createCaller(createContext() as never);
|
||||||
|
|
||||||
|
await assert.rejects(
|
||||||
|
() => caller.health.upsertWeeklyCaloriePlan({ date: "2026-05-30", plannedCalories: 500 }),
|
||||||
|
(error: unknown) => {
|
||||||
|
assert.equal((error as { code?: string }).code, "BAD_REQUEST");
|
||||||
|
return true;
|
||||||
|
},
|
||||||
|
);
|
||||||
|
await assert.rejects(
|
||||||
|
() => caller.health.upsertWeeklyCaloriePlan({ date: "2026-05-30", plannedCalories: 9000 }),
|
||||||
|
(error: unknown) => {
|
||||||
|
assert.equal((error as { code?: string }).code, "BAD_REQUEST");
|
||||||
|
return true;
|
||||||
|
},
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("health.addActivityLog schreibt Hellfireclub-Punkte mit Quelle und Idempotenz", async () => {
|
||||||
|
const { db, calls } = createHealthDbMock();
|
||||||
|
const caller = appRouter.createCaller(createContext({ db }) as never);
|
||||||
|
|
||||||
|
await caller.health.addActivityLog({
|
||||||
|
date: "2026-05-26",
|
||||||
|
name: "30 Minuten Joggen",
|
||||||
|
minutes: 30,
|
||||||
|
points: 45,
|
||||||
|
calories: 280,
|
||||||
|
source: "fitbit",
|
||||||
|
externalId: "fitbit-activity-99",
|
||||||
|
});
|
||||||
|
|
||||||
|
const values = calls.find((call) => call.op === "insert.values")?.payload as {
|
||||||
|
userId?: string;
|
||||||
|
name?: string;
|
||||||
|
points?: number;
|
||||||
|
calories?: number;
|
||||||
|
source?: string;
|
||||||
|
externalId?: string | null;
|
||||||
|
};
|
||||||
|
assert.equal(values.userId, "user-health");
|
||||||
|
assert.equal(values.name, "30 Minuten Joggen");
|
||||||
|
assert.equal(values.points, 45);
|
||||||
|
assert.equal(values.calories, 280);
|
||||||
|
assert.equal(values.source, "fitbit");
|
||||||
|
assert.equal(values.externalId, "fitbit-activity-99");
|
||||||
|
assert.ok(
|
||||||
|
calls.some((call) => call.op === "insert.values.result.onConflictDoNothing"),
|
||||||
|
"Wiederholtes Importieren der gleichen externalId darf nicht doppelt zaehlen",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
|
|
||||||
229
packages/api/src/trpc/security.test.ts
Normal file
229
packages/api/src/trpc/security.test.ts
Normal file
|
|
@ -0,0 +1,229 @@
|
||||||
|
import assert from "node:assert/strict";
|
||||||
|
import test from "node:test";
|
||||||
|
import { appRouter } from "./index";
|
||||||
|
import { twoFactorLossReasons } from "../lib/security-audit";
|
||||||
|
|
||||||
|
type Call = { op: string; payload?: unknown };
|
||||||
|
|
||||||
|
type DbUserRow = {
|
||||||
|
email?: string;
|
||||||
|
role?: string;
|
||||||
|
twoFactorEnabled?: boolean | null;
|
||||||
|
twoFactorRecoveryRequired?: boolean | null;
|
||||||
|
} | null;
|
||||||
|
|
||||||
|
type TwoFactorRow = { enabled?: boolean | null } | null;
|
||||||
|
|
||||||
|
function chain(calls: Call[], op: string, payload?: unknown): any {
|
||||||
|
calls.push({ op, payload });
|
||||||
|
return {
|
||||||
|
set(value: unknown) {
|
||||||
|
calls.push({ op: `${op}.set`, payload: value });
|
||||||
|
return chain(calls, `${op}.set.result`);
|
||||||
|
},
|
||||||
|
where(value?: unknown) {
|
||||||
|
calls.push({ op: `${op}.where`, payload: value });
|
||||||
|
return Promise.resolve([]);
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function createSecurityDbMock(options: { dbUser?: DbUserRow; twoFactorRow?: TwoFactorRow } = {}) {
|
||||||
|
const calls: Call[] = [];
|
||||||
|
const db = {
|
||||||
|
query: {
|
||||||
|
user: { findFirst: async () => options.dbUser ?? null },
|
||||||
|
twoFactor: { findFirst: async () => options.twoFactorRow ?? null },
|
||||||
|
},
|
||||||
|
update(table: unknown) {
|
||||||
|
return chain(calls, "update", table);
|
||||||
|
},
|
||||||
|
};
|
||||||
|
return { db, calls };
|
||||||
|
}
|
||||||
|
|
||||||
|
function createContext(overrides: Record<string, unknown> = {}) {
|
||||||
|
const user = { id: "user-1", email: "user@example.org", role: "user" };
|
||||||
|
return {
|
||||||
|
db: {},
|
||||||
|
headers: new Headers(),
|
||||||
|
session: { user },
|
||||||
|
user,
|
||||||
|
userRole: "user",
|
||||||
|
isPlatformAdmin: false,
|
||||||
|
...overrides,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function createUnauthedContext() {
|
||||||
|
return {
|
||||||
|
db: {},
|
||||||
|
headers: new Headers(),
|
||||||
|
session: null,
|
||||||
|
user: null,
|
||||||
|
userRole: "user",
|
||||||
|
isPlatformAdmin: false,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
test("twoFactorLossReasons meldet nur Probleme fuer privilegierte Accounts", () => {
|
||||||
|
assert.deepEqual(
|
||||||
|
twoFactorLossReasons({
|
||||||
|
isPrivileged: false,
|
||||||
|
userTwoFactorEnabled: false,
|
||||||
|
twoFactorRowExists: false,
|
||||||
|
twoFactorRowEnabled: false,
|
||||||
|
recoveryRequired: true,
|
||||||
|
}),
|
||||||
|
[],
|
||||||
|
"Normale Nutzer sind nicht zu 2FA verpflichtet",
|
||||||
|
);
|
||||||
|
|
||||||
|
const reasons = twoFactorLossReasons({
|
||||||
|
isPrivileged: true,
|
||||||
|
userTwoFactorEnabled: false,
|
||||||
|
twoFactorRowExists: false,
|
||||||
|
twoFactorRowEnabled: false,
|
||||||
|
recoveryRequired: true,
|
||||||
|
});
|
||||||
|
assert.ok(reasons.includes("user.twoFactorEnabled=false"));
|
||||||
|
assert.ok(reasons.includes("twoFactor row missing"));
|
||||||
|
assert.ok(reasons.includes("twoFactorRecoveryRequired=true"));
|
||||||
|
|
||||||
|
assert.deepEqual(
|
||||||
|
twoFactorLossReasons({
|
||||||
|
isPrivileged: true,
|
||||||
|
userTwoFactorEnabled: true,
|
||||||
|
twoFactorRowExists: true,
|
||||||
|
twoFactorRowEnabled: true,
|
||||||
|
recoveryRequired: false,
|
||||||
|
}),
|
||||||
|
[],
|
||||||
|
"Sauberer Admin-Account hat keine Recovery-Reasons",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("twoFactorLossReasons unterscheidet fehlende Row von deaktivierter Row", () => {
|
||||||
|
const missing = twoFactorLossReasons({
|
||||||
|
isPrivileged: true,
|
||||||
|
userTwoFactorEnabled: true,
|
||||||
|
twoFactorRowExists: false,
|
||||||
|
twoFactorRowEnabled: false,
|
||||||
|
recoveryRequired: false,
|
||||||
|
});
|
||||||
|
assert.deepEqual(missing, ["twoFactor row missing"]);
|
||||||
|
|
||||||
|
const disabled = twoFactorLossReasons({
|
||||||
|
isPrivileged: true,
|
||||||
|
userTwoFactorEnabled: true,
|
||||||
|
twoFactorRowExists: true,
|
||||||
|
twoFactorRowEnabled: false,
|
||||||
|
recoveryRequired: false,
|
||||||
|
});
|
||||||
|
assert.deepEqual(disabled, ["twoFactor.enabled=false"]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("security.status erfordert Authentifizierung", async () => {
|
||||||
|
const caller = appRouter.createCaller(createUnauthedContext() as never);
|
||||||
|
await assert.rejects(
|
||||||
|
() => caller.security.status(),
|
||||||
|
(error: unknown) => {
|
||||||
|
assert.equal((error as { code?: string }).code, "UNAUTHORIZED");
|
||||||
|
return true;
|
||||||
|
},
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("security.status meldet sauberen Admin mit aktivem 2FA", async () => {
|
||||||
|
const { db, calls } = createSecurityDbMock({
|
||||||
|
dbUser: {
|
||||||
|
email: "admin@example.org",
|
||||||
|
role: "admin",
|
||||||
|
twoFactorEnabled: true,
|
||||||
|
twoFactorRecoveryRequired: false,
|
||||||
|
},
|
||||||
|
twoFactorRow: { enabled: true },
|
||||||
|
});
|
||||||
|
const caller = appRouter.createCaller(createContext({ db }) as never);
|
||||||
|
|
||||||
|
const status = await caller.security.status();
|
||||||
|
|
||||||
|
assert.deepEqual(status, {
|
||||||
|
isAdminAccount: true,
|
||||||
|
twoFactorEnabled: true,
|
||||||
|
hasTwoFactorSecret: true,
|
||||||
|
twoFactorRecoveryRequired: false,
|
||||||
|
requiresTwoFactorSetup: false,
|
||||||
|
});
|
||||||
|
assert.equal(calls.length, 0, "Keine Recovery-Updates noetig");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("security.status markiert Admin ohne 2FA-Row als setup-pflichtig", async () => {
|
||||||
|
const { db } = createSecurityDbMock({
|
||||||
|
dbUser: {
|
||||||
|
email: "admin@example.org",
|
||||||
|
role: "platform_admin",
|
||||||
|
twoFactorEnabled: false,
|
||||||
|
twoFactorRecoveryRequired: false,
|
||||||
|
},
|
||||||
|
twoFactorRow: null,
|
||||||
|
});
|
||||||
|
const caller = appRouter.createCaller(createContext({ db }) as never);
|
||||||
|
|
||||||
|
const status = await caller.security.status();
|
||||||
|
|
||||||
|
assert.equal(status.isAdminAccount, true);
|
||||||
|
assert.equal(status.twoFactorEnabled, false);
|
||||||
|
assert.equal(status.hasTwoFactorSecret, false);
|
||||||
|
assert.equal(status.requiresTwoFactorSetup, true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("security.status loescht Recovery-Flag automatisch wenn 2FA wieder aktiv", async () => {
|
||||||
|
const { db, calls } = createSecurityDbMock({
|
||||||
|
dbUser: {
|
||||||
|
email: "admin@example.org",
|
||||||
|
role: "admin",
|
||||||
|
twoFactorEnabled: true,
|
||||||
|
twoFactorRecoveryRequired: true,
|
||||||
|
},
|
||||||
|
twoFactorRow: { enabled: true },
|
||||||
|
});
|
||||||
|
const caller = appRouter.createCaller(createContext({ db }) as never);
|
||||||
|
|
||||||
|
const status = await caller.security.status();
|
||||||
|
|
||||||
|
assert.equal(status.twoFactorRecoveryRequired, false, "Flag wird im Response zurueckgesetzt");
|
||||||
|
assert.equal(status.requiresTwoFactorSetup, false);
|
||||||
|
const updateSet = calls.find((call) => call.op === "update.set")?.payload as {
|
||||||
|
twoFactorRecoveryRequired?: boolean;
|
||||||
|
twoFactorRecoveryStartedAt?: Date | null;
|
||||||
|
twoFactorRecoveryStartedBy?: string | null;
|
||||||
|
};
|
||||||
|
assert.equal(updateSet.twoFactorRecoveryRequired, false);
|
||||||
|
assert.equal(updateSet.twoFactorRecoveryStartedAt, null);
|
||||||
|
assert.equal(updateSet.twoFactorRecoveryStartedBy, null);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("security.status haelt requiresTwoFactorSetup aktiv solange Recovery noch laeuft mit deaktivierter Row", async () => {
|
||||||
|
const { db, calls } = createSecurityDbMock({
|
||||||
|
dbUser: {
|
||||||
|
email: "admin@example.org",
|
||||||
|
role: "admin",
|
||||||
|
twoFactorEnabled: true,
|
||||||
|
twoFactorRecoveryRequired: true,
|
||||||
|
},
|
||||||
|
twoFactorRow: { enabled: false },
|
||||||
|
});
|
||||||
|
const caller = appRouter.createCaller(createContext({ db }) as never);
|
||||||
|
|
||||||
|
const status = await caller.security.status();
|
||||||
|
|
||||||
|
assert.equal(status.twoFactorEnabled, false, "Row.enabled=false -> 2FA gilt als aus");
|
||||||
|
assert.equal(status.twoFactorRecoveryRequired, true);
|
||||||
|
assert.equal(status.requiresTwoFactorSetup, true);
|
||||||
|
assert.equal(
|
||||||
|
calls.some((call) => call.op === "update.set"),
|
||||||
|
false,
|
||||||
|
"Kein Auto-Clear solange 2FA effektiv aus ist",
|
||||||
|
);
|
||||||
|
});
|
||||||
Loading…
Add table
Reference in a new issue