-
Notifications
You must be signed in to change notification settings - Fork 89
Credentials provider #192
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Credentials provider #192
Conversation
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the WalkthroughThe changes update the database schema, authentication flow, and login components. The modifications add two new text columns for storing an encrypted password and initialization vector in the User table. Adjustments are made in the Prisma schema for consistency. A new API endpoint has been created to verify user credentials and either retrieve or create a user record with encryption handling. The login page is refactored to use a new LoginForm component, and the NextAuth configuration now includes a Credentials provider with schema validation and error handling updates. Changes
Sequence Diagram(s)sequenceDiagram
participant User
participant UI as LoginForm
participant API as /api/auth/verifyCredentials
participant DB as Database (Prisma)
User->>UI: Submit email & password
UI->>API: POST credentials
API->>API: Validate request schema
API->>DB: Query user via getOrCreateUser
DB-->>API: Return user record or null
alt User exists
API->>API: Decrypt and compare password
API-->>UI: Return user data or error
else User not found
API->>DB: Create user with encrypted password
DB-->>API: Return new user record
API-->>UI: Return user data
end
UI-->>User: Display authentication result
Poem
🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 2
🧹 Nitpick comments (9)
packages/web/src/app/api/(server)/auth/verifyCredentials/route.ts (1)
10-34
: Consider implementing rate-limiting or account lockout.The
POST
handler processes credentials without any brute-force protection. Attackers can repeatedly attempt password guesses. We recommend adding measures such as rate-limiting or account lockout to help mitigate credential-stuffing attacks.packages/web/src/app/login/page.tsx (1)
3-9
: Avoid marking the function as async if there's no await.The
Login
function is declared async but doesn't use await. If no asynchronous calls are expected, consider removing the async keyword to keep the code clean.-export default async function Login() { +export default function Login() { return ( <div className="flex flex-col justify-center items-center h-screen"> <LoginForm /> </div> ); }packages/db/prisma/migrations/20250214014146_add_encrypted_password_to_user/migration.sql (1)
1-3
: Consider adding column constraints and an email index.For better security and performance:
- Add maximum length constraints to prevent excessive data storage
- Add an index on the email column to optimize credential verification lookups
-- AlterTable ALTER TABLE "User" ADD COLUMN "encryptedPassword" TEXT, ADD COLUMN "iv" TEXT; + +-- Add constraints +ALTER TABLE "User" + ALTER COLUMN "encryptedPassword" TYPE TEXT CHECK (length("encryptedPassword") <= 1024), + ALTER COLUMN "iv" TYPE TEXT CHECK (length("iv") <= 64); + +-- Add index +CREATE INDEX "User_email_idx" ON "User"("email");packages/web/src/lib/schemas.ts (1)
166-169
: Enhance password validation rules.While the minimum length requirement is good, consider adding:
- Maximum length constraints matching database limits
- Password complexity requirements (uppercase, lowercase, numbers, special chars)
export const verifyCredentialsRequestSchema = z.object({ email: z.string().email(), - password: z.string().min(8), + password: z.string() + .min(8) + .max(1024) + .regex(/[A-Z]/, "Password must contain at least one uppercase letter") + .regex(/[a-z]/, "Password must contain at least one lowercase letter") + .regex(/[0-9]/, "Password must contain at least one number") + .regex(/[^A-Za-z0-9]/, "Password must contain at least one special character"), });packages/web/src/app/login/components/loginForm.tsx (3)
45-49
: Improve error message clarity.The current generic error message could be more helpful to users. Consider mapping error codes to specific messages.
-There was a problem when trying to authenticate. code: {error} +{(() => { + switch(error) { + case 'CredentialsSignin': + return 'Invalid email or password. Please try again.'; + case 'OAuthAccountNotLinked': + return 'This email is already associated with a different sign-in method.'; + default: + return 'An error occurred during authentication. Please try again.'; + } +})()}
92-94
: Add autocomplete attributes for better UX.Help password managers by adding appropriate autocomplete attributes.
-<Input placeholder="email@example.com" {...field} /> +<Input + placeholder="email@example.com" + autoComplete="username email" + {...field} +/>
105-107
: Add password visibility toggle.Consider adding a button to toggle password visibility for better UX.
<FormControl> - <Input type="password" {...field} /> + <div className="relative"> + <Input + type={showPassword ? "text" : "password"} + autoComplete="current-password" + {...field} + /> + <Button + type="button" + variant="ghost" + className="absolute right-0 top-0 h-full px-3" + onClick={() => setShowPassword(!showPassword)} + > + {showPassword ? <EyeOffIcon /> : <EyeIcon />} + </Button> + </div> </FormControl>packages/db/prisma/schema.prisma (2)
162-164
: Add an index to the email field for better login performance.Since this field will be frequently queried during login attempts, adding an index will improve performance.
- email String? @unique + email String? @unique @index
158-175
: Add documentation for encryption-related fields.Please add comments explaining:
- The encryption method being used
- Expected format and length of the encrypted password
- IV requirements and generation method
Example:
// @see : https://authjs.dev/concepts/database-models#user +// Password Storage: +// - encryptedPassword: AES-256-GCM encrypted password, base64 encoded +// - iv: 16-byte initialization vector for AES-GCM, base64 encoded model User {
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (8)
packages/db/prisma/migrations/20250214014146_add_encrypted_password_to_user/migration.sql
(1 hunks)packages/db/prisma/schema.prisma
(2 hunks)packages/web/src/app/api/(server)/auth/verifyCredentials/route.ts
(1 hunks)packages/web/src/app/login/components/loginForm.tsx
(1 hunks)packages/web/src/app/login/page.tsx
(1 hunks)packages/web/src/auth.ts
(2 hunks)packages/web/src/lib/errorCodes.ts
(1 hunks)packages/web/src/lib/schemas.ts
(1 hunks)
🔇 Additional comments (4)
packages/web/src/app/api/(server)/auth/verifyCredentials/route.ts (1)
36-76
:✅ Verification successful
Confirm that email is strictly unique in the Prisma schema.
When creating a user if one doesn't exist, multiple concurrent requests with the same email could race, causing data conflicts. Ensure a unique constraint on
You can verify the presence of a unique constraint by searching the Prisma schema files:
🏁 Script executed:
#!/bin/bash # Check that the 'User' model has a unique constraint on 'email' rg -A 10 'model User' prisma | rg 'email.*unique'Length of output: 98
Ensure Unique Constraint on Prisma Email Field
It appears that the initial search failed because the expected
prisma
directory does not exist. Please verify that your Prisma schema file is correctly located (e.g. at the root asschema.prisma
or in another folder) and that theUser
model declares a unique constraint on the
🏁 Script executed:
#!/bin/bash # Locate the Prisma schema file in the repository (may be named either 'schema.prisma' or reside in a 'prisma' folder) echo "Searching for schema.prisma file..." fd schema.prisma . # If found, display the 'User' model section to inspect the email field for a unique constraint. SCHEMA_FILE=$(fd schema.prisma . | head -n 1) if [ -n "$SCHEMA_FILE" ]; then echo "Found Prisma schema file at: $SCHEMA_FILE" echo "Displaying 'User' model section (10 lines after 'model User'):" grep -A 10 'model User' "$SCHEMA_FILE" else echo "No Prisma schema file found; please verify the location of your Prisma schema." fiLength of output: 1221
Unique Constraint on Email Confirmed in Prisma Schema
- The Prisma schema located at
./packages/db/prisma/schema.prisma
shows that theUser
model's@unique
attribute.- Since the
getOrCreateUser
function always provides a non-null email, this unique constraint effectively prevents duplicate entries in concurrent scenarios.- Additional Suggestion: If every user is expected to have an email, consider making the field non-nullable (i.e., remove the
?
) to ensure that no multiple null values can slip through, as some databases may allow several null entries even on uniquely constrained columns.packages/web/src/lib/errorCodes.ts (1)
15-15
: Nice addition for authentication flow.The
INVALID_CREDENTIALS
error code clearly communicates the authentication failure scenario. This is a valuable addition for more specific error handling.packages/db/prisma/schema.prisma (2)
107-122
: LGTM!The formatting changes to the
Org
model improve code readability while maintaining the same functionality.
163-164
: Consider adding field length constraints for encrypted data.The
encryptedPassword
andiv
fields should have maximum length constraints to prevent potential storage issues and ensure compatibility with your encryption method.Could you provide details about the encryption method being used? This would help determine appropriate field lengths. For example:
- encryptedPassword String? - iv String? + encryptedPassword String? @db.VarChar(255) // Adjust length based on encryption method + iv String? @db.VarChar(32) // Adjust length based on IV size
packages/web/src/app/api/(server)/auth/verifyCredentials/route.ts
Outdated
Show resolved
Hide resolved
* SQL Database (#157) * point zoekt to v3 branch * bump zoekt version * Add tenant ID concept into web app and backend (#160) * hacked together a example of using zoekt grpc api * provide tenant id to zoekt git indexer * update zoekt version to point to multitenant branch * pipe tenant id through header to zoekt * remove incorrect submodule reference and settings typo * update zoekt commit * remove unused yarn script * remove unused grpc client in web server * remove unneeded deps and improve tenant id log * pass tenant id when creating repo in db * add mt yarn script * add nocheckin comment to tenant id in v2 schema --------- Co-authored-by: bkellam <bshizzle1234@gmail.com> * bump zoekt version * parallelize repo indexing (#163) * hacked together a example of using zoekt grpc api * provide tenant id to zoekt git indexer * update zoekt version to point to multitenant branch * pipe tenant id through header to zoekt * remove incorrect submodule reference and settings typo * update zoekt commit * remove unused yarn script * remove unused grpc client in web server * remove unneeded deps and improve tenant id log * pass tenant id when creating repo in db * add mt yarn script * add pol of bullmq into backend * add better error handling and concurrency setting * spin up redis instance in dockerfile * cleanup transaction logic when adding repos to index queue * add NEW index status fetch condition * move bullmq deps to backend --------- Co-authored-by: bkellam <bshizzle1234@gmail.com> * Authentication (#164) * Add Org table (#167) * Move logout button & profile picture into settings dropdown (#172) * Multi tenancy support in config syncer (#171) * [wip] initial mt support in config syncer * Move logout button & profile picture into settings dropdown (#172) * update sync status properly and fix bug with multiple config in db case * make config path required in single tenant mode NOTE: deleting config/repos is currently not supported in multi tenancy case. Support for this will be added in a future PR --------- Co-authored-by: Brendan Kellam <bshizzle1234@gmail.com> * add tenant mode support in docker container: * Organization switching & active org management (#173) * updated syncedAt date after config sync: * Migrate to postgres (#174) * spin up postgres in docker container * get initial pol of postgres db working in docker image * spin up postgres server in dev case * updated syncedAt date after config sync: * remove unnecessary port expose in docker file * Connection creation form (#175) * fix issue with yarn dev startup * init (#176) * Add `@sourcebot/schemas` package (#177) * Connection management (#178) * add concept of secrets (#180) * add @sourcebot/schemas package * migrate things to use the schemas package * Dockerfile support * add secret table to schema * Add concept of connection manager * Rename Config->Connection * Handle job failures * Add join table between repo and connection * nits * create first version of crypto package * add crypto package as deps to others * forgot to add package changes * add server action for adding and listing secrets, create test page for it * add secrets page to nav menu * add secret to config and support fetching it in backend * reset secret form on successful submission * add toast feedback for secrets form * add instructions for adding encryption key to dev instructions * add encryption key support in docker file * add delete secret button * fix nits from pr review --------- Co-authored-by: bkellam <bshizzle1234@gmail.com> * bump zoekt version * enforce tenancy on search and repo listing endpoints (#181) * enforce tenancy on search and repo listing * remove orgId from request schemas * adds garbage collection for repos (#182) * refactor repo indexing logic into RepoManager * wip cleanup stale repos * add rest of gc logic * set status to indexing properly * add initial logic for staging environment * try to move encryption key env decleration in docker file to fix build issues * switch encryption key as build arg to se if that fixes build issues * add deployment action for staging image * try using mac github action runners instead * switch to using arm64 runners on arm64 build * change workflow names to fix trigger issue * trigger staging actions to see if it works * fix working directory typo and pray it doesnt push to prod * checkout v3 when deploying staging * try to change into the staging dir manuall * dummy commit to trigger v3 workflows to test * update staging deploy script to match new version in main * reference proper image:tag in staging fly config * update staging fly config to point to ghcr * Connection management (#183) * add invite system and google oauth provider (#185) * add settings page with members list * add invite to schema and basic create form * add invite table * add basic invite link copy button * add auth invite accept case * add non auth logic * add google oauth provider * fix reference to header component in connections * add google logo to google oauth * fix web build errors * bump staging resources * change staging cpu to perf * add side bar nav in settings page * improve styling of members page * wip adding stripe checkout button * wip onboarding flow * add stripe subscription id to org * save stripe session id and add manage subscription button in settings * properly block access to pages if user isn't in an org * wip add paywall * Domain support * Domain support (#188) * Update Makefile to include crypto package when doing a make clean * Add default for AUTH_URL in attempt to fix build * attempt 2 * fix attempt #3: Do not require a encrpytion key at build time * Fix generate script race condition * Attempt #4 * add back paywall and also add support for incrememnting seat count on invite redemption * prevent self invite * action button styling in settings and toast on copy * add ability to remove member from org * move stripe product id to env var * add await for blocking loop in backend * add subscription info to billing page * handle trial case in billing info page * add trial duration indicator to nav bar * check if domain starts or ends with dash * remove unused no org component * Generate AUTH_SECRET if not provided (#189) * remove package lock file and fix prisma dep version * revert dep version updates * fix yarn.lock * add auth and membership check to fetchSubscription * properly handle invite redeem with no valid subscription case * change back fetch subscription to not require org membership * add back subscription check in invite redeem page * Add stripe billing logic (#190) * add side bar nav in settings page * improve styling of members page * wip adding stripe checkout button * wip onboarding flow * add stripe subscription id to org * save stripe session id and add manage subscription button in settings * properly block access to pages if user isn't in an org * wip add paywall * Domain support * add back paywall and also add support for incrememnting seat count on invite redemption * prevent self invite * action button styling in settings and toast on copy * add ability to remove member from org * move stripe product id to env var * add await for blocking loop in backend * add subscription info to billing page * handle trial case in billing info page * add trial duration indicator to nav bar * check if domain starts or ends with dash * remove unused no org component * remove package lock file and fix prisma dep version * revert dep version updates * fix yarn.lock * add auth and membership check to fetchSubscription * properly handle invite redeem with no valid subscription case * change back fetch subscription to not require org membership * add back subscription check in invite redeem page --------- Co-authored-by: bkellam <bshizzle1234@gmail.com> * fix nits * remove providers check * fix more nits * change stripe init to be behind function * fix publishible stripe key handling in docker container * enforce owner perms (#191) * add make owner logic, and owner perms for removal, invite, and manage subscription * add change billing email card to billing settings * enforce owner role in action level * remove unused hover card component * cleanup * add back gitlab, gitea, and gerrit support (#184) * add non github config definitions * refactor github config compilation to seperate file * add gitlab config compilation * Connection management (#183) * wip gitlab repo sync support * fix gitlab zoekt metadata * add gitea support * add gerrit support * Connection management (#183) * add gerrit config compilation * Connection management (#183) --------- Co-authored-by: Brendan Kellam <bshizzle1234@gmail.com> * fix apos usage in redeem page * change csrf cookie to secure not host * Credentials provider (#192) * email password functionality * feedback * cleanup org's repos and shards if it's inactive (#194) * add stripe subscription status and webhook * add inactive org repo cleanup logic * mark reactivated org connections for sync * connections qol improvements (#195) * add client side polling to connections list * properly fetch repo image url * add client polling to connection management page, and add ability to sync failed connections * Fix build with suspense boundary * improved fix * add retries for 429 issues (#196) * add connection compile retry and hard repo limit * add more retry checks * cleanup unused change * address feedback * fix build errors and add index concurrency env var * add config upsert timeout env var * Membership settings rework (#198) * Add refined members list * futher progress on members settings polish * Remove old components * feedback * Magic links (#199) * wip on magic link support * Switch to nodemailer / resend for transactional mail * Further cleanup * Add stylized email using react-email * fix * Fix build * db performance improvements and job resilience (#200) * replace upsert with seperate create many and raw update many calls * add bulk repo status update and queue addition with priority * add support for managed redis * add note for changing raw sql on schema change * remove non secret token options * fix token examples in schema * add better visualization for connection/repo errors and warnings (#201) * replace upsert with seperate create many and raw update many calls * add bulk repo status update and queue addition with priority * add support for managed redis * add note for changing raw sql on schema change * add error package and use BackendException in connection manager * handle connection failure display on web app * add warning banner for not found orgs/repos/users * add failure handling for gerrit * add gitea notfound warning support * add warning icon in connections list * style nits * add failed repo vis in connections list * added retry failed repo index buttons * move nav indicators to client with polling * fix indicator flash issue and truncate large list results * display error nav better * truncate failed repo list in connection list item * fix merge error * fix merge bug * add connection util file [wip] * refactor notfound fetch logic and add missing error package to dockerfile * move repeated logic to function and add zod schema for syncStatusMetadata * add orgid unique constraint to repo * revert repo compile update logic to upsert loop * log upsert stats * [temp] disable polling everywhere (#205) * add health check endpoint * Refined onboarding flow (#202) * Redeem UX pass (#204) * add log for health check * fix new connection complete callback route * add cpu split logic and only wait for postgres if we're going to connec to it * Inline secret creation (#207) * use docker scopes to try and improve caching * Dummy change * remove cpu split logic * Add some instrumentation to web * add posthog events on various user actions (#208) * add page view event support * add posthog events * nit: remove unused import * feedback * fix merge error * use staging posthog papik when building staging image * fix other merge error and build warnings * Add invite email (#209) * wrap posthog provider in suspense to fix build error * add grafana alloy config and setup (#210) * add grafana alloy config and setup * add basic repo prom metrics * nits in dockerfile * remove invalid characters when auto filling domain * add login posthog events * remove hard coded sourcebot.app references * make repo garbage collection async (#211) * add gc queue logic * fix missing switch cases for gc status * style org create form better with new staging domain * change repo rm logic to be async * simplify repo for inactive org query * add grace period for garbage collecting repos * make prom scrape interval 500ms * fix typo in trial card * onboarding tweaks * rename some prom metrics and cleanup unused * wipe existing repo if we've picked up a killed job to ensure good state * Connections UX pass + query optimizations (#212) * remove git & local schemas (#213) * skip stripe checkout for trial + fix indexing in progress UI + additional schema validation (#214) * add additional config validation * wip bypass stripe checkout for trial * fix stripe trial checkout bypass * fix indexing in progress ui on home page * add subscription checks, more schema validation, and fix issue with complete page * dont display if no indexed repos * fix skipping onboard complete check * fix build error * add back button in onboard connection creation flow * Add back revision support (#215) * fix build * Fix bug with repository snapshot * fix share links * fix repo rm issue, 502 page, condition on test clock * Make login and onboarding mobile friendly * fix ordering of quick actions * remove error msg dump on failed repo index job, and update indexedAt field * Add mobile unsupported splash screne * cherry pick fix for file links * [Cherry Pick] Syntax reference guide (#169) (#216) * Add .env to db gitignore * fix case where we have repos but they're all failed for repo snapshot * /settings/secrets page (#217) * display domain properly in org create form * Quick action tweaks (#218) * revamp repo page (#220) * wip repo table * new repo page * add indicator for when feedback is applied in repo page * add repo button * fetch connection data in one query * fix styling * fix (#219) * remove / keyboard shortcut hint in search bar * prevent switching to first page on data update and truncate long repo names in repo list * General settings + cleanup (#221) * General settings * Add alert to org domain change * First attempt at sending logs to grafana * logs wip * add alloy logs * wip * [temp] comment out loki for now * update trial card content and add events for code host selection on onboard * reduce scraping interval to 15s * Add prometheus metric for pending repo indexing jobs * switch magic link to invite code (#222) * wip magic link codes * pipe email to email provider properly * remove magic link data cookie after sign in * clean up unused imports * dont remove cookie before we use it * rm package-lock.json * revert yarn files to v3 state * switch email passing from cookie to search param * add comment for settings dropdown auth update * remove unused middleware file * fix build error and warnings * fix build error with useSearchParam not wrapped in suspense * add sentry support to backend and webapp (#223) * add sentry to web app * set sentry environemnt from env var * add sentry env replace logic in docker container * wip add backend sentry * add sentry to backend * move dns to env var * remove test exception * Fix root domain issue on onboarding * add setup sentry cli step to github action * login to sentry * fix sentry login in action * Update grafana loki endpoint * switch source map publish to runtime in entrypoint * catch and rethrow simplegit exceptions * alloy nits * fix alloy * backend logging (#224) * revert grafana loki config * fix login ui nits * fix quick actions * fix typo in secret creation * fix private repo clone issue for gitlab * add repo index timeout logic * add posthog identify call after registeration * various changes to add terms and security info (#225) * add terms and security to footer * add security card * add demo card * fix build error * nit fix: center 'get in touch' on security card * Dark theme improvements (#226) * (fix) Fixed bug with gitlab and gitea not including hostname in the repoName * Switch to using t3-env for env-var management (#230) * Add missing env var * fix build * Centralize to using a single .env.development for development workflows (#231) * Make billing optional (#232) * Massage environment variables from strings to numbers (#234) * Single tenancy & auth modes (#233) * Add docs to this repo * dummy change * Declarative connection configuration (#235) * fix build * upgrade to next 14.2.25 * Improved database DX * migrate to yarn v4 * Use origin from header for baseUrl of emails (instead of AUTH_URL). Also removed reference to hide scrollbars * Remove SOURCEBOT_ENCRYPTION_KEY from build arg * Fix issue with linking default user to org in single tenant + no-auth mode * Fix fallback tokens (#242) * add SECURITY_CARD_ENABLED flag * Add repository weburl (#243) * Random fixes and improvements (#244) * add zoekt max wall time env var * remove empty warning in docs * fix reference in sh docs * add connection manager upsert timeout env var * Declarative connection cleanup + improvements (#245) * change contact us footer in app to point to main contact form * PostHog event pass (#246) * fix typo * Add sourcebot cloud environment prop to staging workflow * Update generated files * remove AUTH_URL since it unused and (likely) unnecessary * Revert "remove AUTH_URL since it unused and (likely) unnecessary" This reverts commit 1f4a5ae. * cleanup GitHub action releases (#252) * remove alloy, change auth defaul to disabled, add settings page in me dropdown * enforce connection management perms to owner (#253) * enforce conneciton management perms to owner * fix formatting * more formatting * naming nits * fix var name error * change empty repo set copy if auth is disabled * add CONTRIBUTING.md file * hide settings in dropdown with auth isnt enabled * handle case where gerrit weburl is just gitiles path * Docs overhall (#251) * remove nocheckin * fix build error * remove v3 trigger from deploy staging * fix build errors round 2 * another error fix --------- Co-authored-by: msukkari <michael.sukkarieh@mail.mcgill.ca>
This PR adds support for email / password login
Summary by CodeRabbit
New Features
Refactor