You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
429 lines
12 KiB
429 lines
12 KiB
export const AUTH_ARTIFACT = 'auth' as const;
|
|
export const AUTH_MODULE = AUTH_ARTIFACT;
|
|
|
|
export const AUTH_AAPP_KEYS = {
|
|
ENGINE: 'auth.engine',
|
|
ACTIVE: 'auth.active'
|
|
} as const;
|
|
|
|
/**
|
|
* Routes the built-in auth handler (`createAuthHttpHandlers`) dispatches.
|
|
* Every entry here has an active server-side path; the public client
|
|
* (`ActiveAuth`) drives them through this list.
|
|
*/
|
|
export const AUTH_ROUTE_PATHS = {
|
|
BASE: '/api/auth',
|
|
CURRENT: '/api/auth/current',
|
|
CSRF: '/api/auth/csrf',
|
|
SIGN_UP_PASSWORD: '/api/auth/sign-up/password',
|
|
SIGN_IN_PASSWORD: '/api/auth/sign-in/password',
|
|
SIGN_OUT: '/api/auth/sign-out',
|
|
SIGN_OUT_GLOBAL: '/api/auth/sign-out/global',
|
|
EMAIL_VERIFY_REQUEST: '/api/auth/email/verify/request',
|
|
EMAIL_VERIFY_COMPLETE: '/api/auth/email/verify/complete',
|
|
PASSWORD_RESET_REQUEST: '/api/auth/password/reset/request',
|
|
PASSWORD_RESET_COMPLETE: '/api/auth/password/reset/complete',
|
|
DEVICES: '/api/auth/devices',
|
|
DEVICE_REVOKE: '/api/auth/devices/revoke'
|
|
} as const;
|
|
|
|
/**
|
|
* Reserved paths for OAuth, MFA and WebAuthn flows. The built-in
|
|
* handler does NOT dispatch these — engine/server code for them is
|
|
* either partial or out of scope for the current release. Apps that
|
|
* implement those flows must wire their own SvelteKit handlers at the
|
|
* paths declared here so a future built-in handler stays
|
|
* URL-compatible.
|
|
*
|
|
* Marking them experimental, instead of leaving them next to the
|
|
* supported routes, prevents the situation the codex audit flagged:
|
|
* `ActiveAuth` consumers calling URLs that silently 404 because the
|
|
* generic dispatcher never routed them.
|
|
*/
|
|
export const AUTH_EXPERIMENTAL_ROUTE_PATHS = {
|
|
OAUTH_START: '/api/auth/oauth/start',
|
|
OAUTH_CALLBACK: '/api/auth/oauth/callback',
|
|
MFA_CHALLENGE: '/api/auth/mfa/challenge',
|
|
MFA_VERIFY: '/api/auth/mfa/verify',
|
|
WEBAUTHN_REGISTER_OPTIONS: '/api/auth/webauthn/register/options',
|
|
WEBAUTHN_REGISTER_VERIFY: '/api/auth/webauthn/register/verify',
|
|
WEBAUTHN_AUTH_OPTIONS: '/api/auth/webauthn/auth/options',
|
|
WEBAUTHN_AUTH_VERIFY: '/api/auth/webauthn/auth/verify'
|
|
} as const;
|
|
|
|
export const AUTH_HTTP_METHODS = {
|
|
GET: 'GET',
|
|
POST: 'POST',
|
|
PUT: 'PUT',
|
|
PATCH: 'PATCH',
|
|
DELETE: 'DELETE'
|
|
} as const;
|
|
|
|
export const AUTH_HTTP_STATUS = {
|
|
OK: 200,
|
|
BAD_REQUEST: 400,
|
|
UNAUTHORIZED: 401,
|
|
FORBIDDEN: 403,
|
|
NOT_FOUND: 404,
|
|
TOO_MANY_REQUESTS: 429
|
|
} as const;
|
|
|
|
export const AUTH_CONTENT_TYPES = {
|
|
JSON: 'application/json'
|
|
} as const;
|
|
|
|
export const AUTH_COOKIE_NAMES = {
|
|
CSRF: '__Host-active.auth.csrf',
|
|
FLOW: '__Host-active.auth.flow',
|
|
DEVICE: '__Host-active.auth.device',
|
|
REFRESH: '__Host-active.auth.refresh'
|
|
} as const;
|
|
|
|
export const AUTH_COOKIE_ATTRIBUTES = {
|
|
HTTP_ONLY: 'HttpOnly',
|
|
SECURE: 'Secure',
|
|
SAME_SITE: 'SameSite',
|
|
PATH: 'Path',
|
|
MAX_AGE: 'Max-Age',
|
|
EXPIRES: 'Expires',
|
|
LAX: 'Lax',
|
|
STRICT: 'Strict',
|
|
NONE: 'None'
|
|
} as const;
|
|
|
|
export const AUTH_HEADER_NAMES = {
|
|
ACCEPT: 'accept',
|
|
CONTENT_TYPE: 'content-type',
|
|
COOKIE: 'cookie',
|
|
SET_COOKIE: 'set-cookie',
|
|
CSRF: 'x-active-auth-csrf',
|
|
REQUEST_ID: 'x-active-request-id',
|
|
FETCH_SITE: 'sec-fetch-site',
|
|
FETCH_MODE: 'sec-fetch-mode',
|
|
FETCH_DEST: 'sec-fetch-dest',
|
|
ORIGIN: 'origin',
|
|
REFERER: 'referer',
|
|
USER_AGENT: 'user-agent'
|
|
} as const;
|
|
|
|
export const AUTH_CREDENTIAL_KINDS = {
|
|
PASSWORD: 'password',
|
|
EMAIL_OTP: 'email_otp',
|
|
MAGIC_LINK: 'magic_link',
|
|
OAUTH: 'oauth',
|
|
OIDC: 'oidc',
|
|
TOTP: 'totp',
|
|
BACKUP_CODE: 'backup_code',
|
|
WEBAUTHN: 'webauthn',
|
|
PASSKEY: 'passkey'
|
|
} as const;
|
|
|
|
export const AUTH_FACTOR_KINDS = {
|
|
PASSWORD: 'password',
|
|
EMAIL: 'email',
|
|
OAUTH: 'oauth',
|
|
TOTP: 'totp',
|
|
BACKUP_CODE: 'backup_code',
|
|
WEBAUTHN: 'webauthn',
|
|
PASSKEY: 'passkey'
|
|
} as const;
|
|
|
|
export const AUTH_AAL = {
|
|
ANONYMOUS: 'aal0',
|
|
SINGLE_FACTOR: 'aal1',
|
|
MULTI_FACTOR: 'aal2',
|
|
PHISHING_RESISTANT: 'aal3'
|
|
} as const;
|
|
|
|
export const AUTH_AMR = {
|
|
PASSWORD: 'pwd',
|
|
EMAIL_OTP: 'otp_email',
|
|
MAGIC_LINK: 'link_email',
|
|
OAUTH: 'oauth',
|
|
OIDC: 'oidc',
|
|
TOTP: 'totp',
|
|
BACKUP_CODE: 'backup',
|
|
WEBAUTHN: 'webauthn',
|
|
PASSKEY: 'passkey'
|
|
} as const;
|
|
|
|
export const AUTH_SESSION_STATUSES = {
|
|
ANONYMOUS: 'anonymous',
|
|
AUTHENTICATED: 'authenticated',
|
|
MFA_REQUIRED: 'mfa_required'
|
|
} as const;
|
|
|
|
export const AUTH_FLOW_KINDS = {
|
|
SIGN_IN: 'sign_in',
|
|
SIGN_UP: 'sign_up',
|
|
EMAIL_VERIFICATION: 'email_verification',
|
|
PASSWORD_RESET: 'password_reset',
|
|
OAUTH_STATE: 'oauth_state',
|
|
MFA_CHALLENGE: 'mfa_challenge',
|
|
WEBAUTHN_REGISTRATION: 'webauthn_registration',
|
|
WEBAUTHN_AUTHENTICATION: 'webauthn_authentication'
|
|
} as const;
|
|
|
|
export const AUTH_PROVIDER_KINDS = {
|
|
OAUTH2: 'oauth2',
|
|
OIDC: 'oidc'
|
|
} as const;
|
|
|
|
export const AUTH_EVENT_NAMES = {
|
|
SIGN_UP_SUCCEEDED: 'auth.sign_up.succeeded',
|
|
SIGN_UP_FAILED: 'auth.sign_up.failed',
|
|
SIGN_IN_SUCCEEDED: 'auth.sign_in.succeeded',
|
|
SIGN_IN_FAILED: 'auth.sign_in.failed',
|
|
SIGN_OUT_SUCCEEDED: 'auth.sign_out.succeeded',
|
|
SIGN_OUT_GLOBAL_SUCCEEDED: 'auth.sign_out.global_succeeded',
|
|
SESSION_BOUND: 'auth.session.bound',
|
|
SESSION_REVOKED: 'auth.session.revoked',
|
|
DEVICE_REGISTERED: 'auth.device.registered',
|
|
DEVICE_REVOKED: 'auth.device.revoked',
|
|
CSRF_ISSUED: 'auth.csrf.issued',
|
|
CSRF_REJECTED: 'auth.csrf.rejected',
|
|
PASSWORD_CHANGED: 'auth.password.changed',
|
|
PASSWORD_RESET_REQUESTED: 'auth.password_reset.requested',
|
|
PASSWORD_RESET_COMPLETED: 'auth.password_reset.completed',
|
|
EMAIL_VERIFICATION_REQUESTED: 'auth.email_verification.requested',
|
|
EMAIL_VERIFIED: 'auth.email.verified',
|
|
OAUTH_STARTED: 'auth.oauth.started',
|
|
OAUTH_CALLBACK_SUCCEEDED: 'auth.oauth.callback_succeeded',
|
|
OAUTH_CALLBACK_FAILED: 'auth.oauth.callback_failed',
|
|
OAUTH_ACCOUNT_LINKED: 'auth.oauth.account_linked',
|
|
MFA_CHALLENGE_CREATED: 'auth.mfa.challenge_created',
|
|
MFA_VERIFIED: 'auth.mfa.verified',
|
|
MFA_REQUIRED: 'auth.mfa.required',
|
|
REFRESH_ROTATED: 'auth.refresh.rotated',
|
|
REFRESH_REUSE_DETECTED: 'auth.refresh.reuse_detected',
|
|
WEBAUTHN_REGISTERED: 'auth.webauthn.registered',
|
|
WEBAUTHN_VERIFIED: 'auth.webauthn.verified'
|
|
} as const;
|
|
|
|
|
|
export const AUTH_LOG_LEVELS = {
|
|
DEBUG: 'debug',
|
|
INFO: 'info',
|
|
WARN: 'warn',
|
|
ERROR: 'error'
|
|
} as const;
|
|
|
|
export const AUTH_LOG_CATEGORIES = {
|
|
ROOT: AUTH_ARTIFACT,
|
|
ENGINE: 'auth.engine',
|
|
SESSION: 'auth.session',
|
|
CREDENTIAL: 'auth.credential',
|
|
CSRF: 'auth.csrf',
|
|
OAUTH: 'auth.oauth',
|
|
MFA: 'auth.mfa',
|
|
DEVICE: 'auth.device',
|
|
REFRESH: 'auth.refresh',
|
|
WEBAUTHN: 'auth.webauthn'
|
|
} as const;
|
|
|
|
export const AUTH_LOG_MESSAGES = {
|
|
SIGN_IN_SUCCEEDED: 'auth.sign_in.succeeded',
|
|
SIGN_IN_FAILED: 'auth.sign_in.failed',
|
|
SIGN_UP_SUCCEEDED: 'auth.sign_up.succeeded',
|
|
SIGN_UP_FAILED: 'auth.sign_up.failed',
|
|
SIGN_OUT_SUCCEEDED: 'auth.sign_out.succeeded',
|
|
CSRF_ISSUED: 'auth.csrf.issued',
|
|
CSRF_REJECTED: 'auth.csrf.rejected',
|
|
TOKEN_REUSE_DETECTED: 'auth.refresh.reuse_detected',
|
|
ACCOUNT_NOT_LINKED: 'auth.oauth.account_not_linked',
|
|
SESSION_REVOKED: 'auth.session.revoked',
|
|
MFA_REQUIRED: 'auth.mfa.required',
|
|
WEBAUTHN_FAILED: 'auth.webauthn.failed',
|
|
EMAIL_VERIFICATION_REQUESTED: 'auth.email_verification.requested',
|
|
EMAIL_VERIFIED: 'auth.email.verified',
|
|
PASSWORD_RESET_REQUESTED: 'auth.password_reset.requested',
|
|
PASSWORD_RESET_COMPLETED: 'auth.password_reset.completed'
|
|
} as const;
|
|
|
|
export const AUTH_DIAGNOSTIC_EVENTS = {
|
|
SECURITY_EVENT: 'auth.security_event'
|
|
} as const;
|
|
|
|
export const AUTH_DEFAULTS = {
|
|
CSRF_TTL_MS: 30 * 60 * 1000,
|
|
FLOW_TTL_MS: 10 * 60 * 1000,
|
|
OTP_TTL_MS: 10 * 60 * 1000,
|
|
PASSWORD_RESET_TTL_MS: 15 * 60 * 1000,
|
|
ACCESS_TOKEN_TTL_MS: 10 * 60 * 1000,
|
|
REFRESH_REUSE_GRACE_MS: 10 * 1000,
|
|
REFRESH_IDLE_TTL_MS: 30 * 24 * 60 * 60 * 1000,
|
|
CLOCK_SKEW_MS: 60 * 1000,
|
|
PASSWORD_MIN_LENGTH_WITH_MFA: 8,
|
|
PASSWORD_MIN_LENGTH_WITHOUT_MFA: 15,
|
|
PASSWORD_MAX_LENGTH: 1024,
|
|
RANDOM_TOKEN_BYTES: 32,
|
|
ID_RANDOM_BYTES: 16,
|
|
HASH_PREVIEW_CHARS: 8
|
|
} as const;
|
|
|
|
export const AUTH_COOKIE_POLICY = {
|
|
AUTH_COOKIES_PREFIX: '__Host-',
|
|
PATH: '/',
|
|
SAME_SITE: 'strict',
|
|
SECURE: true,
|
|
HTTP_ONLY_FOR_SECRETS: true,
|
|
DOMAIN: undefined
|
|
} as const;
|
|
|
|
export const AUTH_CACHE_TAGS = {
|
|
AUTH_CURRENT: 'auth.current',
|
|
AUTH_DEVICES: 'auth.devices',
|
|
AUTH_FACTORS: 'auth.factors'
|
|
} as const;
|
|
|
|
export const AUTH_LOCALS_KEYS = {
|
|
AUTH: 'auth'
|
|
} as const;
|
|
|
|
export const AUTH_STORAGE_KEYS = {
|
|
CURRENT_VIEW: 'auth.current.view',
|
|
NON_SECRET_CSRF_CACHE: 'auth.csrf.non_secret_cache'
|
|
} as const;
|
|
|
|
export const AUTH_ID_PREFIXES = {
|
|
ACTOR: 'auth_actor',
|
|
CREDENTIAL: 'auth_cred',
|
|
FLOW: 'auth_flow',
|
|
DEVICE: 'auth_dev',
|
|
SESSION: 'auth_sess',
|
|
LINKED_ACCOUNT: 'auth_link',
|
|
REFRESH_FAMILY: 'auth_rfam',
|
|
REFRESH_TOKEN: 'auth_rtok',
|
|
WEBAUTHN_CREDENTIAL: 'auth_wac'
|
|
} as const;
|
|
|
|
export const AUTH_TOKEN_FORMATS = {
|
|
CSRF_VERSION: 'v1',
|
|
SEGMENT_SEPARATOR: '.',
|
|
COOKIE_ASSIGNMENT: '=',
|
|
COOKIE_SEPARATOR: '; ',
|
|
BASE64URL_PADDING: '=',
|
|
BASE64URL_PLUS: '+',
|
|
BASE64URL_SLASH: '/',
|
|
BASE64URL_MINUS: '-',
|
|
BASE64URL_UNDERSCORE: '_',
|
|
EMPTY: ''
|
|
} as const;
|
|
|
|
export const AUTH_REVOKE_REASONS = {
|
|
LOGOUT: 'logout',
|
|
GLOBAL_LOGOUT: 'global_logout',
|
|
DEVICE_REVOKED: 'device_revoked',
|
|
PASSWORD_CHANGED: 'password_changed',
|
|
REFRESH_REUSE: 'refresh_reuse',
|
|
TENANT_BOUNDARY: 'tenant_boundary',
|
|
ADMIN: 'admin'
|
|
} as const;
|
|
|
|
export const AUTH_TEST_IDS = {
|
|
CURRENT: 'auth-test-current',
|
|
PASSWORD_FORM: 'auth-test-password-form',
|
|
SIGN_OUT: 'auth-test-sign-out',
|
|
EVENTS: 'auth-test-events',
|
|
DEVICES: 'auth-test-devices'
|
|
} as const;
|
|
|
|
export const AUTH_TEST_COOKIE_NAMES = {
|
|
SESSION: 'active.auth.test.session'
|
|
} as const;
|
|
|
|
export const AUTH_TEST_ACTIONS = {
|
|
SIGN_UP: 'signUp',
|
|
SIGN_IN: 'signIn',
|
|
SIGN_OUT: 'signOut',
|
|
SIGN_OUT_GLOBAL: 'signOutGlobal',
|
|
CSRF_ROUNDTRIP: 'csrfRoundtrip',
|
|
CSRF_EXPIRED: 'csrfExpired',
|
|
RESET: 'reset'
|
|
} as const;
|
|
|
|
export const AUTH_TEST_FORM_FIELDS = {
|
|
IDENTIFIER: 'identifier',
|
|
PASSWORD: 'password',
|
|
DISPLAY_NAME: 'displayName'
|
|
} as const;
|
|
|
|
export const AUTH_MAIL_KINDS = {
|
|
EMAIL_VERIFICATION: 'email_verification',
|
|
PASSWORD_RESET: 'password_reset',
|
|
EMAIL_OTP: 'email_otp',
|
|
SECURITY_ALERT: 'security_alert'
|
|
} as const;
|
|
|
|
export const AUTH_PASSWORD_HASH_ALGORITHMS = {
|
|
TEST: 'test-plain-base64-not-production',
|
|
SCRYPT: 'scrypt'
|
|
} as const;
|
|
|
|
export const AUTH_OAUTH_PARAMS = {
|
|
RESPONSE_TYPE: 'response_type',
|
|
CLIENT_ID: 'client_id',
|
|
REDIRECT_URI: 'redirect_uri',
|
|
SCOPE: 'scope',
|
|
STATE: 'state',
|
|
CODE_CHALLENGE_METHOD: 'code_challenge_method',
|
|
CODE_CHALLENGE: 'code_challenge'
|
|
} as const;
|
|
|
|
export const AUTH_OAUTH_FLOW_METADATA = {
|
|
STATE: 'state',
|
|
VERIFIER: 'verifier'
|
|
} as const;
|
|
|
|
export const AUTH_OAUTH_VALUES = {
|
|
CODE: 'code',
|
|
S256: 'S256',
|
|
OPENID: 'openid',
|
|
EMAIL: 'email',
|
|
PROFILE: 'profile',
|
|
SCOPE_SEPARATOR: ' '
|
|
} as const;
|
|
|
|
export const AUTH_POLICY_KEYS = {
|
|
PASSWORD_LENGTH: 'password_length'
|
|
} as const;
|
|
|
|
export const AUTH_ENGINE_METHODS = {
|
|
CURRENT: 'current',
|
|
SIGN_UP_PASSWORD: 'signUpPassword',
|
|
SIGN_IN_PASSWORD: 'signInPassword',
|
|
SIGN_OUT: 'signOut',
|
|
SIGN_OUT_GLOBAL: 'signOutGlobal',
|
|
ISSUE_CSRF: 'issueCsrf',
|
|
VERIFY_CSRF: 'verifyCsrf',
|
|
REQUEST_EMAIL_VERIFICATION: 'requestEmailVerification',
|
|
COMPLETE_EMAIL_VERIFICATION: 'completeEmailVerification',
|
|
REQUEST_PASSWORD_RESET: 'requestPasswordReset',
|
|
COMPLETE_PASSWORD_RESET: 'completePasswordReset',
|
|
LIST_DEVICES: 'listDevices',
|
|
REVOKE_DEVICE: 'revokeDevice',
|
|
START_OAUTH: 'startOAuth',
|
|
COMPLETE_OAUTH: 'completeOAuth',
|
|
CREATE_MFA_CHALLENGE: 'createMfaChallenge',
|
|
VERIFY_MFA_CHALLENGE: 'verifyMfaChallenge'
|
|
} as const;
|
|
|
|
export const AUTH_INTERNAL_ERROR_MESSAGES = {
|
|
MEMORY_REFRESH_TOKEN_NOT_FOUND: 'AUTH_MEMORY_REFRESH_TOKEN_NOT_FOUND',
|
|
DB_REFRESH_TOKEN_NOT_FOUND: 'AUTH_DB_REFRESH_TOKEN_NOT_FOUND',
|
|
INVALID_ACTIVE_RESPONSE: 'AUTH_INVALID_ACTIVE_RESPONSE'
|
|
} as const;
|
|
|
|
export const AUTH_MEMORY_ADAPTER_PRODUCTION_WARNING = 'auth.memory_adapter.production_warning';
|
|
|
|
export const AUTH_EVENT_PREFIXES = {
|
|
CSRF: 'auth.csrf',
|
|
OAUTH: 'auth.oauth',
|
|
MFA: 'auth.mfa',
|
|
DEVICE: 'auth.device',
|
|
REFRESH: 'auth.refresh',
|
|
WEBAUTHN: 'auth.webauthn',
|
|
SESSION: 'auth.session',
|
|
SIGN_OUT: 'auth.sign_out'
|
|
} as const;
|