You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
svelte-kit-vice/src/libs/auth/consts.ts

429 lines
12 KiB

export const AUTH_ARTIFACT = 'auth' as const;
export const AUTH_MODULE = AUTH_ARTIFACT;
export const AUTH_AAPP_KEYS = {
ENGINE: 'auth.engine',
ACTIVE: 'auth.active'
} as const;
/**
* Routes the built-in auth handler (`createAuthHttpHandlers`) dispatches.
* Every entry here has an active server-side path; the public client
* (`ActiveAuth`) drives them through this list.
*/
export const AUTH_ROUTE_PATHS = {
BASE: '/api/auth',
CURRENT: '/api/auth/current',
CSRF: '/api/auth/csrf',
SIGN_UP_PASSWORD: '/api/auth/sign-up/password',
SIGN_IN_PASSWORD: '/api/auth/sign-in/password',
SIGN_OUT: '/api/auth/sign-out',
SIGN_OUT_GLOBAL: '/api/auth/sign-out/global',
EMAIL_VERIFY_REQUEST: '/api/auth/email/verify/request',
EMAIL_VERIFY_COMPLETE: '/api/auth/email/verify/complete',
PASSWORD_RESET_REQUEST: '/api/auth/password/reset/request',
PASSWORD_RESET_COMPLETE: '/api/auth/password/reset/complete',
DEVICES: '/api/auth/devices',
DEVICE_REVOKE: '/api/auth/devices/revoke'
} as const;
/**
* Reserved paths for OAuth, MFA and WebAuthn flows. The built-in
* handler does NOT dispatch these — engine/server code for them is
* either partial or out of scope for the current release. Apps that
* implement those flows must wire their own SvelteKit handlers at the
* paths declared here so a future built-in handler stays
* URL-compatible.
*
* Marking them experimental, instead of leaving them next to the
* supported routes, prevents the situation the codex audit flagged:
* `ActiveAuth` consumers calling URLs that silently 404 because the
* generic dispatcher never routed them.
*/
export const AUTH_EXPERIMENTAL_ROUTE_PATHS = {
OAUTH_START: '/api/auth/oauth/start',
OAUTH_CALLBACK: '/api/auth/oauth/callback',
MFA_CHALLENGE: '/api/auth/mfa/challenge',
MFA_VERIFY: '/api/auth/mfa/verify',
WEBAUTHN_REGISTER_OPTIONS: '/api/auth/webauthn/register/options',
WEBAUTHN_REGISTER_VERIFY: '/api/auth/webauthn/register/verify',
WEBAUTHN_AUTH_OPTIONS: '/api/auth/webauthn/auth/options',
WEBAUTHN_AUTH_VERIFY: '/api/auth/webauthn/auth/verify'
} as const;
export const AUTH_HTTP_METHODS = {
GET: 'GET',
POST: 'POST',
PUT: 'PUT',
PATCH: 'PATCH',
DELETE: 'DELETE'
} as const;
export const AUTH_HTTP_STATUS = {
OK: 200,
BAD_REQUEST: 400,
UNAUTHORIZED: 401,
FORBIDDEN: 403,
NOT_FOUND: 404,
TOO_MANY_REQUESTS: 429
} as const;
export const AUTH_CONTENT_TYPES = {
JSON: 'application/json'
} as const;
export const AUTH_COOKIE_NAMES = {
CSRF: '__Host-active.auth.csrf',
FLOW: '__Host-active.auth.flow',
DEVICE: '__Host-active.auth.device',
REFRESH: '__Host-active.auth.refresh'
} as const;
export const AUTH_COOKIE_ATTRIBUTES = {
HTTP_ONLY: 'HttpOnly',
SECURE: 'Secure',
SAME_SITE: 'SameSite',
PATH: 'Path',
MAX_AGE: 'Max-Age',
EXPIRES: 'Expires',
LAX: 'Lax',
STRICT: 'Strict',
NONE: 'None'
} as const;
export const AUTH_HEADER_NAMES = {
ACCEPT: 'accept',
CONTENT_TYPE: 'content-type',
COOKIE: 'cookie',
SET_COOKIE: 'set-cookie',
CSRF: 'x-active-auth-csrf',
REQUEST_ID: 'x-active-request-id',
FETCH_SITE: 'sec-fetch-site',
FETCH_MODE: 'sec-fetch-mode',
FETCH_DEST: 'sec-fetch-dest',
ORIGIN: 'origin',
REFERER: 'referer',
USER_AGENT: 'user-agent'
} as const;
export const AUTH_CREDENTIAL_KINDS = {
PASSWORD: 'password',
EMAIL_OTP: 'email_otp',
MAGIC_LINK: 'magic_link',
OAUTH: 'oauth',
OIDC: 'oidc',
TOTP: 'totp',
BACKUP_CODE: 'backup_code',
WEBAUTHN: 'webauthn',
PASSKEY: 'passkey'
} as const;
export const AUTH_FACTOR_KINDS = {
PASSWORD: 'password',
EMAIL: 'email',
OAUTH: 'oauth',
TOTP: 'totp',
BACKUP_CODE: 'backup_code',
WEBAUTHN: 'webauthn',
PASSKEY: 'passkey'
} as const;
export const AUTH_AAL = {
ANONYMOUS: 'aal0',
SINGLE_FACTOR: 'aal1',
MULTI_FACTOR: 'aal2',
PHISHING_RESISTANT: 'aal3'
} as const;
export const AUTH_AMR = {
PASSWORD: 'pwd',
EMAIL_OTP: 'otp_email',
MAGIC_LINK: 'link_email',
OAUTH: 'oauth',
OIDC: 'oidc',
TOTP: 'totp',
BACKUP_CODE: 'backup',
WEBAUTHN: 'webauthn',
PASSKEY: 'passkey'
} as const;
export const AUTH_SESSION_STATUSES = {
ANONYMOUS: 'anonymous',
AUTHENTICATED: 'authenticated',
MFA_REQUIRED: 'mfa_required'
} as const;
export const AUTH_FLOW_KINDS = {
SIGN_IN: 'sign_in',
SIGN_UP: 'sign_up',
EMAIL_VERIFICATION: 'email_verification',
PASSWORD_RESET: 'password_reset',
OAUTH_STATE: 'oauth_state',
MFA_CHALLENGE: 'mfa_challenge',
WEBAUTHN_REGISTRATION: 'webauthn_registration',
WEBAUTHN_AUTHENTICATION: 'webauthn_authentication'
} as const;
export const AUTH_PROVIDER_KINDS = {
OAUTH2: 'oauth2',
OIDC: 'oidc'
} as const;
export const AUTH_EVENT_NAMES = {
SIGN_UP_SUCCEEDED: 'auth.sign_up.succeeded',
SIGN_UP_FAILED: 'auth.sign_up.failed',
SIGN_IN_SUCCEEDED: 'auth.sign_in.succeeded',
SIGN_IN_FAILED: 'auth.sign_in.failed',
SIGN_OUT_SUCCEEDED: 'auth.sign_out.succeeded',
SIGN_OUT_GLOBAL_SUCCEEDED: 'auth.sign_out.global_succeeded',
SESSION_BOUND: 'auth.session.bound',
SESSION_REVOKED: 'auth.session.revoked',
DEVICE_REGISTERED: 'auth.device.registered',
DEVICE_REVOKED: 'auth.device.revoked',
CSRF_ISSUED: 'auth.csrf.issued',
CSRF_REJECTED: 'auth.csrf.rejected',
PASSWORD_CHANGED: 'auth.password.changed',
PASSWORD_RESET_REQUESTED: 'auth.password_reset.requested',
PASSWORD_RESET_COMPLETED: 'auth.password_reset.completed',
EMAIL_VERIFICATION_REQUESTED: 'auth.email_verification.requested',
EMAIL_VERIFIED: 'auth.email.verified',
OAUTH_STARTED: 'auth.oauth.started',
OAUTH_CALLBACK_SUCCEEDED: 'auth.oauth.callback_succeeded',
OAUTH_CALLBACK_FAILED: 'auth.oauth.callback_failed',
OAUTH_ACCOUNT_LINKED: 'auth.oauth.account_linked',
MFA_CHALLENGE_CREATED: 'auth.mfa.challenge_created',
MFA_VERIFIED: 'auth.mfa.verified',
MFA_REQUIRED: 'auth.mfa.required',
REFRESH_ROTATED: 'auth.refresh.rotated',
REFRESH_REUSE_DETECTED: 'auth.refresh.reuse_detected',
WEBAUTHN_REGISTERED: 'auth.webauthn.registered',
WEBAUTHN_VERIFIED: 'auth.webauthn.verified'
} as const;
export const AUTH_LOG_LEVELS = {
DEBUG: 'debug',
INFO: 'info',
WARN: 'warn',
ERROR: 'error'
} as const;
export const AUTH_LOG_CATEGORIES = {
ROOT: AUTH_ARTIFACT,
ENGINE: 'auth.engine',
SESSION: 'auth.session',
CREDENTIAL: 'auth.credential',
CSRF: 'auth.csrf',
OAUTH: 'auth.oauth',
MFA: 'auth.mfa',
DEVICE: 'auth.device',
REFRESH: 'auth.refresh',
WEBAUTHN: 'auth.webauthn'
} as const;
export const AUTH_LOG_MESSAGES = {
SIGN_IN_SUCCEEDED: 'auth.sign_in.succeeded',
SIGN_IN_FAILED: 'auth.sign_in.failed',
SIGN_UP_SUCCEEDED: 'auth.sign_up.succeeded',
SIGN_UP_FAILED: 'auth.sign_up.failed',
SIGN_OUT_SUCCEEDED: 'auth.sign_out.succeeded',
CSRF_ISSUED: 'auth.csrf.issued',
CSRF_REJECTED: 'auth.csrf.rejected',
TOKEN_REUSE_DETECTED: 'auth.refresh.reuse_detected',
ACCOUNT_NOT_LINKED: 'auth.oauth.account_not_linked',
SESSION_REVOKED: 'auth.session.revoked',
MFA_REQUIRED: 'auth.mfa.required',
WEBAUTHN_FAILED: 'auth.webauthn.failed',
EMAIL_VERIFICATION_REQUESTED: 'auth.email_verification.requested',
EMAIL_VERIFIED: 'auth.email.verified',
PASSWORD_RESET_REQUESTED: 'auth.password_reset.requested',
PASSWORD_RESET_COMPLETED: 'auth.password_reset.completed'
} as const;
export const AUTH_DIAGNOSTIC_EVENTS = {
SECURITY_EVENT: 'auth.security_event'
} as const;
export const AUTH_DEFAULTS = {
CSRF_TTL_MS: 30 * 60 * 1000,
FLOW_TTL_MS: 10 * 60 * 1000,
OTP_TTL_MS: 10 * 60 * 1000,
PASSWORD_RESET_TTL_MS: 15 * 60 * 1000,
ACCESS_TOKEN_TTL_MS: 10 * 60 * 1000,
REFRESH_REUSE_GRACE_MS: 10 * 1000,
REFRESH_IDLE_TTL_MS: 30 * 24 * 60 * 60 * 1000,
CLOCK_SKEW_MS: 60 * 1000,
PASSWORD_MIN_LENGTH_WITH_MFA: 8,
PASSWORD_MIN_LENGTH_WITHOUT_MFA: 15,
PASSWORD_MAX_LENGTH: 1024,
RANDOM_TOKEN_BYTES: 32,
ID_RANDOM_BYTES: 16,
HASH_PREVIEW_CHARS: 8
} as const;
export const AUTH_COOKIE_POLICY = {
AUTH_COOKIES_PREFIX: '__Host-',
PATH: '/',
SAME_SITE: 'strict',
SECURE: true,
HTTP_ONLY_FOR_SECRETS: true,
DOMAIN: undefined
} as const;
export const AUTH_CACHE_TAGS = {
AUTH_CURRENT: 'auth.current',
AUTH_DEVICES: 'auth.devices',
AUTH_FACTORS: 'auth.factors'
} as const;
export const AUTH_LOCALS_KEYS = {
AUTH: 'auth'
} as const;
export const AUTH_STORAGE_KEYS = {
CURRENT_VIEW: 'auth.current.view',
NON_SECRET_CSRF_CACHE: 'auth.csrf.non_secret_cache'
} as const;
export const AUTH_ID_PREFIXES = {
ACTOR: 'auth_actor',
CREDENTIAL: 'auth_cred',
FLOW: 'auth_flow',
DEVICE: 'auth_dev',
SESSION: 'auth_sess',
LINKED_ACCOUNT: 'auth_link',
REFRESH_FAMILY: 'auth_rfam',
REFRESH_TOKEN: 'auth_rtok',
WEBAUTHN_CREDENTIAL: 'auth_wac'
} as const;
export const AUTH_TOKEN_FORMATS = {
CSRF_VERSION: 'v1',
SEGMENT_SEPARATOR: '.',
COOKIE_ASSIGNMENT: '=',
COOKIE_SEPARATOR: '; ',
BASE64URL_PADDING: '=',
BASE64URL_PLUS: '+',
BASE64URL_SLASH: '/',
BASE64URL_MINUS: '-',
BASE64URL_UNDERSCORE: '_',
EMPTY: ''
} as const;
export const AUTH_REVOKE_REASONS = {
LOGOUT: 'logout',
GLOBAL_LOGOUT: 'global_logout',
DEVICE_REVOKED: 'device_revoked',
PASSWORD_CHANGED: 'password_changed',
REFRESH_REUSE: 'refresh_reuse',
TENANT_BOUNDARY: 'tenant_boundary',
ADMIN: 'admin'
} as const;
export const AUTH_TEST_IDS = {
CURRENT: 'auth-test-current',
PASSWORD_FORM: 'auth-test-password-form',
SIGN_OUT: 'auth-test-sign-out',
EVENTS: 'auth-test-events',
DEVICES: 'auth-test-devices'
} as const;
export const AUTH_TEST_COOKIE_NAMES = {
SESSION: 'active.auth.test.session'
} as const;
export const AUTH_TEST_ACTIONS = {
SIGN_UP: 'signUp',
SIGN_IN: 'signIn',
SIGN_OUT: 'signOut',
SIGN_OUT_GLOBAL: 'signOutGlobal',
CSRF_ROUNDTRIP: 'csrfRoundtrip',
CSRF_EXPIRED: 'csrfExpired',
RESET: 'reset'
} as const;
export const AUTH_TEST_FORM_FIELDS = {
IDENTIFIER: 'identifier',
PASSWORD: 'password',
DISPLAY_NAME: 'displayName'
} as const;
export const AUTH_MAIL_KINDS = {
EMAIL_VERIFICATION: 'email_verification',
PASSWORD_RESET: 'password_reset',
EMAIL_OTP: 'email_otp',
SECURITY_ALERT: 'security_alert'
} as const;
export const AUTH_PASSWORD_HASH_ALGORITHMS = {
TEST: 'test-plain-base64-not-production',
SCRYPT: 'scrypt'
} as const;
export const AUTH_OAUTH_PARAMS = {
RESPONSE_TYPE: 'response_type',
CLIENT_ID: 'client_id',
REDIRECT_URI: 'redirect_uri',
SCOPE: 'scope',
STATE: 'state',
CODE_CHALLENGE_METHOD: 'code_challenge_method',
CODE_CHALLENGE: 'code_challenge'
} as const;
export const AUTH_OAUTH_FLOW_METADATA = {
STATE: 'state',
VERIFIER: 'verifier'
} as const;
export const AUTH_OAUTH_VALUES = {
CODE: 'code',
S256: 'S256',
OPENID: 'openid',
EMAIL: 'email',
PROFILE: 'profile',
SCOPE_SEPARATOR: ' '
} as const;
export const AUTH_POLICY_KEYS = {
PASSWORD_LENGTH: 'password_length'
} as const;
export const AUTH_ENGINE_METHODS = {
CURRENT: 'current',
SIGN_UP_PASSWORD: 'signUpPassword',
SIGN_IN_PASSWORD: 'signInPassword',
SIGN_OUT: 'signOut',
SIGN_OUT_GLOBAL: 'signOutGlobal',
ISSUE_CSRF: 'issueCsrf',
VERIFY_CSRF: 'verifyCsrf',
REQUEST_EMAIL_VERIFICATION: 'requestEmailVerification',
COMPLETE_EMAIL_VERIFICATION: 'completeEmailVerification',
REQUEST_PASSWORD_RESET: 'requestPasswordReset',
COMPLETE_PASSWORD_RESET: 'completePasswordReset',
LIST_DEVICES: 'listDevices',
REVOKE_DEVICE: 'revokeDevice',
START_OAUTH: 'startOAuth',
COMPLETE_OAUTH: 'completeOAuth',
CREATE_MFA_CHALLENGE: 'createMfaChallenge',
VERIFY_MFA_CHALLENGE: 'verifyMfaChallenge'
} as const;
export const AUTH_INTERNAL_ERROR_MESSAGES = {
MEMORY_REFRESH_TOKEN_NOT_FOUND: 'AUTH_MEMORY_REFRESH_TOKEN_NOT_FOUND',
DB_REFRESH_TOKEN_NOT_FOUND: 'AUTH_DB_REFRESH_TOKEN_NOT_FOUND',
INVALID_ACTIVE_RESPONSE: 'AUTH_INVALID_ACTIVE_RESPONSE'
} as const;
export const AUTH_MEMORY_ADAPTER_PRODUCTION_WARNING = 'auth.memory_adapter.production_warning';
export const AUTH_EVENT_PREFIXES = {
CSRF: 'auth.csrf',
OAUTH: 'auth.oauth',
MFA: 'auth.mfa',
DEVICE: 'auth.device',
REFRESH: 'auth.refresh',
WEBAUTHN: 'auth.webauthn',
SESSION: 'auth.session',
SIGN_OUT: 'auth.sign_out'
} as const;

Powered by TurnKey Linux.