|
1 | 1 | import type { LoaderFunction } from "@remix-run/node"; |
2 | 2 | import { redirect } from "@remix-run/node"; |
| 3 | +import { prisma } from "~/db.server"; |
| 4 | +import { getSession, redirectWithErrorMessage } from "~/models/message.server"; |
3 | 5 | import { authenticator } from "~/services/auth.server"; |
| 6 | +import { commitSession } from "~/services/sessionStorage.server"; |
4 | 7 | import { redirectCookie } from "./auth.github"; |
5 | | -import { getUserSession, commitSession } from "~/services/sessionStorage.server"; |
6 | | -import { logger } from "~/services/logger.server"; |
7 | | -import { MfaRequiredError } from "~/services/mfa/multiFactorAuthentication.server"; |
8 | 8 |
|
9 | 9 | export let loader: LoaderFunction = async ({ request }) => { |
10 | | - try { |
11 | | - const cookie = request.headers.get("Cookie"); |
12 | | - const redirectValue = await redirectCookie.parse(cookie); |
13 | | - const redirectTo = redirectValue ?? "/"; |
| 10 | + const cookie = request.headers.get("Cookie"); |
| 11 | + const redirectValue = await redirectCookie.parse(cookie); |
| 12 | + const redirectTo = redirectValue ?? "/"; |
| 13 | + |
| 14 | + const auth = await authenticator.authenticate("github", request, { |
| 15 | + failureRedirect: "/login", // If auth fails, the failureRedirect will be thrown as a Response |
| 16 | + }); |
| 17 | + |
| 18 | + // manually get the session |
| 19 | + const session = await getSession(request.headers.get("cookie")); |
| 20 | + |
| 21 | + const userRecord = await prisma.user.findFirst({ |
| 22 | + where: { |
| 23 | + id: auth.userId, |
| 24 | + }, |
| 25 | + select: { |
| 26 | + id: true, |
| 27 | + mfaEnabledAt: true, |
| 28 | + }, |
| 29 | + }); |
| 30 | + |
| 31 | + if (!userRecord) { |
| 32 | + return redirectWithErrorMessage( |
| 33 | + "/login", |
| 34 | + request, |
| 35 | + "Could not find your account. Please contact support." |
| 36 | + ); |
| 37 | + } |
14 | 38 |
|
15 | | - logger.debug("auth.github.callback loader", { |
16 | | - redirectTo, |
17 | | - }); |
| 39 | + if (userRecord.mfaEnabledAt) { |
| 40 | + session.set("pending-mfa-user-id", userRecord.id); |
| 41 | + session.set("pending-mfa-redirect-to", redirectTo); |
18 | 42 |
|
19 | | - const authuser = await authenticator.authenticate("github", request, { |
20 | | - successRedirect: undefined, // Don't auto-redirect, we'll handle it |
21 | | - failureRedirect: undefined, // Don't auto-redirect on failure either |
| 43 | + return redirect("/login/mfa", { |
| 44 | + headers: { |
| 45 | + "Set-Cookie": await commitSession(session), |
| 46 | + }, |
22 | 47 | }); |
| 48 | + } |
23 | 49 |
|
24 | | - logger.debug("auth.github.callback authuser", { |
25 | | - authuser, |
26 | | - }); |
| 50 | + // and store the user data |
| 51 | + session.set(authenticator.sessionKey, auth); |
27 | 52 |
|
28 | | - // If we get here, user doesn't have MFA - complete login normally |
29 | | - return redirect(redirectTo); |
30 | | - } catch (error) { |
31 | | - // Check if this is an MFA_REQUIRED error |
32 | | - if (error instanceof MfaRequiredError) { |
33 | | - // User has MFA enabled - store pending user ID and redirect to MFA page |
34 | | - const session = await getUserSession(request); |
35 | | - session.set("pending-mfa-user-id", error.userId); |
36 | | - |
37 | | - const cookie = request.headers.get("Cookie"); |
38 | | - const redirectValue = await redirectCookie.parse(cookie); |
39 | | - const redirectTo = redirectValue ?? "/"; |
40 | | - session.set("pending-mfa-redirect-to", redirectTo); |
41 | | - |
42 | | - return redirect("/login/mfa", { |
43 | | - headers: { |
44 | | - "Set-Cookie": await commitSession(session), |
45 | | - }, |
46 | | - }); |
47 | | - } |
48 | | - |
49 | | - // Regular authentication failure, redirect to login page |
50 | | - logger.debug("auth.github.callback error", { error }); |
51 | | - return redirect("/login"); |
52 | | - } |
| 53 | + return redirect(redirectTo, { |
| 54 | + headers: { |
| 55 | + "Set-Cookie": await commitSession(session), |
| 56 | + }, |
| 57 | + }); |
53 | 58 | }; |
0 commit comments