Added secuirty 2FA for users
This commit is contained in:
Vendored
+38
-4
@@ -42,6 +42,44 @@ import { buildSeoPlugin, injectAutoFillMeta, injectSeoTabs } from './modules/seo
|
||||
let config = {
|
||||
...incomingConfig
|
||||
};
|
||||
// --- custom admin route (e.g. '/its' instead of '/admin') ---
|
||||
// Sets config.routes.admin; the project must move its app/(payload)/<route>/
|
||||
// folder to match (plugin can't create files in the project's app/).
|
||||
if (options.adminRoute) {
|
||||
config.routes = {
|
||||
...config.routes ?? {},
|
||||
admin: options.adminRoute
|
||||
};
|
||||
}
|
||||
// --- enforced 2FA (TOTP) via @clocklimited/payload-2fa ---
|
||||
// Enforced by default (forceSetup) unless twoFactor is explicitly false. The
|
||||
// plugin is a PEER dependency imported dynamically — ipal-kit doesn't bundle
|
||||
// it, so projects that opt out (twoFactor: false) needn't install it, and the
|
||||
// import never runs under generate:importmap when 2FA is off. Wrapping access
|
||||
// control (not just admin UI) means TOTP gates data access — no API bypass.
|
||||
if (options.twoFactor !== false) {
|
||||
const tf = options.twoFactor;
|
||||
if (!tf?.issuer) {
|
||||
throw new Error('[ipal] twoFactor.issuer is required (name shown in the authenticator ' + 'app). Pass twoFactor: { issuer: "Your Site" }, or twoFactor: false to ' + 'opt out (discouraged).');
|
||||
}
|
||||
try {
|
||||
// Dynamic specifier via a variable so TS doesn't try to resolve this
|
||||
// optional peer dependency at build time (it isn't in the plugin's own
|
||||
// node_modules). Avoids TS2307 without @ts-expect-error; the module
|
||||
// exists at runtime in projects that installed it.
|
||||
const pkg = '@clocklimited/payload-2fa';
|
||||
const { totpPlugin } = await import(pkg);
|
||||
config = await totpPlugin({
|
||||
collection: tf.collectionSlug ?? 'users',
|
||||
forceSetup: true,
|
||||
totp: {
|
||||
issuer: tf.issuer
|
||||
}
|
||||
})(config);
|
||||
} catch (err) {
|
||||
throw new Error('[ipal] 2FA is enforced but @clocklimited/payload-2fa is not installed. ' + 'Run: pnpm add @clocklimited/payload-2fa — or set twoFactor: false to ' + `opt out (discouraged). Original error: ${String(err)}`);
|
||||
}
|
||||
}
|
||||
// --- i18n ---
|
||||
config.localization = buildLocalizationConfig(options.i18n);
|
||||
// --- access: inject roles into the client's auth collection ---
|
||||
@@ -88,10 +126,6 @@ import { buildSeoPlugin, injectAutoFillMeta, injectSeoTabs } from './modules/seo
|
||||
buildCookieSettings(),
|
||||
buildNotifications()
|
||||
];
|
||||
// --- endpoints ---
|
||||
// Test-email endpoint (admin-only): POST /api/ipal/test-email sends a probe
|
||||
// message through the currently selected transport, so the panel's "send
|
||||
// test" button can confirm delivery without leaving the admin UI.
|
||||
config.endpoints = [
|
||||
...config.endpoints ?? [],
|
||||
testEmailEndpoint
|
||||
|
||||
Reference in New Issue
Block a user