gfds
This commit is contained in:
+10
-1
@@ -118,7 +118,7 @@ export async function getOrCreateAnonUserByCredential(credentialId, req = null,
|
||||
* @param {string} [hwFingerprint]
|
||||
* @returns {Promise<{ session: string, csrf_token: string }>}
|
||||
*/
|
||||
export async function createAnonSession(userId, req, hwFingerprint = null) {
|
||||
export async function createAnonSession(userId, req, hwFingerprint = null, credentialId = null) {
|
||||
const auditIp = resolveAuditIP(req);
|
||||
|
||||
// Update anon_identities last_ip and hw_fingerprint
|
||||
@@ -130,8 +130,15 @@ export async function createAnonSession(userId, req, hwFingerprint = null) {
|
||||
WHERE user_id = ${userId}
|
||||
`.catch(() => {});
|
||||
|
||||
// Remember which passkey this session runs on (settings: can't delete the one in use)
|
||||
const markCredential = async (sessionHash) => {
|
||||
if (!credentialId) return;
|
||||
await db`UPDATE user_sessions SET passkey_credential_id = ${credentialId} WHERE session = ${sessionHash}`.catch(() => {});
|
||||
};
|
||||
|
||||
// If req.session is already active for this exact userId, reuse it
|
||||
if (req?.session && req.session.id === userId && req.session.csrf_token && req.cookies?.session) {
|
||||
await markCredential(lib.sha256(req.cookies.session));
|
||||
await logAnonActivity(req, { action: 'handshake', hwFingerprint });
|
||||
return { session: req.cookies.session, csrf_token: req.session.csrf_token };
|
||||
}
|
||||
@@ -146,6 +153,7 @@ export async function createAnonSession(userId, req, hwFingerprint = null) {
|
||||
`;
|
||||
if (existing.length > 0) {
|
||||
await db`UPDATE user_sessions SET last_used = ${~~(Date.now() / 1e3)} WHERE session = ${existingHash}`;
|
||||
await markCredential(existingHash);
|
||||
await logAnonActivity({ ...req, session: { id: userId, is_anon: true } }, { action: 'handshake', hwFingerprint });
|
||||
return { session: req.cookies.session, csrf_token: existing[0].csrf_token };
|
||||
}
|
||||
@@ -173,6 +181,7 @@ export async function createAnonSession(userId, req, hwFingerprint = null) {
|
||||
await db`
|
||||
INSERT INTO "user_sessions" ${db(sessRecord, 'user_id', 'session', 'csrf_token', 'browser', 'created_at', 'last_used', 'last_action', 'kmsi', 'ip')}
|
||||
`;
|
||||
await markCredential(sessionHash);
|
||||
|
||||
await logAnonActivity({ ...req, session: { id: userId, is_anon: true } }, { action: 'handshake', hwFingerprint });
|
||||
|
||||
|
||||
Reference in New Issue
Block a user