This commit is contained in:
2026-09-29 04:35:35 +02:00
parent 73c0659d4a
commit 6c813143eb
51 changed files with 3708 additions and 743 deletions
+10 -1
View File
@@ -118,7 +118,7 @@ export async function getOrCreateAnonUserByCredential(credentialId, req = null,
* @param {string} [hwFingerprint]
* @returns {Promise<{ session: string, csrf_token: string }>}
*/
export async function createAnonSession(userId, req, hwFingerprint = null) {
export async function createAnonSession(userId, req, hwFingerprint = null, credentialId = null) {
const auditIp = resolveAuditIP(req);
// Update anon_identities last_ip and hw_fingerprint
@@ -130,8 +130,15 @@ export async function createAnonSession(userId, req, hwFingerprint = null) {
WHERE user_id = ${userId}
`.catch(() => {});
// Remember which passkey this session runs on (settings: can't delete the one in use)
const markCredential = async (sessionHash) => {
if (!credentialId) return;
await db`UPDATE user_sessions SET passkey_credential_id = ${credentialId} WHERE session = ${sessionHash}`.catch(() => {});
};
// If req.session is already active for this exact userId, reuse it
if (req?.session && req.session.id === userId && req.session.csrf_token && req.cookies?.session) {
await markCredential(lib.sha256(req.cookies.session));
await logAnonActivity(req, { action: 'handshake', hwFingerprint });
return { session: req.cookies.session, csrf_token: req.session.csrf_token };
}
@@ -146,6 +153,7 @@ export async function createAnonSession(userId, req, hwFingerprint = null) {
`;
if (existing.length > 0) {
await db`UPDATE user_sessions SET last_used = ${~~(Date.now() / 1e3)} WHERE session = ${existingHash}`;
await markCredential(existingHash);
await logAnonActivity({ ...req, session: { id: userId, is_anon: true } }, { action: 'handshake', hwFingerprint });
return { session: req.cookies.session, csrf_token: existing[0].csrf_token };
}
@@ -173,6 +181,7 @@ export async function createAnonSession(userId, req, hwFingerprint = null) {
await db`
INSERT INTO "user_sessions" ${db(sessRecord, 'user_id', 'session', 'csrf_token', 'browser', 'created_at', 'last_used', 'last_action', 'kmsi', 'ip')}
`;
await markCredential(sessionHash);
await logAnonActivity({ ...req, session: { id: userId, is_anon: true } }, { action: 'handshake', hwFingerprint });