feat: Add two-factor authentication via TOTP

Adds TOTP setup with QR code, login challenge, recovery codes and
trusted devices that let a browser skip the second factor for 30
days. Admins can reset another user's second factor by confirming
with their own password.
This commit is contained in:
Daniel Hiller
2026-08-07 20:11:55 +02:00
parent 36aa732fec
commit 2e4904f77d
74 changed files with 4173 additions and 4 deletions
@@ -0,0 +1,32 @@
/*!
* Copyright (c) 2024 PLANKA Software GmbH
* Licensed under the Fair Use License: https://github.com/plankanban/planka/blob/master/LICENSE.md
*/
/* Query methods */
const createOne = (values) => TrustedDevice.create({ ...values }).fetch();
const getActiveByUserId = (userId) =>
TrustedDevice.find({
userId,
expiresAt: { '>': new Date().toISOString() },
}).sort('lastUsedAt DESC');
const updateOne = (criteria, values) => TrustedDevice.updateOne(criteria).set({ ...values });
// eslint-disable-next-line no-underscore-dangle
const delete_ = (criteria) => TrustedDevice.destroy(criteria).fetch();
const deleteByUserId = (userId) => TrustedDevice.destroy({ userId }).fetch();
const deleteOneByUserIdAndId = (userId, id) => TrustedDevice.destroyOne({ userId, id });
module.exports = {
createOne,
getActiveByUserId,
updateOne,
delete: delete_,
deleteByUserId,
deleteOneByUserIdAndId,
};