Merge branch 'feature/auth-2fa-security' into main
Auth/registration/account-security overhaul: per-account lockout, TOTP 2FA (RFC 6238) with recovery codes, trusted devices (30-day 2FA skip), configurable email verification enforcement, and server-tracked sessions (view/revoke/sign-out-others). Full security-settings UI and login/OAuth 2FA challenge step. # Conflicts: # JobTrackerApi/Services/StartupInitializationExtensions.cs
This commit is contained in:
@@ -28,6 +28,9 @@ namespace JobTrackerApi.Data
|
||||
public DbSet<CvUploadArtifact> CvUploadArtifacts => Set<CvUploadArtifact>();
|
||||
public DbSet<CvExtractionRun> CvExtractionRuns => Set<CvExtractionRun>();
|
||||
public DbSet<TailoredCvDraft> TailoredCvDrafts => Set<TailoredCvDraft>();
|
||||
public DbSet<TwoFactorRecoveryCode> TwoFactorRecoveryCodes => Set<TwoFactorRecoveryCode>();
|
||||
public DbSet<TrustedDevice> TrustedDevices => Set<TrustedDevice>();
|
||||
public DbSet<UserSession> UserSessions => Set<UserSession>();
|
||||
|
||||
protected override void OnModelCreating(ModelBuilder modelBuilder)
|
||||
{
|
||||
@@ -152,6 +155,39 @@ namespace JobTrackerApi.Data
|
||||
.WithOne(j => j.TailoredCvDraft)
|
||||
.HasForeignKey<TailoredCvDraft>(x => x.JobApplicationId)
|
||||
.OnDelete(DeleteBehavior.Cascade);
|
||||
|
||||
// No FK to AspNetUsers: the login-time challenge endpoint reads these rows before a
|
||||
// session (and thus CurrentUserId) exists, via IgnoreQueryFilters() -- same convention
|
||||
// as AdminAuditController's cross-cutting queries.
|
||||
modelBuilder.Entity<TwoFactorRecoveryCode>()
|
||||
.HasQueryFilter(x => CurrentUserId != null && x.UserId == CurrentUserId);
|
||||
|
||||
modelBuilder.Entity<TwoFactorRecoveryCode>()
|
||||
.HasIndex(x => new { x.UserId, x.UsedAtUtc });
|
||||
|
||||
// No FK to AspNetUsers: the login-time trusted-device check reads these rows before a
|
||||
// session (and thus CurrentUserId) exists, via IgnoreQueryFilters() -- same convention
|
||||
// as TwoFactorRecoveryCode above.
|
||||
modelBuilder.Entity<TrustedDevice>()
|
||||
.HasQueryFilter(x => CurrentUserId != null && x.UserId == CurrentUserId);
|
||||
|
||||
modelBuilder.Entity<TrustedDevice>()
|
||||
.HasIndex(x => x.UserId);
|
||||
|
||||
modelBuilder.Entity<TrustedDevice>()
|
||||
.HasIndex(x => x.TokenHash);
|
||||
|
||||
// No FK to AspNetUsers, same convention as TrustedDevice/TwoFactorRecoveryCode above: the
|
||||
// OnTokenValidated auth check reads this table before CurrentUserId is meaningfully set
|
||||
// for the request being validated, via IgnoreQueryFilters().
|
||||
modelBuilder.Entity<UserSession>()
|
||||
.HasKey(x => x.Id);
|
||||
|
||||
modelBuilder.Entity<UserSession>()
|
||||
.HasQueryFilter(x => CurrentUserId != null && x.UserId == CurrentUserId);
|
||||
|
||||
modelBuilder.Entity<UserSession>()
|
||||
.HasIndex(x => x.UserId);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user