Stage M2
This commit is contained in:
@@ -0,0 +1,83 @@
|
||||
/**
|
||||
* Creates or repairs a SUPER_ADMIN account.
|
||||
*
|
||||
* pnpm --filter @sport/api run create-admin
|
||||
* ADMIN_EMAIL=me@example.com ADMIN_PASSWORD='…' pnpm ... run create-admin
|
||||
*
|
||||
* This is the production bootstrap path, and the reason the seed never creates
|
||||
* a privileged account with a known password. Safe to re-run: an existing
|
||||
* account has its password reset and its role re-granted, which doubles as the
|
||||
* "locked out of the admin" recovery procedure.
|
||||
*/
|
||||
import { PrismaClient } from '@prisma/client';
|
||||
import { SYSTEM_ROLES } from '@sport/types';
|
||||
|
||||
import { generatePassword, hashPassword, verifyPassword } from './seed/accounts';
|
||||
|
||||
const prisma = new PrismaClient();
|
||||
|
||||
async function main(): Promise<void> {
|
||||
const email = (process.env['ADMIN_EMAIL'] ?? 'admin@sport.local').trim().toLowerCase();
|
||||
const provided = process.env['ADMIN_PASSWORD'];
|
||||
const password = provided ?? generatePassword();
|
||||
|
||||
if (provided && provided.length < 10) {
|
||||
throw new Error('ADMIN_PASSWORD must be at least 10 characters.');
|
||||
}
|
||||
|
||||
const passwordHash = await hashPassword(password);
|
||||
|
||||
// Verify the hash round-trips before writing it. A malformed hash here would
|
||||
// create an account nobody can ever sign in to, and the failure would only
|
||||
// surface at the login screen.
|
||||
if (!(await verifyPassword(password, passwordHash))) {
|
||||
throw new Error('Password hash failed self-verification; refusing to write.');
|
||||
}
|
||||
|
||||
const role = await prisma.role.findUnique({ where: { key: SYSTEM_ROLES.SUPER_ADMIN } });
|
||||
if (!role) {
|
||||
throw new Error('The super_admin role is missing. Run `pnpm db:seed` first.');
|
||||
}
|
||||
|
||||
const user = await prisma.user.upsert({
|
||||
where: { email },
|
||||
update: { passwordHash, status: 'ACTIVE', type: 'SUPER_ADMIN', deletedAt: null },
|
||||
create: {
|
||||
email,
|
||||
passwordHash,
|
||||
type: 'SUPER_ADMIN',
|
||||
status: 'ACTIVE',
|
||||
firstName: 'Super',
|
||||
lastName: 'Admin',
|
||||
emailVerifiedAt: new Date(),
|
||||
},
|
||||
select: { id: true },
|
||||
});
|
||||
|
||||
await prisma.userRole.upsert({
|
||||
where: { userId_roleId: { userId: user.id, roleId: role.id } },
|
||||
update: {},
|
||||
create: { userId: user.id, roleId: role.id },
|
||||
});
|
||||
|
||||
console.log('\nSuper admin ready.\n');
|
||||
console.log(` Email: ${email}`);
|
||||
|
||||
if (provided) {
|
||||
console.log(' Password: (from ADMIN_PASSWORD)');
|
||||
} else {
|
||||
console.log(` Password: ${password}`);
|
||||
console.log('\n Generated password — shown once. Store it now.');
|
||||
}
|
||||
|
||||
console.log('');
|
||||
}
|
||||
|
||||
main()
|
||||
.catch((error: unknown) => {
|
||||
console.error(error instanceof Error ? error.message : error);
|
||||
process.exitCode = 1;
|
||||
})
|
||||
.finally(() => {
|
||||
void prisma.$disconnect();
|
||||
});
|
||||
@@ -9,6 +9,7 @@
|
||||
import { PrismaClient } from '@prisma/client';
|
||||
import { ALL_PERMISSIONS, PERMISSIONS, SYSTEM_ROLES, type Permission } from '@sport/types';
|
||||
|
||||
import { seedDevAccounts } from './seed/accounts';
|
||||
import { seedCatalog } from './seed/catalog';
|
||||
|
||||
const prisma = new PrismaClient();
|
||||
@@ -144,6 +145,19 @@ async function main(): Promise<void> {
|
||||
}
|
||||
|
||||
await seedCatalog(prisma);
|
||||
|
||||
const accounts = await seedDevAccounts(prisma);
|
||||
const created = accounts.filter((account) => account.created);
|
||||
|
||||
if (created.length > 0) {
|
||||
console.log('\nDevelopment sign-in accounts (shown once):\n');
|
||||
for (const account of created) {
|
||||
console.log(` ${account.email.padEnd(24)} ${account.password} [${account.role}]`);
|
||||
}
|
||||
console.log('\n Development only. Use `pnpm db:create-admin` for real environments.\n');
|
||||
} else {
|
||||
console.log('Development accounts already exist; passwords left unchanged.');
|
||||
}
|
||||
}
|
||||
|
||||
main()
|
||||
|
||||
@@ -0,0 +1,167 @@
|
||||
import { randomBytes, scrypt, timingSafeEqual } from 'node:crypto';
|
||||
|
||||
import type { PrismaClient } from '@prisma/client';
|
||||
import { SYSTEM_ROLES } from '@sport/types';
|
||||
|
||||
/**
|
||||
* Password hashing for scripts.
|
||||
*
|
||||
* Deliberately duplicated from `common/security/password.service.ts` rather
|
||||
* than imported: these scripts run under `tsx` outside the Nest container, and
|
||||
* booting the DI graph to hash one string would be the more fragile choice.
|
||||
*
|
||||
* The hash FORMAT is the contract between the two, and it is self-describing —
|
||||
* so a drift shows up as a failed login on the very next attempt, not as silent
|
||||
* corruption. If a third caller ever appears, extract it to a package.
|
||||
*/
|
||||
const PARAMS = { N: 16_384, r: 8, p: 1 } as const;
|
||||
const KEY_LENGTH = 64;
|
||||
const MAX_MEM = 64 * 1024 * 1024;
|
||||
|
||||
export function hashPassword(plaintext: string): Promise<string> {
|
||||
const salt = randomBytes(16);
|
||||
|
||||
return new Promise((resolve, reject) => {
|
||||
scrypt(
|
||||
plaintext.normalize('NFKC'),
|
||||
salt,
|
||||
KEY_LENGTH,
|
||||
{ ...PARAMS, maxmem: MAX_MEM },
|
||||
(error, derived) => {
|
||||
if (error) return reject(error);
|
||||
|
||||
resolve(
|
||||
[
|
||||
'scrypt',
|
||||
PARAMS.N,
|
||||
PARAMS.r,
|
||||
PARAMS.p,
|
||||
salt.toString('base64'),
|
||||
derived.toString('base64'),
|
||||
].join('$'),
|
||||
);
|
||||
},
|
||||
);
|
||||
});
|
||||
}
|
||||
|
||||
/** Used by the smoke test below to prove the format round-trips. */
|
||||
export function verifyPassword(plaintext: string, stored: string): Promise<boolean> {
|
||||
const parts = stored.split('$');
|
||||
if (parts.length !== 6 || parts[0] !== 'scrypt') return Promise.resolve(false);
|
||||
|
||||
const [, n, r, p, salt, hash] = parts;
|
||||
|
||||
return new Promise((resolve) => {
|
||||
scrypt(
|
||||
plaintext.normalize('NFKC'),
|
||||
Buffer.from(salt ?? '', 'base64'),
|
||||
KEY_LENGTH,
|
||||
{ N: Number(n), r: Number(r), p: Number(p), maxmem: MAX_MEM },
|
||||
(error, derived) => {
|
||||
if (error) return resolve(false);
|
||||
|
||||
const expected = Buffer.from(hash ?? '', 'base64');
|
||||
resolve(derived.length === expected.length && timingSafeEqual(derived, expected));
|
||||
},
|
||||
);
|
||||
});
|
||||
}
|
||||
|
||||
/** A readable, high-entropy password for generated accounts. */
|
||||
export function generatePassword(): string {
|
||||
// Base64url of 18 bytes ≈ 24 characters, ~144 bits. Suffixed to guarantee the
|
||||
// policy's uppercase/lowercase/digit requirements regardless of the draw.
|
||||
return `${randomBytes(18).toString('base64url')}aA1`;
|
||||
}
|
||||
|
||||
export interface SeededAccount {
|
||||
email: string;
|
||||
password: string;
|
||||
role: string;
|
||||
created: boolean;
|
||||
}
|
||||
|
||||
/**
|
||||
* Development sign-in accounts.
|
||||
*
|
||||
* Guarded twice — by NODE_ENV and by an explicit opt-out — because a known
|
||||
* password reaching production is the single worst thing a seed can do. The
|
||||
* generated password is printed once and never stored anywhere else.
|
||||
*
|
||||
* Existing accounts are left completely alone: re-running the seed must not
|
||||
* reset a password someone has already changed.
|
||||
*/
|
||||
export async function seedDevAccounts(prisma: PrismaClient): Promise<SeededAccount[]> {
|
||||
const accounts: SeededAccount[] = [];
|
||||
|
||||
const definitions = [
|
||||
{
|
||||
email: 'admin@sport.local',
|
||||
type: 'SUPER_ADMIN' as const,
|
||||
firstName: 'Demo',
|
||||
lastName: 'Admin',
|
||||
roleKey: SYSTEM_ROLES.SUPER_ADMIN,
|
||||
},
|
||||
{
|
||||
email: 'staff@sport.local',
|
||||
type: 'STAFF' as const,
|
||||
firstName: 'Demo',
|
||||
lastName: 'Staff',
|
||||
roleKey: SYSTEM_ROLES.CATALOG_MANAGER,
|
||||
},
|
||||
{
|
||||
email: 'customer@sport.local',
|
||||
type: 'CUSTOMER' as const,
|
||||
firstName: 'Demo',
|
||||
lastName: 'Customer',
|
||||
roleKey: SYSTEM_ROLES.CUSTOMER,
|
||||
},
|
||||
];
|
||||
|
||||
for (const definition of definitions) {
|
||||
const existing = await prisma.user.findUnique({ where: { email: definition.email } });
|
||||
|
||||
if (existing) {
|
||||
accounts.push({
|
||||
email: definition.email,
|
||||
password: '(unchanged)',
|
||||
role: definition.roleKey,
|
||||
created: false,
|
||||
});
|
||||
continue;
|
||||
}
|
||||
|
||||
const password = generatePassword();
|
||||
const role = await prisma.role.findUnique({ where: { key: definition.roleKey } });
|
||||
|
||||
const user = await prisma.user.create({
|
||||
data: {
|
||||
email: definition.email,
|
||||
passwordHash: await hashPassword(password),
|
||||
type: definition.type,
|
||||
status: 'ACTIVE',
|
||||
firstName: definition.firstName,
|
||||
lastName: definition.lastName,
|
||||
emailVerifiedAt: new Date(),
|
||||
...(role ? { roles: { create: { roleId: role.id } } } : {}),
|
||||
},
|
||||
select: { id: true },
|
||||
});
|
||||
|
||||
// A customer account needs its shopper profile, or /account has nothing to
|
||||
// hang addresses and orders off later.
|
||||
if (definition.type === 'CUSTOMER') {
|
||||
await prisma.customer.create({ data: { userId: user.id } });
|
||||
}
|
||||
|
||||
accounts.push({
|
||||
email: definition.email,
|
||||
password,
|
||||
role: definition.roleKey,
|
||||
created: true,
|
||||
});
|
||||
}
|
||||
|
||||
return accounts;
|
||||
}
|
||||
Reference in New Issue
Block a user