Voeg auto-inlog toe per tenant

Genereert een HMAC-gesigneerd token (60s geldig) en redirect naar
<slug>.rikxplatform.nl/auto-login. Token bevat userId, accountId en
expiry; gedeeld AUTO_LOGIN_SECRET verifieert de handtekening.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Maarten Elsenaar
2026-09-15 13:43:54 +02:00
parent c293669dd2
commit ff395ac959
2 changed files with 43 additions and 1 deletions
+29
View File
@@ -0,0 +1,29 @@
"use server";
import { createHmac } from "crypto";
import { redirect } from "next/navigation";
import { getSession } from "../../lib/auth";
import { getPlatformDb } from "../../lib/platform-db";
export async function autoLogin(formData: FormData) {
const session = await getSession();
if (!session) redirect("/login");
const accountId = Number(formData.get("account_id"));
const slug = formData.get("slug") as string;
const db = getPlatformDb();
const user = db
.prepare("SELECT id FROM users WHERE account_id = ? AND role = 'admin' LIMIT 1")
.get(accountId) as { id: number } | undefined;
if (!user) redirect("/tenants?error=no-admin");
const secret = process.env.AUTO_LOGIN_SECRET!;
const expires = Date.now() + 60_000;
const payload = `${user.id}:${accountId}:${expires}`;
const sig = createHmac("sha256", secret).update(payload).digest("hex");
const token = `${payload}:${sig}`;
redirect(`https://${slug}.rikxplatform.nl/auto-login?token=${encodeURIComponent(token)}`);
}