Voeg auto-inlog toe per tenant
Genereert een HMAC-gesigneerd token (60s geldig) en redirect naar <slug>.rikxplatform.nl/auto-login. Token bevat userId, accountId en expiry; gedeeld AUTO_LOGIN_SECRET verifieert de handtekening. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,29 @@
|
|||||||
|
"use server";
|
||||||
|
|
||||||
|
import { createHmac } from "crypto";
|
||||||
|
import { redirect } from "next/navigation";
|
||||||
|
import { getSession } from "../../lib/auth";
|
||||||
|
import { getPlatformDb } from "../../lib/platform-db";
|
||||||
|
|
||||||
|
export async function autoLogin(formData: FormData) {
|
||||||
|
const session = await getSession();
|
||||||
|
if (!session) redirect("/login");
|
||||||
|
|
||||||
|
const accountId = Number(formData.get("account_id"));
|
||||||
|
const slug = formData.get("slug") as string;
|
||||||
|
|
||||||
|
const db = getPlatformDb();
|
||||||
|
const user = db
|
||||||
|
.prepare("SELECT id FROM users WHERE account_id = ? AND role = 'admin' LIMIT 1")
|
||||||
|
.get(accountId) as { id: number } | undefined;
|
||||||
|
|
||||||
|
if (!user) redirect("/tenants?error=no-admin");
|
||||||
|
|
||||||
|
const secret = process.env.AUTO_LOGIN_SECRET!;
|
||||||
|
const expires = Date.now() + 60_000;
|
||||||
|
const payload = `${user.id}:${accountId}:${expires}`;
|
||||||
|
const sig = createHmac("sha256", secret).update(payload).digest("hex");
|
||||||
|
const token = `${payload}:${sig}`;
|
||||||
|
|
||||||
|
redirect(`https://${slug}.rikxplatform.nl/auto-login?token=${encodeURIComponent(token)}`);
|
||||||
|
}
|
||||||
+14
-1
@@ -3,6 +3,7 @@ import { getSession } from "../../lib/auth";
|
|||||||
import { listAccounts } from "../../lib/platform-db";
|
import { listAccounts } from "../../lib/platform-db";
|
||||||
import { createTenant, deleteTenant } from "./actions";
|
import { createTenant, deleteTenant } from "./actions";
|
||||||
import { logout } from "./logout";
|
import { logout } from "./logout";
|
||||||
|
import { autoLogin } from "./auto-login";
|
||||||
|
|
||||||
export default async function TenantsPage({
|
export default async function TenantsPage({
|
||||||
searchParams,
|
searchParams,
|
||||||
@@ -56,7 +57,7 @@ export default async function TenantsPage({
|
|||||||
<th className="text-left px-4 py-3 font-medium">URL</th>
|
<th className="text-left px-4 py-3 font-medium">URL</th>
|
||||||
<th className="text-left px-4 py-3 font-medium">Gebruikers</th>
|
<th className="text-left px-4 py-3 font-medium">Gebruikers</th>
|
||||||
<th className="text-left px-4 py-3 font-medium">Aangemaakt</th>
|
<th className="text-left px-4 py-3 font-medium">Aangemaakt</th>
|
||||||
<th className="px-4 py-3"></th>
|
<th className="px-4 py-3" colSpan={2}></th>
|
||||||
</tr>
|
</tr>
|
||||||
</thead>
|
</thead>
|
||||||
<tbody className="divide-y divide-zinc-100 dark:divide-zinc-800">
|
<tbody className="divide-y divide-zinc-100 dark:divide-zinc-800">
|
||||||
@@ -78,6 +79,18 @@ export default async function TenantsPage({
|
|||||||
<td className="px-4 py-3 text-zinc-500 dark:text-zinc-500 text-xs">
|
<td className="px-4 py-3 text-zinc-500 dark:text-zinc-500 text-xs">
|
||||||
{new Date(a.created_at).toLocaleDateString("nl-NL")}
|
{new Date(a.created_at).toLocaleDateString("nl-NL")}
|
||||||
</td>
|
</td>
|
||||||
|
<td className="px-4 py-3 text-right">
|
||||||
|
<form action={autoLogin}>
|
||||||
|
<input type="hidden" name="account_id" value={a.id} />
|
||||||
|
<input type="hidden" name="slug" value={a.slug} />
|
||||||
|
<button
|
||||||
|
type="submit"
|
||||||
|
className="text-xs text-blue-600 hover:text-blue-800 dark:text-blue-400 dark:hover:text-blue-300 transition-colors"
|
||||||
|
>
|
||||||
|
Inloggen
|
||||||
|
</button>
|
||||||
|
</form>
|
||||||
|
</td>
|
||||||
<td className="px-4 py-3 text-right">
|
<td className="px-4 py-3 text-right">
|
||||||
<form action={deleteTenant}>
|
<form action={deleteTenant}>
|
||||||
<input type="hidden" name="account_id" value={a.id} />
|
<input type="hidden" name="account_id" value={a.id} />
|
||||||
|
|||||||
Reference in New Issue
Block a user