aboutsummaryrefslogtreecommitdiff
path: root/server.mjs
diff options
context:
space:
mode:
Diffstat (limited to 'server.mjs')
-rw-r--r--server.mjs12
1 files changed, 8 insertions, 4 deletions
diff --git a/server.mjs b/server.mjs
index 9984ecc..cfd963c 100644
--- a/server.mjs
+++ b/server.mjs
@@ -577,12 +577,14 @@ const server = http.createServer(async (req, res) => {
if (req.method !== "POST") return json(res, 405, { error: "method not allowed" })
if (await loadAdmin()) return json(res, 409, { error: "admin already configured" })
const body = await readBody(req, 1024)
+ const username = String(body?.username || "").trim() || "pathways-admin"
const password = String(body?.password || "")
+ if (username.length < 2 || username.length > 40) return json(res, 400, { error: "username must be 2-40 characters" })
if (password.length < 8) return json(res, 400, { error: "password must be at least 8 characters" })
const salt = randomBytes(16).toString("hex")
const hash = await hashPassword(password, salt)
- await writeJson(ADMIN_FILE, { salt, hash, createdAt: new Date().toISOString() })
- return json(res, 200, { ok: true })
+ await writeJson(ADMIN_FILE, { username, salt, hash, createdAt: new Date().toISOString() })
+ return json(res, 200, { ok: true, username })
}
if (path === "/api/admin/login") {
if (req.method !== "POST") return json(res, 405, { error: "method not allowed" })
@@ -593,11 +595,13 @@ const server = http.createServer(async (req, res) => {
const admin = await loadAdmin()
if (!admin) return json(res, 400, { error: "no admin password configured yet" })
const body = await readBody(req, 1024)
+ const username = String(body?.username || "").trim().toLowerCase() || "pathways-admin"
const password = String(body?.password || "")
- if (!(await verifyPassword(password, admin))) {
+ const storedUser = String(admin.username || "pathways-admin").trim().toLowerCase()
+ if (username !== storedUser || !(await verifyPassword(password, admin))) {
loginFails++
if (loginFails >= 8) { loginFails = 0; loginLockUntil = Date.now() + 60_000 }
- return json(res, 401, { error: "wrong password" })
+ return json(res, 401, { error: "wrong username or password" })
}
loginFails = 0
const remember = !!body?.remember