DEV1.0: Initial commit - Workflow Portal with security fixes
- Backend: Express.js + PostgreSQL/SQLite with LDAP/AD integration - Frontend: React 18 + Vite + TailwindCSS/DaisyUI - Security fixes applied (2026-07 + 2026-08): - LDAP injection prevention, CSRF protection, HttpOnly cookies - Session hashing (SHA-256), account lockout, rate limiting - Input validation (zod), file upload security, CSP/HSTS headers - V3: express-rate-limit updated (ip-address SSRF fix) - V4: postcss updated (nanoid DoS fix) - V5: Rate-limit on /health endpoint - V6: Session rotation on login (session fixation prevention) - V9: Task values array limit (DoS prevention) - V10: Frontend XSS audit completed - Docker: Multi-stage build, non-root user, PostgreSQL + backup service
This commit is contained in:
90
frontend/src/context/AuthContext.jsx
Normal file
90
frontend/src/context/AuthContext.jsx
Normal file
@@ -0,0 +1,90 @@
|
||||
import React, { createContext, useContext, useState, useCallback, useEffect } from 'react';
|
||||
import { API_BASE, setCSRFToken, getCSRFToken } from '../utils/api';
|
||||
|
||||
const AuthContext = createContext(null);
|
||||
|
||||
export function AuthProvider({ children }) {
|
||||
const [user, setUser] = useState(() => {
|
||||
try {
|
||||
const saved = localStorage.getItem('workflow_user');
|
||||
if (saved) return JSON.parse(saved);
|
||||
} catch (e) { /* ignore */ }
|
||||
return null;
|
||||
});
|
||||
const [loading, setLoading] = useState(true);
|
||||
|
||||
// Verify session on mount - P5: cookie-only auth (no token in localStorage)
|
||||
useEffect(() => {
|
||||
fetch(`${API_BASE}/auth/me`, { credentials: 'include' })
|
||||
.then(res => res.ok ? res.json() : Promise.reject())
|
||||
.then(data => { setUser(data); localStorage.setItem('workflow_user', JSON.stringify(data)); })
|
||||
.catch(() => {
|
||||
setUser(null);
|
||||
localStorage.removeItem('workflow_user');
|
||||
setCSRFToken(null);
|
||||
})
|
||||
.finally(() => setLoading(false));
|
||||
}, []);
|
||||
|
||||
const login = useCallback(async (email, password) => {
|
||||
const res = await fetch(`${API_BASE}/auth/login`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ email, password }),
|
||||
credentials: 'include', // P5: HttpOnly-Cookie only
|
||||
});
|
||||
const data = await res.json();
|
||||
if (!res.ok) throw new Error(data.error || 'Anmeldung fehlgeschlagen');
|
||||
setUser(data);
|
||||
localStorage.setItem('workflow_user', JSON.stringify(data));
|
||||
// P4: Store CSRF token in memory (returned from login response)
|
||||
if (data.csrfToken) setCSRFToken(data.csrfToken);
|
||||
return data;
|
||||
}, []);
|
||||
|
||||
const register = useCallback(async (email, password, name = '') => {
|
||||
const res = await fetch(`${API_BASE}/auth/register`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ email, password, name, role: 'user' }),
|
||||
credentials: 'include', // P5: HttpOnly-Cookie only
|
||||
});
|
||||
const data = await res.json();
|
||||
if (!res.ok) throw new Error(data.error || 'Registrierung fehlgeschlagen');
|
||||
setUser(data);
|
||||
localStorage.setItem('workflow_user', JSON.stringify(data));
|
||||
// P4: Store CSRF token in memory (returned from register response)
|
||||
if (data.csrfToken) setCSRFToken(data.csrfToken);
|
||||
return data;
|
||||
}, []);
|
||||
|
||||
const logout = useCallback(async () => {
|
||||
try {
|
||||
// Bug 2/4: Send CSRF token with logout request
|
||||
const csrf = getCSRFToken();
|
||||
await fetch(`${API_BASE}/auth/logout`, {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
...(csrf ? { 'x-csrf-token': csrf } : {}),
|
||||
},
|
||||
credentials: 'include',
|
||||
});
|
||||
} catch (e) { /* ignore */ }
|
||||
setUser(null);
|
||||
localStorage.removeItem('workflow_user');
|
||||
setCSRFToken(null);
|
||||
}, []);
|
||||
|
||||
return (
|
||||
<AuthContext.Provider value={{ user, login, register, logout, loading }}>
|
||||
{children}
|
||||
</AuthContext.Provider>
|
||||
);
|
||||
}
|
||||
|
||||
export function useAuth() {
|
||||
const ctx = useContext(AuthContext);
|
||||
if (!ctx) throw new Error('useAuth must be used within AuthProvider');
|
||||
return ctx;
|
||||
}
|
||||
Reference in New Issue
Block a user