From 5400482b3a560d2a95ba9f93d84410ff2c61c66e Mon Sep 17 00:00:00 2001 From: Harshit Vashisht <120767685+HarshitVashisht11@users.noreply.github.com> Date: Thu, 26 Oct 2023 12:44:06 +0000 Subject: [PATCH 1/2] Updated Code --- apps/webapp/app/env.server.ts | 1 + apps/webapp/app/models/user.server.ts | 11 +++++++++++ 2 files changed, 12 insertions(+) diff --git a/apps/webapp/app/env.server.ts b/apps/webapp/app/env.server.ts index 4e229834c42..29674276f2d 100644 --- a/apps/webapp/app/env.server.ts +++ b/apps/webapp/app/env.server.ts @@ -11,6 +11,7 @@ const EnvironmentSchema = z.object({ MAGIC_LINK_SECRET: z.string(), ENCRYPTION_KEY: z.string(), REMIX_APP_PORT: z.string().optional(), + WHITELISTED_EMAILS: z.string().optional(), LOGIN_ORIGIN: z.string().default("http://localhost:3030"), APP_ORIGIN: z.string().default("http://localhost:3030"), APP_ENV: z diff --git a/apps/webapp/app/models/user.server.ts b/apps/webapp/app/models/user.server.ts index 31e8621edb4..8644ee5893a 100644 --- a/apps/webapp/app/models/user.server.ts +++ b/apps/webapp/app/models/user.server.ts @@ -1,6 +1,7 @@ import type { Prisma, User } from "@trigger.dev/database"; import type { GitHubProfile } from "remix-auth-github"; import { prisma } from "~/db.server"; +import { env } from "~/env.server"; export type { User } from "@trigger.dev/database"; type FindOrCreateMagicLink = { @@ -23,6 +24,16 @@ type LoggedInUser = { }; export async function findOrCreateUser(input: FindOrCreateUser): Promise { + if (env.WHITELISTED_EMAILS) { + // Create a regular expression from the whitelist pattern + const emailWhitelistRegex = new RegExp(env.WHITELISTED_EMAILS); + + // Check if the user's email matches the whitelist pattern + if (!emailWhitelistRegex.test(input.email)) { + // If the email is not in the whitelist, throw an error + throw new Error('Email address is not allowed.'); + } + } switch (input.authenticationMethod) { case "GITHUB": { return findOrCreateGithubUser(input); From 9d4f19b0087aa1219586e175685b5cca5beb34ff Mon Sep 17 00:00:00 2001 From: Harshit Vashisht <120767685+HarshitVashisht11@users.noreply.github.com> Date: Sat, 28 Oct 2023 06:35:02 +0000 Subject: [PATCH 2/2] Updated Code --- .env.example | 5 +++++ apps/webapp/app/models/user.server.ts | 25 ++++++++++++++++--------- apps/webapp/app/routes/magic.tsx | 2 +- 3 files changed, 22 insertions(+), 10 deletions(-) diff --git a/.env.example b/.env.example index 48170e8f365..25645d52092 100644 --- a/.env.example +++ b/.env.example @@ -24,6 +24,11 @@ NODE_ENV=development # FROM_EMAIL= # REPLY_TO_EMAIL= +# OPTIONAL VARIABLES +WHITELISTED_EMAILS="matt@gmail\.com|jane@yahoo\.com" +# Description: This environment variable defines a regex pattern for allowed email addresses. +# Only emails that match this pattern will be able to sign up or log in. + # CLOUD VARIABLES POSTHOG_PROJECT_KEY= PLAIN_API_KEY= diff --git a/apps/webapp/app/models/user.server.ts b/apps/webapp/app/models/user.server.ts index 8644ee5893a..42e250ebbee 100644 --- a/apps/webapp/app/models/user.server.ts +++ b/apps/webapp/app/models/user.server.ts @@ -2,8 +2,12 @@ import type { Prisma, User } from "@trigger.dev/database"; import type { GitHubProfile } from "remix-auth-github"; import { prisma } from "~/db.server"; import { env } from "~/env.server"; +import { authenticator } from "~/services/auth.server"; +import { addEmailLinkStrategy } from "~/services/emailAuth.server"; export type { User } from "@trigger.dev/database"; +addEmailLinkStrategy(authenticator); + type FindOrCreateMagicLink = { authenticationMethod: "MAGIC_LINK"; email: string; @@ -23,16 +27,11 @@ type LoggedInUser = { isNewUser: boolean; }; +class EmailWhitelistError extends Error {} + export async function findOrCreateUser(input: FindOrCreateUser): Promise { - if (env.WHITELISTED_EMAILS) { - // Create a regular expression from the whitelist pattern - const emailWhitelistRegex = new RegExp(env.WHITELISTED_EMAILS); - - // Check if the user's email matches the whitelist pattern - if (!emailWhitelistRegex.test(input.email)) { - // If the email is not in the whitelist, throw an error - throw new Error('Email address is not allowed.'); - } + if (!isEmailWhitelisted(input.email, env.WHITELISTED_EMAILS)) { + throw new EmailWhitelistError("Access to this instance is restricted."); } switch (input.authenticationMethod) { case "GITHUB": { @@ -189,3 +188,11 @@ export async function grantUserCloudAccess({ id, inviteCode }: { id: string; inv }, }); } + +function isEmailWhitelisted(email: string, whitelist: string | undefined) { + if (whitelist) { + const regex = new RegExp(whitelist); + return regex.test(email); + } + return true; // No whitelist means all emails are allowed +} \ No newline at end of file diff --git a/apps/webapp/app/routes/magic.tsx b/apps/webapp/app/routes/magic.tsx index 6a65b5cc9d2..d137cbf9137 100644 --- a/apps/webapp/app/routes/magic.tsx +++ b/apps/webapp/app/routes/magic.tsx @@ -7,6 +7,6 @@ export async function loader({ request }: LoaderArgs) { await authenticator.authenticate("email-link", request, { successRedirect: redirectTo ?? "/", - failureRedirect: "/login", + failureRedirect: "/login/magic", }); }