@@ -384,6 +384,15 @@ async function findByUsername(username) {
|
||||
return { ...fromRow(r), passwordHash: r.PASSWORD };
|
||||
}
|
||||
|
||||
// ── Find by email (for central-auth SSO — the only identity it hands us) ──────
|
||||
async function findByEmail(email) {
|
||||
const rows = await exec(
|
||||
`SELECT * FROM ${TABLE} WHERE LOWER(EMAIL) = ? AND ACTIVE = 1`,
|
||||
[(email || '').trim().toLowerCase()]
|
||||
);
|
||||
return rows.length ? fromRow(rows[0]) : null;
|
||||
}
|
||||
|
||||
// ── List all users ────────────────────────────────────────────────────────────
|
||||
async function listUsers() {
|
||||
const rows = await exec(`SELECT * FROM ${TABLE} ORDER BY ROLE, USERNAME`);
|
||||
@@ -450,8 +459,17 @@ async function deleteUser(id) {
|
||||
|
||||
// ── Verify password ───────────────────────────────────────────────────────────
|
||||
async function verifyPassword(plaintext, hash) {
|
||||
// "md5:<hex>" = an account migrated from the old msale portal (unsalted
|
||||
// MD5, see scripts/migrate-msale.js). Accepted once; the login route
|
||||
// re-hashes it to bcrypt immediately on success (upgradeLegacyPassword).
|
||||
if (typeof hash === 'string' && hash.startsWith('md5:')) {
|
||||
return require('crypto').createHash('md5').update(String(plaintext)).digest('hex') === hash.slice(4).toLowerCase();
|
||||
}
|
||||
return bcrypt.compare(plaintext, hash);
|
||||
}
|
||||
async function upgradeLegacyPassword(id, plaintext, hash) {
|
||||
if (typeof hash === 'string' && hash.startsWith('md5:')) await updateUser(id, { password: plaintext });
|
||||
}
|
||||
|
||||
// ── Per-user SAP credentials ──────────────────────────────────────────────────
|
||||
// Set the current/given user's own SAP Service-Layer login. Password is
|
||||
@@ -534,12 +552,14 @@ module.exports = {
|
||||
bootstrap,
|
||||
createUser,
|
||||
findByUsername,
|
||||
findByEmail,
|
||||
listUsers,
|
||||
findById,
|
||||
updateUser,
|
||||
deleteUser,
|
||||
touchLastLogin,
|
||||
verifyPassword,
|
||||
upgradeLegacyPassword,
|
||||
setSapCredentials,
|
||||
getSapCredentials,
|
||||
getSapLoginMapRaw,
|
||||
|
||||
Reference in New Issue
Block a user