fix(auth): move the BankID flow into a signed, user-gated, single-use cookie (#1625)

* fix(auth): move the BankID flow into a signed, single-use, confirm-on-resume cookie

A user's BankID signup identified successfully four times and created no
account. His screenshots show four tabs, one on the finished "Verifierad med
BankID, ange e-post" step, and the tab he was looking at showing the idle
button. Prod agreed: no bankid_identities row, no auth.users row.

On iOS outside plain Safari the BankID return URL is handed to the OS, which
opens a NEW tab. The session lived in per-tab sessionStorage, so that tab
started empty and rendered the start button while the completed flow sat
stranded. Login hid it (self-finishing, cookie-backed session); signup waits
for a human to type an e-mail into the stranded tab, so it dies there.

The session id is no longer handed to the browser. It lives in a signed
__Host- HttpOnly cookie set at /start; /poll, /complete, /link and /cancel
read it. Cookies are shared by every tab of the origin, which is what the
handoff needed. The id had to leave the client because it is an
unauthenticated bearer credential: /poll was skipAuth and returned
user.personalNumber, and /complete with mode 'login' returns a tokenHash that
verifyOtp turns into a session, MFA skipped for bankid_linked accounts.

A completed identification must never be consumed by whoever merely opens the
page. A shared cookie plus a shared machine means the tab that finds a
completed flow cannot prove the person at it is the one who made it, and no
client-side token can prove otherwise: nothing survives an iOS same-tab reload
yet dies on reopen-closed-tab / session restore / tab duplication. So a resume
is never automatic. The mount probe routes any found live flow to a confirm
card ("Fortsätt bara om det var du") that reveals no name, and only that click
polls and consumes. Auto-consume happens only inside the live component
instance that called startSession (desktop QR; the pre-navigation mobile
launch), which by construction is the originator. Cost: one tap after
returning from the BankID app on iOS, exactly where the reported bug lives;
desktop and Android never hit the resume path.

The rest is defence the four review rounds proved load-bearing:
- __Host- with Path=/ and unconditional Secure, so a script cannot plant the
  same name at a longer path; readBankIdFlow fails closed on duplicates and on
  a malformed percent-escape.
- Single-use is a unique index (bankid_consumed_sessions), claimed before
  generateLink, not a Set-Cookie. Fail-closed on any non-23505 error, so the
  migration MUST be applied before the code.
- A link flow requires auth at /start and pins userId; /link rejects a flow
  owned by anyone else, before any TIC call. mode is pinned and /poll rejects a
  body mode that does not match, so a login session cannot finish through the
  signup panel. /poll withholds the holder name from a probe. The 900s
  verified-step window is capped by MAX_TOTAL_LIFE from a signed startedAt.
  /poll never clears the cookie (an untargeted Set-Cookie would delete a newer
  flow); only /cancel and terminal /complete + /link exits clear. Avbryt holds
  a 'cancelling' state until /cancel resolves so a new /start cannot race the
  clear. Session id is logged only as an 8-char prefix.

The launch is untouched: iOS keeps its return URL, Android keeps redirect=null
(#194 closed that path deliberately).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(auth): bind BankID actions to the resumed flow

* docs: record BankID staging migration drift

* fix(auth): address BankID PR review

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-08-15 23:07:29 +02:00
committed by GitHub
co-authored by Claude Opus 5
parent 2deea05d42
commit edfdbe2d2a
13 changed files with 2294 additions and 227 deletions
@@ -15,11 +15,52 @@ vi.mock('@/lib/supabase/server', () => ({
createClient: vi.fn(),
}))
import { collectBankIdResult, requestEnrichment, fetchEnrichmentData } from '../lib/bankid-client'
import {
cancelBankIdSession,
collectBankIdResult,
pollBankIdSession,
requestEnrichment,
fetchEnrichmentData,
startBankIdAuth,
} from '../lib/bankid-client'
import { createServiceClient } from '@/lib/supabase/server'
import { ticExtension } from '../index'
import {
BANKID_FLOW_COOKIE,
BANKID_FLOW_ID_HEADER,
signBankIdFlow,
verifyBankIdFlow,
type BankIdFlowMode,
} from '../lib/bankid-flow-cookie'
const TEST_KEY = 'a'.repeat(64)
const TEST_FLOW_ID = 'flow-1'
/**
* The session id and the mode now arrive in a signed HttpOnly cookie rather
* than the request body, so nothing a caller can name decides which session
* gets completed, or as which kind of flow.
*/
async function flowCookie(
mode: BankIdFlowMode,
sessionId = 'test-session',
userId = 'user-1',
): Promise<Record<string, string>> {
const value = await signBankIdFlow({
version: 1,
sessionId,
flowId: TEST_FLOW_ID,
mode,
// A link flow is owned by the user who opened it; login/signup have none.
userId: mode === 'link' ? userId : undefined,
startedAt: Date.now(),
expiresAt: Date.now() + 60_000,
})
return {
cookie: `${BANKID_FLOW_COOKIE}=${encodeURIComponent(value)}`,
[BANKID_FLOW_ID_HEADER]: TEST_FLOW_ID,
}
}
function findCompleteHandler() {
const route = ticExtension.apiRoutes!.find(
@@ -45,7 +86,14 @@ function makeSession(overrides: Partial<{ status: string; user: unknown }> = {})
type QueuedResult = { data?: unknown; error?: unknown }
function mockServiceClient(fromResults: QueuedResult[]) {
function mockServiceClient(
fromResults: QueuedResult[],
// The single-use claim against bankid_consumed_sessions. Routed by table name
// rather than taken from the queue, so each test's queue keeps describing
// only the lookups it cares about. `{ error: { code: '23505' } }` is the
// other tab having claimed the session first.
consumed: QueuedResult = { error: null },
) {
const queue = [...fromResults]
const chain = (): unknown => {
@@ -82,7 +130,9 @@ function mockServiceClient(fromResults: QueuedResult[]) {
}
const client = {
from: vi.fn().mockImplementation(() => chain()),
from: vi.fn().mockImplementation((table: string) =>
table === 'bankid_consumed_sessions' ? chain2(consumed) : chain()
),
auth: { admin },
}
@@ -117,7 +167,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'victim@example.com' },
headers: await flowCookie('signup'),
body: { email: 'victim@example.com' },
})
const { status, body } = await parseJsonResponse<{ error?: string; data?: unknown }>(
await findCompleteHandler()(req)
@@ -149,7 +200,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'fresh@example.com' },
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
@@ -171,7 +223,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'fresh@example.com' },
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
const { status, body } = await parseJsonResponse<{
data?: { tokenHash?: string; type?: string; isNewUser?: boolean }
@@ -203,7 +256,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'x@example.com' },
headers: await flowCookie('signup'),
body: { email: 'x@example.com' },
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
@@ -217,7 +271,7 @@ describe('POST /bankid/complete', () => {
})
})
describe('signup mode — rollback on partial failure', () => {
describe('signup mode: rollback on partial failure', () => {
// A half-created account strands the user: retrying signup hits
// account_exists/already_linked, but the account only has a random
// password they never saw. Every failure after createUser must delete
@@ -232,7 +286,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'fresh@example.com' },
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
@@ -258,7 +313,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'fresh@example.com' },
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
@@ -281,7 +337,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'fresh@example.com' },
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
@@ -302,7 +359,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'fresh@example.com' },
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
const { status } = await parseJsonResponse(await findCompleteHandler()(req))
@@ -320,7 +378,7 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'login' },
headers: await flowCookie('login'),
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
@@ -395,7 +453,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'fresh@example.com' },
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
const { status, body } = await parseJsonResponse<{
data?: { tokenHash?: string; isNewUser?: boolean }
@@ -434,7 +493,8 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup', email: 'x@example.com' },
headers: await flowCookie('signup'),
body: { email: 'x@example.com' },
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
@@ -449,7 +509,7 @@ describe('POST /bankid/complete', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'test-session', mode: 'signup' },
headers: await flowCookie('signup'),
})
const { status } = await parseJsonResponse(await findCompleteHandler()(req))
@@ -458,4 +518,516 @@ describe('POST /bankid/complete', () => {
expect(collectBankIdResult).not.toHaveBeenCalled()
})
})
describe('the flow cookie is the only thing that names a session', () => {
/** Did the handler expire the flow cookie on this response? */
function clearedFlow(response: Response): boolean {
return response.headers
.getSetCookie()
.some((c) => c.startsWith(`${BANKID_FLOW_COOKIE}=`) && /Max-Age=0/i.test(c))
}
it('refuses completion from a stale tab after the shared cookie was replaced', async () => {
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
mockServiceClient([])
const headers = await flowCookie('signup')
headers[BANKID_FLOW_ID_HEADER] = 'older-flow'
const { status } = await parseJsonResponse(
await findCompleteHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
headers,
body: { email: 'fresh@example.com' },
})
)
)
expect(status).toBe(400)
expect(collectBankIdResult).not.toHaveBeenCalled()
})
it('ignores a sessionId and mode supplied in the body', async () => {
// The old contract took both from the body, which made /complete a
// bearer endpoint: anyone who had seen a session id could complete it,
// in whatever mode suited them.
mockServiceClient([])
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
body: { sessionId: 'attacker-session', mode: 'login' },
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
)
expect(status).toBe(400)
expect(body.error).toBe('session_invalid')
expect(collectBankIdResult).not.toHaveBeenCalled()
})
it('refuses to complete a session that was opened as a link flow', async () => {
// Linking happens on the authenticated /bankid/link route. Completing a
// link session here would create or sign in an account off a session
// opened for something else entirely.
mockServiceClient([])
const req = createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
headers: await flowCookie('link'),
body: { email: 'attacker@example.com' },
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(req)
)
expect(status).toBe(400)
expect(body.error).toBe('session_invalid')
expect(collectBankIdResult).not.toHaveBeenCalled()
})
it('spends the flow on success, so a second tab cannot mint a rival magic link', async () => {
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const { admin } = mockServiceClient([
{ data: null }, // pnr lookup → not linked
{ error: null }, // bankid_identities insert OK
])
const response = await findCompleteHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
)
expect(response.status).toBe(200)
expect(admin.generateLink).toHaveBeenCalled()
// Without this, two tabs that both saw 'complete' would each mint a
// magic link and the second would invalidate the first.
expect(clearedFlow(response)).toBe(true)
})
it('refuses a login whose session another tab already spent', async () => {
// The Set-Cookie clear does NOT make this single-use: two requests that
// both already carried the cookie both reach here. The unique index on
// bankid_consumed_sessions is what stops the second from minting a rival
// magic link that would invalidate the first tab's.
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const { admin } = mockServiceClient(
[{ data: { user_id: 'existing-user' } }], // pnr is linked
{ error: { code: '23505', message: 'duplicate key' } },
)
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findCompleteHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
headers: await flowCookie('login'),
})
)
)
expect(status).toBe(400)
expect(body.error).toBe('session_invalid')
expect(admin.generateLink).not.toHaveBeenCalled()
})
it('rolls the new account back when a signup loses the same race', async () => {
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const { admin } = mockServiceClient(
[{ data: null }, { error: null }],
{ error: { code: '23505', message: 'duplicate key' } },
)
const { status } = await parseJsonResponse(
await findCompleteHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
headers: await flowCookie('signup'),
body: { email: 'fresh@example.com' },
})
)
)
expect(status).toBe(400)
expect(admin.generateLink).not.toHaveBeenCalled()
// A half-created account would strand the address: the retry would hit
// account_exists on an account whose password the user never saw.
expect(admin.deleteUser).toHaveBeenCalledWith('new-user-uuid')
})
it('fails closed when the single-use claim errors for any other reason', async () => {
// Minting a second magic link is worse than asking the user to
// authenticate again, so an unreachable table must not be waved through.
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const { admin } = mockServiceClient(
[{ data: { user_id: 'existing-user' } }],
{ error: { code: '42P01', message: 'relation does not exist' } },
)
const { status } = await parseJsonResponse(
await findCompleteHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
headers: await flowCookie('login'),
})
)
)
expect(status).toBe(400)
expect(admin.generateLink).not.toHaveBeenCalled()
})
it('keeps the flow alive when the e-mail is already taken, so it can be corrected', async () => {
// account_exists consumes nothing and is usually a typo: forcing a
// second BankID round trip to fix an address would be gratuitous.
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const { admin } = mockServiceClient([{ data: null }])
admin.createUser.mockResolvedValueOnce({
data: { user: null },
error: { status: 422, code: 'email_exists', message: 'already registered' },
} as never)
const response = await findCompleteHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/complete', {
method: 'POST',
headers: await flowCookie('signup'),
body: { email: 'taken@example.com' },
})
)
expect(response.status).toBe(409)
expect(clearedFlow(response)).toBe(false)
})
})
})
describe('POST /bankid/start', () => {
function findStartHandler() {
const route = ticExtension.apiRoutes!.find(
(r) => r.method === 'POST' && r.path === '/bankid/start'
)
if (!route) throw new Error('POST /bankid/start route not found')
return route.handler
}
it('rejects a request that does not name a flow', async () => {
const { status } = await parseJsonResponse(
await findStartHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/start', {
method: 'POST',
body: { mode: 'admin' },
})
)
)
expect(status).toBe(400)
expect(startBankIdAuth).not.toHaveBeenCalled()
})
it('withholds the session id from the response and puts it in the cookie', async () => {
vi.mocked(startBankIdAuth).mockResolvedValue({
sessionId: 'secret-session',
autoStartToken: 'ast',
qrStartToken: 'qrt',
qrStartSecret: 'qrs',
} as never)
const response = await findStartHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/start', {
method: 'POST',
body: { mode: 'signup' },
})
)
const payload = await response.clone().text()
const parsed = JSON.parse(payload) as { data: { flowId: string } }
// The id is a bearer credential for a personnummer and for a session.
// The browser gets the autostart/QR tokens, which identify nobody.
expect(payload).not.toContain('secret-session')
expect(payload).toContain('ast')
expect(parsed.data.flowId).toBeTruthy()
const flowCookieHeader = response.headers
.getSetCookie()
.find((c) => c.startsWith(`${BANKID_FLOW_COOKIE}=`))
expect(flowCookieHeader).toMatch(/HttpOnly/i)
const [, value] = /^[^=]+=([^;]*)/.exec(flowCookieHeader!)!
const flow = await verifyBankIdFlow(decodeURIComponent(value))
expect(flow).toMatchObject({
sessionId: 'secret-session',
mode: 'signup',
})
expect(flow?.flowId).toBe(parsed.data.flowId)
})
})
describe('POST /bankid/poll', () => {
function findPollHandler() {
const route = ticExtension.apiRoutes!.find(
(r) => r.method === 'POST' && r.path === '/bankid/poll'
)
if (!route) throw new Error('POST /bankid/poll route not found')
return route.handler
}
it('answers 404 when the browser holds no flow, instead of polling a named session', async () => {
const { status } = await parseJsonResponse(
await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
body: { sessionId: 'attacker-session' },
})
)
)
expect(status).toBe(404)
expect(pollBankIdSession).not.toHaveBeenCalled()
})
it('never returns the personnummer', async () => {
// This route is skipAuth, so whatever it returns is readable by whoever
// holds the flow cookie. The UI only ever needed the names.
vi.mocked(pollBankIdSession).mockResolvedValue({
status: 'complete',
user: {
personalNumber: '199001011234',
givenName: 'Anna',
surname: 'Andersson',
name: 'Anna Andersson',
},
} as never)
const response = await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
headers: await flowCookie('signup'),
body: { mode: 'signup' },
})
)
const payload = await response.clone().text()
const { body } = await parseJsonResponse<{ data: { user?: Record<string, unknown> } }>(response)
expect(payload).not.toContain('199001011234')
expect(body.data.user).toEqual({ givenName: 'Anna', surname: 'Andersson' })
})
it('withholds the holder name from a probe, but gives it to the active poll', async () => {
// The mount probe runs before the person here has confirmed the flow is
// theirs, so the name must not reach them (it would identify a stranger on
// a shared machine). The active poll, reached only after ownership/confirm,
// needs the name for the signup e-mail step.
vi.mocked(pollBankIdSession).mockResolvedValue({
status: 'complete',
user: { givenName: 'Anna', surname: 'Andersson', personalNumber: 'x' },
} as never)
const probe = await parseJsonResponse<{ data: { flowId?: string; user?: unknown } }>(
await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
headers: await flowCookie('signup'),
body: { mode: 'signup', probe: true },
})
)
)
expect(probe.body.data.flowId).toBe(TEST_FLOW_ID)
expect(probe.body.data.user).toBeUndefined()
const active = await parseJsonResponse<{ data: { user?: unknown } }>(
await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
headers: await flowCookie('signup'),
body: { mode: 'signup' },
})
)
)
expect(active.body.data.user).toEqual({ givenName: 'Anna', surname: 'Andersson' })
})
it('refuses to poll a flow whose mode does not match the panel asking', async () => {
// A login session started on /login must not be pollable by the signup
// panel: the client would render the signup e-mail step and /complete
// would then read mode 'login' off the cookie, either signing the user in
// from the "Skapa konto" form or burning the identification on no_account.
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
headers: await flowCookie('login'),
body: { mode: 'signup' },
})
)
)
expect(status).toBe(404)
expect(body.error).toBe('no_session')
expect(pollBankIdSession).not.toHaveBeenCalled()
})
it('polls when both the panel mode and tab flow id match', async () => {
vi.mocked(pollBankIdSession).mockResolvedValue({ status: 'pending' } as never)
const { status } = await parseJsonResponse(
await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
headers: await flowCookie('signup'),
body: { mode: 'signup' },
})
)
)
expect(status).toBe(200)
expect(pollBankIdSession).toHaveBeenCalledOnce()
})
it('refuses a stale tab after a newer same-mode flow replaced the shared cookie', async () => {
vi.mocked(pollBankIdSession).mockResolvedValue({ status: 'complete' } as never)
const headers = await flowCookie('signup')
headers[BANKID_FLOW_ID_HEADER] = 'older-flow'
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
headers,
body: { mode: 'signup' },
})
)
)
expect(status).toBe(404)
expect(body.error).toBe('no_session')
expect(pollBankIdSession).not.toHaveBeenCalled()
})
it('does NOT clear the cookie when TIC has forgotten the session', async () => {
// A clearing Set-Cookie cannot be aimed at one flow, so a slow response
// about a dead session would delete whatever flow is in the jar by the
// time it lands, including one the user just started in another tab.
const { TICAPIError } = await import('../lib/tic-types')
vi.mocked(pollBankIdSession).mockRejectedValueOnce(
new TICAPIError('gone', 404)
)
const response = await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
headers: await flowCookie('login'),
body: { mode: 'login' },
})
)
const { status, body } = await parseJsonResponse<{ error?: string }>(response)
expect(status).toBe(404)
expect(body.error).toBe('no_session')
const cleared = response.headers
.getSetCookie()
.some((c) => c.startsWith(`${BANKID_FLOW_COOKIE}=`) && /Max-Age=0/i.test(c))
expect(cleared).toBe(false)
})
it('extends the window to the verified budget once identification completes', async () => {
// The signup e-mail step is a person typing; the order window (300s) is
// too short for it, so completion re-issues at the longer budget.
vi.mocked(pollBankIdSession).mockResolvedValue({
status: 'complete',
user: { givenName: 'Anna', surname: 'Andersson', personalNumber: 'x' },
} as never)
const response = await findPollHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/poll', {
method: 'POST',
headers: await flowCookie('signup'),
body: { mode: 'signup' },
})
)
// A fresh signed cookie is issued (Max-Age well past the 300s order window).
const reissued = response.headers
.getSetCookie()
.find((c) => c.startsWith(`${BANKID_FLOW_COOKIE}=`))
expect(reissued).toBeDefined()
const maxAge = Number(/Max-Age=(\d+)/i.exec(reissued!)?.[1])
expect(maxAge).toBeGreaterThan(300)
})
})
describe('POST /bankid/cancel', () => {
function findCancelHandler() {
const route = ticExtension.apiRoutes!.find(
(r) => r.method === 'POST' && r.path === '/bankid/cancel'
)
if (!route) throw new Error('POST /bankid/cancel route not found')
return route.handler
}
function clearsFlow(response: Response): boolean {
return response.headers
.getSetCookie()
.some((c) => c.startsWith(`${BANKID_FLOW_COOKIE}=`) && /Max-Age=0/i.test(c))
}
it('cancels the flow this browser holds, with no id to aim it', async () => {
const response = await findCancelHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/cancel', {
method: 'POST',
headers: await flowCookie('signup'),
// A named session in the body must be ignored: the old DELETE route
// took one, which let a caller cancel a session they merely knew of.
body: { sessionId: 'someone-elses-session' },
})
)
expect(response.status).toBe(200)
expect(clearsFlow(response)).toBe(true)
expect(cancelBankIdSession).toHaveBeenCalledWith('test-session')
})
it('still clears the cookie when TIC cannot be reached', async () => {
// Otherwise pressing Avbryt during a TIC outage leaves a flow in the
// browser that the next page load resumes.
vi.mocked(cancelBankIdSession).mockRejectedValueOnce(new Error('network down'))
const response = await findCancelHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/cancel', {
method: 'POST',
headers: await flowCookie('signup'),
})
)
expect(response.status).toBe(200)
expect(clearsFlow(response)).toBe(true)
})
it('does not cancel or clear a newer flow from a stale tab', async () => {
const headers = await flowCookie('signup')
headers[BANKID_FLOW_ID_HEADER] = 'older-flow'
const response = await findCancelHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/cancel', {
method: 'POST',
headers,
})
)
const { body } = await parseJsonResponse<{
data?: { cancelled?: boolean; replaced?: boolean }
}>(response.clone())
expect(response.status).toBe(200)
expect(body.data).toEqual({ cancelled: false, replaced: true })
expect(clearsFlow(response)).toBe(false)
expect(cancelBankIdSession).not.toHaveBeenCalled()
})
it('is a no-op that still succeeds when there is no flow', async () => {
const response = await findCancelHandler()(
createMockRequest('/api/extensions/ext/tic/bankid/cancel', { method: 'POST' })
)
expect(response.status).toBe(200)
expect(cancelBankIdSession).not.toHaveBeenCalled()
})
})
@@ -0,0 +1,268 @@
import { describe, it, expect, vi, beforeEach, afterEach } from 'vitest'
import { NextResponse } from 'next/server'
import {
BANKID_FLOW_COOKIE,
FLOW_VERIFIED_WINDOW_SECONDS,
FLOW_WINDOW_SECONDS,
clearBankIdFlowCookies,
isBankIdFlowMode,
readBankIdFlow,
setBankIdFlowCookies,
signBankIdFlow,
verifyBankIdFlow,
type BankIdFlowState,
} from '../lib/bankid-flow-cookie'
const TEST_KEY = 'a'.repeat(64)
const T0 = 1_700_000_000_000
const STATE: BankIdFlowState = {
version: 1,
sessionId: 'sess-1',
flowId: 'flow-1',
mode: 'signup',
startedAt: T0,
expiresAt: T0 + FLOW_WINDOW_SECONDS * 1000,
}
beforeEach(() => {
vi.stubEnv('BANKID_ENCRYPTION_KEY', TEST_KEY)
})
afterEach(() => {
vi.unstubAllEnvs()
})
/** Parse the Set-Cookie headers a handler attached to its response. */
function setCookies(response: NextResponse): Map<string, { value: string; attrs: string }> {
const result = new Map<string, { value: string; attrs: string }>()
for (const header of response.headers.getSetCookie()) {
const [pair, ...attrs] = header.split(';')
const separator = pair.indexOf('=')
result.set(pair.slice(0, separator).trim(), {
value: decodeURIComponent(pair.slice(separator + 1)),
attrs: attrs.join(';'),
})
}
return result
}
function cookieHeader(value: string, name = BANKID_FLOW_COOKIE): Request {
return new Request('http://localhost:3000/x', {
headers: { cookie: `${name}=${encodeURIComponent(value)}` },
})
}
describe('sign / verify', () => {
it('round-trips a flow', async () => {
const signed = await signBankIdFlow(STATE)
expect(await verifyBankIdFlow(signed, process.env, T0 + 1000)).toEqual(STATE)
})
it('carries the owner of a link flow', async () => {
const link: BankIdFlowState = { ...STATE, mode: 'link', userId: 'user-1' }
expect(await verifyBankIdFlow(await signBankIdFlow(link), process.env, T0)).toEqual(link)
})
it('rejects a link flow with no owner', async () => {
// An unowned link flow is the shape that binds one person's personnummer
// to the next person to use a shared browser.
const signed = await signBankIdFlow({ ...STATE, mode: 'link' })
expect(await verifyBankIdFlow(signed, process.env, T0)).toBeNull()
})
it('does not put the session id in the clear', async () => {
const signed = await signBankIdFlow(STATE)
expect(signed).not.toContain('sess-1')
expect(signed.split('.')).toHaveLength(2)
})
it('rejects a tampered payload', async () => {
const signed = await signBankIdFlow(STATE)
const [, signature] = signed.split('.')
const forged = Buffer.from(
JSON.stringify({ ...STATE, sessionId: 'attacker-session' }),
).toString('base64url')
expect(await verifyBankIdFlow(`${forged}.${signature}`, process.env, T0)).toBeNull()
})
it('rejects an unsigned cookie a script could plant', async () => {
const payload = Buffer.from(JSON.stringify(STATE)).toString('base64url')
expect(await verifyBankIdFlow(payload, process.env, T0)).toBeNull()
expect(await verifyBankIdFlow(`${payload}.`, process.env, T0)).toBeNull()
expect(await verifyBankIdFlow(`${payload}.x`, process.env, T0)).toBeNull()
})
it('rejects a cookie signed with a different secret', async () => {
const signed = await signBankIdFlow(STATE, { BANKID_ENCRYPTION_KEY: 'b'.repeat(64) })
expect(await verifyBankIdFlow(signed, process.env, T0)).toBeNull()
})
it('rejects malformed and empty values', async () => {
expect(await verifyBankIdFlow(undefined, process.env, T0)).toBeNull()
expect(await verifyBankIdFlow('', process.env, T0)).toBeNull()
expect(await verifyBankIdFlow('not.a.cookie', process.env, T0)).toBeNull()
expect(await verifyBankIdFlow('....', process.env, T0)).toBeNull()
})
it('expires on the server clock, not the browser Max-Age', async () => {
const signed = await signBankIdFlow(STATE)
expect(await verifyBankIdFlow(signed, process.env, STATE.expiresAt)).toEqual(STATE)
expect(await verifyBankIdFlow(signed, process.env, STATE.expiresAt + 1)).toBeNull()
})
it('refuses an expiry further out than the longest window this server issues', async () => {
const signed = await signBankIdFlow({ ...STATE, expiresAt: T0 + 24 * 3600 * 1000 })
expect(await verifyBankIdFlow(signed, process.env, T0)).toBeNull()
})
it('accepts the verified window, which the e-mail step needs', async () => {
const verified = { ...STATE, expiresAt: T0 + FLOW_VERIFIED_WINDOW_SECONDS * 1000 }
expect(await verifyBankIdFlow(await signBankIdFlow(verified), process.env, T0)).toEqual(verified)
})
it('caps the whole flow from startedAt, so re-issuing cannot extend it forever', async () => {
// /poll pushes expiresAt out when it sees a completed identification.
// Without a cap measured from the original start, polling in a loop would
// keep a usable identification alive for as long as TIC retains it.
// MAX_TOTAL_LIFE is FLOW_WINDOW + FLOW_VERIFIED_WINDOW from startedAt.
const cap = (FLOW_WINDOW_SECONDS + FLOW_VERIFIED_WINDOW_SECONDS) * 1000
// A cookie re-issued near the cap is still honoured up to it...
const late = { ...STATE, expiresAt: T0 + cap + 60_000 }
const signed = await signBankIdFlow(late)
expect(await verifyBankIdFlow(signed, process.env, T0 + cap)).toEqual(late)
// ...and dies the moment the flow as a whole is older than the cap, no
// matter how far out the latest re-issue pushed expiresAt.
expect(await verifyBankIdFlow(signed, process.env, T0 + cap + 1)).toBeNull()
})
it('rejects a startedAt in the future, which would never age out', async () => {
const signed = await signBankIdFlow({ ...STATE, startedAt: T0 + 60_000 })
expect(await verifyBankIdFlow(signed, process.env, T0)).toBeNull()
})
it('rejects an unknown mode', async () => {
const signed = await signBankIdFlow({ ...STATE, mode: 'admin' as never })
expect(await verifyBankIdFlow(signed, process.env, T0)).toBeNull()
})
it('rejects a flow with no tab-binding id', async () => {
const signed = await signBankIdFlow({ ...STATE, flowId: undefined as never })
expect(await verifyBankIdFlow(signed, process.env, T0)).toBeNull()
})
it('rejects an unknown version, so a future format cannot be replayed as this one', async () => {
const signed = await signBankIdFlow({ ...STATE, version: 2 as never })
expect(await verifyBankIdFlow(signed, process.env, T0)).toBeNull()
})
it('refuses to run without a signing secret rather than falling back to unsigned', async () => {
const empty = {}
await expect(signBankIdFlow(STATE, empty)).rejects.toThrow(/requires BANKID_ENCRYPTION_KEY/)
expect(await verifyBankIdFlow(await signBankIdFlow(STATE), empty, T0)).toBeNull()
})
})
describe('isBankIdFlowMode', () => {
it('accepts exactly the three flows', () => {
expect(isBankIdFlowMode('login')).toBe(true)
expect(isBankIdFlowMode('signup')).toBe(true)
expect(isBankIdFlowMode('link')).toBe(true)
expect(isBankIdFlowMode('unlink')).toBe(false)
expect(isBankIdFlowMode('')).toBe(false)
expect(isBankIdFlowMode(undefined)).toBe(false)
})
})
describe('readBankIdFlow', () => {
it('reads its own cookie out of a header carrying others', async () => {
const signed = await signBankIdFlow({ ...STATE, startedAt: Date.now(), expiresAt: Date.now() + 60_000 })
const request = new Request('http://localhost:3000/x', {
headers: {
cookie: `sb-access-token=abc; ${BANKID_FLOW_COOKIE}=${encodeURIComponent(signed)}; other=1`,
},
})
expect((await readBankIdFlow(request))?.sessionId).toBe('sess-1')
})
it('fails closed when two cookies of this name arrive', async () => {
// The shadowing attack: a script plants the same name at a longer path, and
// RFC 6265 sends longer paths FIRST. Taking the first match would use the
// planted one. The __Host- prefix should make this unreachable; being wrong
// about that must not silently hand the flow to the attacker's cookie.
const mine = await signBankIdFlow({ ...STATE, startedAt: Date.now(), expiresAt: Date.now() + 60_000 })
const planted = await signBankIdFlow({
...STATE,
sessionId: 'attacker-session',
startedAt: Date.now(),
expiresAt: Date.now() + 60_000,
})
const request = new Request('http://localhost:3000/x', {
headers: {
cookie:
`${BANKID_FLOW_COOKIE}=${encodeURIComponent(planted)}; ` +
`${BANKID_FLOW_COOKIE}=${encodeURIComponent(mine)}`,
},
})
expect(await readBankIdFlow(request)).toBeNull()
})
it('returns null with no cookie header and for a foreign cookie name', async () => {
expect(await readBankIdFlow(new Request('http://localhost:3000/x'))).toBeNull()
const signed = await signBankIdFlow({ ...STATE, startedAt: Date.now(), expiresAt: Date.now() + 60_000 })
expect(await readBankIdFlow(cookieHeader(signed, 'accounted-bankid-active'))).toBeNull()
})
})
describe('cookie attributes', () => {
it('is a __Host- cookie: HttpOnly, Secure, Lax, Path=/, no Domain', async () => {
const response = NextResponse.json({})
const expiresAt = Date.now() + FLOW_WINDOW_SECONDS * 1000
await setBankIdFlowCookies(response, { ...STATE, startedAt: Date.now(), expiresAt })
const flow = setCookies(response).get(BANKID_FLOW_COOKIE)!
expect(BANKID_FLOW_COOKIE.startsWith('__Host-')).toBe(true)
expect(flow.attrs).toMatch(/HttpOnly/i)
// Unconditional: __Host- requires it, and BankID is disabled on self-hosted
// so there is no plain-http deployment to accommodate.
expect(flow.attrs).toMatch(/Secure/i)
expect(flow.attrs).toMatch(/Path=\/(;|$)/i)
expect(flow.attrs).not.toMatch(/Domain=/i)
// Lax, not Strict: the BankID app returns the user by a top-level
// navigation from outside the site, and Strict would drop the cookie there.
expect(flow.attrs).toMatch(/SameSite=lax/i)
expect(flow.attrs).not.toMatch(/SameSite=strict/i)
})
it('mirrors the signed expiry in Max-Age', async () => {
const response = NextResponse.json({})
const now = Date.now()
await setBankIdFlowCookies(response, { ...STATE, startedAt: now, expiresAt: now + 120_000 }, process.env, now)
expect(setCookies(response).get(BANKID_FLOW_COOKIE)!.attrs).toMatch(/Max-Age=120/i)
})
it('never emits a non-positive Max-Age for an almost-expired flow', async () => {
// Max-Age=0 would mean "delete", which would drop a flow that is still
// valid for a few hundred milliseconds.
const response = NextResponse.json({})
const now = Date.now()
await setBankIdFlowCookies(response, { ...STATE, startedAt: now, expiresAt: now + 100 }, process.env, now)
expect(setCookies(response).get(BANKID_FLOW_COOKIE)!.attrs).toMatch(/Max-Age=1(;|$)/i)
})
it('clears with the same name and attributes it set', () => {
const response = NextResponse.json({})
clearBankIdFlowCookies(response)
const flow = setCookies(response).get(BANKID_FLOW_COOKIE)!
// A deletion that differs on path or attributes leaves the real cookie.
expect(flow.attrs).toMatch(/Path=\/(;|$)/i)
expect(flow.attrs).toMatch(/HttpOnly/i)
expect(flow.attrs).toMatch(/Secure/i)
expect(flow.attrs).toMatch(/Max-Age=0/i)
})
})
@@ -24,8 +24,37 @@ import { collectBankIdResult } from '../lib/bankid-client'
import { createServiceClient } from '@/lib/supabase/server'
import { requireAuth } from '@/lib/auth/require-auth'
import { ticExtension } from '../index'
import {
BANKID_FLOW_COOKIE,
BANKID_FLOW_ID_HEADER,
signBankIdFlow,
type BankIdFlowMode,
} from '../lib/bankid-flow-cookie'
const TEST_KEY = 'a'.repeat(64)
const TEST_FLOW_ID = 'flow-1'
/** Linking reads its session from the signed flow cookie, not the body. */
async function flowCookie(
mode: BankIdFlowMode,
sessionId = 'test-session',
userId = 'user-1',
): Promise<Record<string, string>> {
const value = await signBankIdFlow({
version: 1,
sessionId,
flowId: TEST_FLOW_ID,
mode,
// A link flow is owned by the user who opened it; login/signup have none.
userId: mode === 'link' ? userId : undefined,
startedAt: Date.now(),
expiresAt: Date.now() + 60_000,
})
return {
cookie: `${BANKID_FLOW_COOKIE}=${encodeURIComponent(value)}`,
[BANKID_FLOW_ID_HEADER]: TEST_FLOW_ID,
}
}
function findRoute(method: string, path: string) {
const route = ticExtension.apiRoutes!.find((r) => r.method === method && r.path === path)
@@ -56,7 +85,12 @@ function mockUnauthenticated() {
type QueuedResult = { data?: unknown; error?: unknown }
/** Minimal chainable service-client mock (same pattern as bankid-complete.test.ts). */
function mockServiceClient(fromResults: QueuedResult[], appMetadata: Record<string, unknown>) {
function mockServiceClient(
fromResults: QueuedResult[],
appMetadata: Record<string, unknown>,
// Single-use claim; `{ error: { code: '23505' } }` means another tab won.
consumed: QueuedResult = { error: null },
) {
const queue = [...fromResults]
const chain = (): unknown => {
@@ -87,7 +121,9 @@ function mockServiceClient(fromResults: QueuedResult[], appMetadata: Record<stri
}
const client = {
from: vi.fn().mockImplementation(() => chain()),
from: vi.fn().mockImplementation((table: string) =>
table === 'bankid_consumed_sessions' ? chain2(consumed) : chain()
),
auth: { admin },
}
@@ -170,6 +206,32 @@ describe('POST /bankid/unlink', () => {
})
})
describe('POST /bankid/start, link mode', () => {
it('requires a signed-in caller, so a link flow always has an owner', async () => {
// An anonymous link flow would have no userId to check at /bankid/link,
// which is what lets an abandoned flow bind to the next person to sign in.
mockUnauthenticated()
const req = createMockRequest('/api/extensions/ext/tic/bankid/start', {
method: 'POST',
body: { mode: 'link' },
})
const { status } = await parseJsonResponse(await findHandler('POST', '/bankid/start')(req))
expect(status).toBe(401)
})
it('does not require auth for login or signup, which have no user yet', async () => {
mockUnauthenticated()
const req = createMockRequest('/api/extensions/ext/tic/bankid/start', {
method: 'POST',
body: { mode: 'login' },
})
const { status } = await parseJsonResponse(await findHandler('POST', '/bankid/start')(req))
expect(status).not.toBe(401)
})
})
describe('POST /bankid/link', () => {
function makeSession() {
return {
@@ -189,13 +251,13 @@ describe('POST /bankid/link', () => {
mockServiceClient([], {})
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
method: 'POST',
body: { sessionId: 'test-session' },
headers: await flowCookie('link'),
})
const { status } = await parseJsonResponse(await findHandler('POST', '/bankid/link')(req))
expect(status).toBe(401)
})
it('returns 400 when sessionId is missing', async () => {
it('returns 400 when the browser holds no flow', async () => {
mockAuthenticated()
mockServiceClient([], {})
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
@@ -206,6 +268,107 @@ describe('POST /bankid/link', () => {
expect(status).toBe(400)
})
it('refuses a session that was not opened as a link flow', async () => {
// A session started to sign someone IN must not be redirectable into
// binding their personnummer to whoever happens to be logged in here.
mockAuthenticated()
const { admin, client } = mockServiceClient([], {})
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
method: 'POST',
headers: await flowCookie('login'),
body: {},
})
const { status } = await parseJsonResponse(await findHandler('POST', '/bankid/link')(req))
expect(status).toBe(400)
expect(collectBankIdResult).not.toHaveBeenCalled()
expect(client.from).not.toHaveBeenCalled()
expect(admin.updateUserById).not.toHaveBeenCalled()
})
it('refuses a link flow that another user opened', async () => {
// The shared-browser takeover: A starts "Koppla BankID" and authenticates
// but never finishes; B signs in on the same machine and clicks the same
// button. Without the owner check, A's personnummer is written against B's
// user_id, and A can then sign in as B with their own BankID.
mockAuthenticated('user-b')
const { admin, client } = mockServiceClient([], {})
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
method: 'POST',
headers: await flowCookie('link', 'test-session', 'user-a'),
})
const { status } = await parseJsonResponse(await findHandler('POST', '/bankid/link')(req))
expect(status).toBe(400)
expect(collectBankIdResult).not.toHaveBeenCalled()
expect(client.from).not.toHaveBeenCalled()
expect(admin.updateUserById).not.toHaveBeenCalled()
})
it('refuses a stale tab after a newer link flow replaced the shared cookie', async () => {
mockAuthenticated()
const { client } = mockServiceClient([], {})
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const headers = await flowCookie('link')
headers[BANKID_FLOW_ID_HEADER] = 'older-flow'
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
method: 'POST',
headers,
})
const { status } = await parseJsonResponse(await findHandler('POST', '/bankid/link')(req))
expect(status).toBe(400)
expect(collectBankIdResult).not.toHaveBeenCalled()
expect(client.from).not.toHaveBeenCalled()
})
it('refuses to link twice off one identification', async () => {
mockAuthenticated()
const { admin, client } = mockServiceClient(
[{ data: null }], // pnr not linked to anyone yet
{},
{ error: { code: '23505', message: 'duplicate key' } }, // another tab claimed it first
)
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
method: 'POST',
headers: await flowCookie('link'),
})
const { status } = await parseJsonResponse(await findHandler('POST', '/bankid/link')(req))
expect(status).toBe(400)
// The identity insert never ran, so nothing was bound twice.
const inserts = vi.mocked(client.from).mock.calls.filter((c) => c[0] === 'bankid_identities')
expect(inserts).toHaveLength(1) // the pnr lookup only
expect(admin.updateUserById).not.toHaveBeenCalled()
})
it('refuses a forged flow cookie', async () => {
mockAuthenticated()
const { client } = mockServiceClient([], {})
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
// Same shape, no valid signature: what a same-origin script could plant.
const forged = Buffer.from(
JSON.stringify({ version: 1, sessionId: 'attacker-session', mode: 'link', startedAt: Date.now() }),
).toString('base64url')
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
method: 'POST',
headers: { cookie: `${BANKID_FLOW_COOKIE}=${forged}.not-a-signature` },
body: {},
})
const { status } = await parseJsonResponse(await findHandler('POST', '/bankid/link')(req))
expect(status).toBe(400)
expect(client.from).not.toHaveBeenCalled()
})
it('merges app_metadata so an existing has_password: true survives linking', async () => {
mockAuthenticated()
vi.mocked(collectBankIdResult).mockResolvedValue(makeSession())
@@ -219,7 +382,7 @@ describe('POST /bankid/link', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
method: 'POST',
body: { sessionId: 'test-session' },
headers: await flowCookie('link'),
})
const { status, body } = await parseJsonResponse<{ data?: { linked?: boolean } }>(
await findHandler('POST', '/bankid/link')(req)
@@ -242,7 +405,7 @@ describe('POST /bankid/link', () => {
const req = createMockRequest('/api/extensions/ext/tic/bankid/link', {
method: 'POST',
body: { sessionId: 'test-session' },
headers: await flowCookie('link'),
})
const { status, body } = await parseJsonResponse<{ error?: string }>(
await findHandler('POST', '/bankid/link')(req)
+373 -60
View File
@@ -25,7 +25,15 @@ import {
} from './lib/bankid-client'
import { TICAPIError } from './lib/tic-types'
import type { TICCompanyProfile, TICFinancialReportSummary } from './lib/tic-types'
import type { BankIdCompleteRequest } from './lib/bankid-types'
import {
BANKID_FLOW_ID_HEADER,
FLOW_VERIFIED_WINDOW_SECONDS,
FLOW_WINDOW_SECONDS,
clearBankIdFlowCookies,
isBankIdFlowMode,
readBankIdFlow,
setBankIdFlowCookies,
} from './lib/bankid-flow-cookie'
import type { CompanyLookupResult } from '@/lib/company-lookup/types'
import { hashPersonalNumber, encryptPersonalNumberForStorage } from '@/lib/auth/bankid'
import { requireAuth } from '@/lib/auth/require-auth'
@@ -36,6 +44,42 @@ import crypto from 'crypto'
const log = createLogger('tic/bankid')
/**
* Claim a BankID session, atomically and exactly once.
*
* The flow lives in a cookie now, so every tab of the browser shares one
* session and two of them can observe `status: complete` in the same poll tick.
* Both would call generateLink(), and the second magic link invalidates the
* first, so the tab the user is actually looking at may be the one that fails.
* Expiring the cookie on the way out does not prevent it: a Set-Cookie only
* applies once a response reaches the browser, and two requests that already
* carried the cookie both pass. The primary key is the only genuinely atomic
* thing available (serverless has no shared memory), so the loser of the race
* gets 23505 and stops before minting anything.
*
* Returns false when the session was already spent.
*/
async function consumeBankIdSession(
supabase: SupabaseClient,
sessionId: string
): Promise<boolean> {
const { error } = await supabase
.from('bankid_consumed_sessions')
.insert({ session_id: sessionId })
if (!error) return true
// 23505 unique_violation: another request got here first.
if (error.code === '23505') return false
// Anything else (table missing, connection lost) must fail closed: minting a
// second magic link is worse than making the user authenticate again.
log.error('could not claim bankid session; refusing to complete', {
code: error.code,
message: error.message,
})
return false
}
/**
* Request SPAR + CompanyRoles enrichment for a completed BankID session and
* cache the CompanyRoles slice in `bankid_enrichment` for the
@@ -787,6 +831,30 @@ export const ticExtension: Extension = {
|| request.headers.get('x-real-ip')
|| '127.0.0.1'
// The flow a session is opened for is fixed here and read back at
// /complete, so a 'link' session can never be finished as a 'login'.
// Validated before the rate limit: a malformed request starts no
// billable session, so it should not spend the caller's cooldown and
// lock them out of the retry that would have worked.
const body = await request.json().catch(() => ({}))
const mode = body?.mode
if (!isBankIdFlowMode(mode)) {
return NextResponse.json({ error: 'mode is required' }, { status: 400 })
}
// A link flow is owned by the user who opened it. /bankid/link binds
// the personnummer to whoever is authenticated when it runs, so an
// unowned link flow left behind in a shared browser would let the
// next person to sign in pick it up and bind the FIRST person's
// identity to their own account. Login and signup have no user yet
// and stay anonymous.
let userId: string | undefined
if (mode === 'link') {
const auth = await requireAuth()
if (auth.error) return auth.error
userId = auth.user.id
}
// Per-IP rate limit (each start = billable TIC session)
const now = Date.now()
const lastStart = bankIdStartCooldowns.get(ip) ?? 0
@@ -804,9 +872,31 @@ export const ticExtension: Extension = {
}
const userAgent = request.headers.get('user-agent') || undefined
const session = await startBankIdAuth(ip, userAgent)
return NextResponse.json({ data: session })
const flowId = crypto.randomUUID()
// sessionId is deliberately NOT in the response. It is a bearer
// credential for the holder's personnummer and for a Supabase
// session; it goes into the signed HttpOnly cookie instead, and the
// client drives the flow without ever seeing it.
const response = NextResponse.json({
data: {
flowId,
autoStartToken: session.autoStartToken,
qrStartToken: session.qrStartToken,
qrStartSecret: session.qrStartSecret,
},
})
await setBankIdFlowCookies(response, {
version: 1,
sessionId: session.sessionId,
flowId,
mode,
userId,
startedAt: Date.now(),
expiresAt: Date.now() + FLOW_WINDOW_SECONDS * 1000,
})
return response
} catch (error) {
if (error instanceof TICAPIError) {
if (error.code === 'NOT_CONFIGURED') {
@@ -835,17 +925,106 @@ export const ticExtension: Extension = {
skipAuth: true,
handler: async (request: Request) => {
try {
const body = await request.json()
const sessionId = body?.sessionId
if (!sessionId || typeof sessionId !== 'string') {
return NextResponse.json({ error: 'sessionId is required' }, { status: 400 })
const flow = await readBankIdFlow(request)
if (!flow) {
// No live flow in this browser: the tab is polling something that
// has finished, expired, or never belonged to it. Terminal, not an
// error, so the client can settle instead of spinning.
return NextResponse.json({ error: 'no_session' }, { status: 404 })
}
// The caller says which mode it is showing, and a flow only answers
// to its own. Without this a login session started on /login is
// picked up by the signup panel (or the reverse) whenever the user
// navigates between them. Deliberately NOT clearing: the flow is
// still legitimate for the page that started it.
const pollBody = await request.json().catch(() => ({}))
if (!isBankIdFlowMode(pollBody?.mode) || pollBody.mode !== flow.mode) {
return NextResponse.json({ error: 'no_session' }, { status: 404 })
}
const isProbe = pollBody?.probe === true
// The cookie is shared by every tab. A newer same-mode /start can
// replace it while an older tab is still polling, so mode alone is
// not enough: without the flow id, that stale tab would silently
// follow and complete the newer person's identification. A mount
// probe has no id yet and may discover it, but every active poll must
// present the id returned by /start or by that probe.
if (!isProbe && request.headers.get(BANKID_FLOW_ID_HEADER) !== flow.flowId) {
return NextResponse.json({ error: 'no_session' }, { status: 404 })
}
let result: Awaited<ReturnType<typeof pollBankIdSession>>
try {
result = await pollBankIdSession(flow.sessionId)
} catch (error) {
// TIC no longer knows this session (404), or answered 410 for an
// expired one. Report it as no_session so the client settles
// instead of counting it as a service outage.
//
// Deliberately does NOT clear the cookie. A clearing Set-Cookie is
// untargeted: a slow response about a dead session would delete
// whatever flow is in the jar by the time it lands, including one
// the user has just started in another tab. The stale cookie is
// harmless (it answers no_session again and expires on its own),
// whereas deleting a live flow costs a billable session.
if (error instanceof TICAPIError && (error.statusCode === 404 || error.statusCode === 410)) {
return NextResponse.json({ error: 'no_session' }, { status: 404 })
}
throw error
}
// An expired-session body comes back with no `status` at all
// (identityFetch returns a 410 body verbatim). Same treatment.
if (!result?.status) {
return NextResponse.json({ error: 'no_session' }, { status: 404 })
}
const result = await pollBankIdSession(sessionId)
if (result.status !== 'pending') {
log.info('poll status', { status: result.status, hintCode: result.hintCode, hasUser: !!result.user?.personalNumber })
}
return NextResponse.json({ data: result })
// Whitelist the fields the UI renders. The raw TIC payload carries
// user.personalNumber, which the client has never used and must
// never receive: this endpoint is skipAuth, so anything it returns
// is readable by whoever holds the flow cookie.
//
// The name (givenName/surname) is withheld from a PROBE. A probe runs
// before the person here has confirmed the flow is theirs, so
// returning the name would hand a stranger's identity to whoever
// opened the page on a shared machine, defeating the confirm card.
// The signup e-mail step needs the name, but it is reached only
// through the active poll loop (no probe mode), which does get it.
const response = NextResponse.json({
data: {
flowId: isProbe ? flow.flowId : undefined,
status: result.status,
message: result.message,
hintCode: result.hintCode,
qrStartToken: result.qrStartToken,
qrStartSecret: result.qrStartSecret,
user: !isProbe && result.user
? { givenName: result.user.givenName, surname: result.user.surname }
: undefined,
},
})
// A failed or cancelled order is over. Not cleared here for the same
// reason as the dead-session branch above: the Set-Cookie cannot be
// aimed at one flow, so a late response would delete a newer one.
// The client settles on this status, and the cookie expires.
if (result.status === 'complete') {
// Identification is done; what remains is the signup e-mail step,
// which is a person typing. Re-issue with the longer window so a
// user hunting for the right address does not have the session
// expire under them: on the old client-state design this step was
// bounded only by TIC's own retention.
await setBankIdFlowCookies(response, {
...flow,
expiresAt: Date.now() + FLOW_VERIFIED_WINDOW_SECONDS * 1000,
})
}
return response
} catch (error) {
if (error instanceof TICAPIError) {
if (error.code === 'RATE_LIMIT_EXCEEDED') {
@@ -870,17 +1049,43 @@ export const ticExtension: Extension = {
skipAuth: true,
handler: async (request: Request) => {
try {
const body: BankIdCompleteRequest = await request.json()
const { sessionId, mode, email } = body
if (!sessionId || !mode) {
// Session id and mode come from the signed cookie, never the body:
// a caller who could name both could complete any session it had
// seen, in whatever flow suited it.
const flow = await readBankIdFlow(request)
if (!flow) {
return NextResponse.json(
{ error: 'sessionId and mode are required' },
{ error: 'session_invalid', message: 'BankID-sessionen är inte längre giltig. Försök igen.' },
{ status: 400 }
)
}
const { sessionId, mode } = flow
// The shared cookie may have been replaced by a newer flow after
// this tab started. Only the tab that started or explicitly resumed
// the current flow may complete it.
if (request.headers.get(BANKID_FLOW_ID_HEADER) !== flow.flowId) {
return NextResponse.json(
{ error: 'session_invalid', message: 'BankID-sessionen är inte längre giltig. Försök igen.' },
{ status: 400 }
)
}
const trimmedEmail = email?.trim().toLowerCase()
if (mode === 'link') {
// Linking runs on the authenticated /bankid/link route, which
// proves who is being linked. Completing a link flow here would
// create or sign in an account off a session opened for something
// else entirely.
return NextResponse.json(
{ error: 'session_invalid', message: 'BankID-sessionen är inte längre giltig. Försök igen.' },
{ status: 400 }
)
}
const body = await request.json().catch(() => ({}))
const trimmedEmail = typeof body?.email === 'string'
? body.email.trim().toLowerCase()
: undefined
if (mode === 'signup' && !trimmedEmail) {
return NextResponse.json(
@@ -889,14 +1094,26 @@ export const ticExtension: Extension = {
)
}
/**
* Every exit from here clears the flow, so a session is usable
* exactly once. Two tabs that both observe completion cannot both
* mint a magic link: the second finds no cookie and gets
* session_invalid, instead of a generateLink that silently
* invalidates the first tab's link and breaks the sign-in.
*/
const settle = (response: NextResponse): NextResponse => {
clearBankIdFlowCookies(response)
return response
}
// Verify BankID session is complete. The message surfaces directly
// in the register-page toast, so it must be Swedish.
const session = await collectBankIdResult(sessionId)
if (session.status !== 'complete' || !session.user) {
return NextResponse.json(
return settle(NextResponse.json(
{ error: 'session_invalid', message: 'BankID-sessionen är inte längre giltig. Försök igen.' },
{ status: 400 }
)
))
}
const { personalNumber, givenName, surname, name } = session.user
@@ -912,20 +1129,35 @@ export const ticExtension: Extension = {
if (mode === 'login') {
if (!existing) {
return NextResponse.json({
// Terminal for a login flow: the user is sent to signup, which
// starts its own session.
return settle(NextResponse.json({
error: 'no_account',
givenName,
surname,
}, { status: 404 })
}, { status: 404 }))
}
// Returning user: generate magic link
const { data: userData } = await supabase.auth.admin.getUserById(existing.user_id)
if (!userData?.user?.email) {
return NextResponse.json(
// Data problem, not a transient one: an identity with no user
// email will never complete. settle() so it is not re-offered as
// a resumable flow on the next page load.
return settle(NextResponse.json(
{ error: 'session_invalid', message: 'User account not found' },
{ status: 500 }
)
))
}
// Claim the session BEFORE minting anything. Two tabs sharing this
// browser's flow cookie can both arrive here; only one may mint,
// because the second magic link invalidates the first.
if (!await consumeBankIdSession(supabase, sessionId)) {
return settle(NextResponse.json(
{ error: 'session_invalid', message: 'BankID-sessionen är inte längre giltig. Försök igen.' },
{ status: 400 }
))
}
const { data: link, error: linkError } = await supabase.auth.admin.generateLink({
@@ -935,30 +1167,38 @@ export const ticExtension: Extension = {
if (linkError || !link?.properties?.hashed_token) {
log.error('generateLink failed for login', { message: linkError?.message, code: linkError?.code })
return NextResponse.json(
// The session is already consumed, so a retry would fail with
// session_invalid anyway; settle() clears the cookie now instead
// of leaving a spent flow to be re-offered as resumable.
return settle(NextResponse.json(
{ error: 'Failed to create session' },
{ status: 500 }
)
))
}
// Refresh enrichment so /select-company sees current Bolagsverket roles.
await fetchAndStoreEnrichment(sessionId, existing.user_id, supabase)
return NextResponse.json({
// settle(): the magic link is minted, so the flow is spent. A
// second tab reaching here would mint another and invalidate this
// one; it now gets session_invalid instead.
return settle(NextResponse.json({
data: {
tokenHash: link.properties.hashed_token,
type: 'magiclink',
isNewUser: false,
},
})
}))
}
// mode === 'signup'
if (existing) {
return NextResponse.json(
// Terminal: this BankID already has an account, so the answer is
// to sign in, not to retry this session.
return settle(NextResponse.json(
{ error: 'already_linked', message: 'This BankID is already linked to an account' },
{ status: 409 }
)
))
}
// Create new Supabase user. Email uniqueness is checked by createUser
@@ -981,10 +1221,15 @@ export const ticExtension: Extension = {
// /bankid/link route so email ownership is proven by password login
// first. (CWE-287)
if (createError?.code === 'email_exists') {
// The session id is a bearer credential for a personnummer at
// TIC; a prefix is enough to correlate log lines.
log.warn('bankid signup rejected: email already registered', {
sessionId,
sessionIdPrefix: sessionId.slice(0, 8),
pnrHashPrefix: pnrHash.slice(0, 8),
})
// Deliberately NOT settled: nothing was consumed and the user
// may simply have typed the wrong address. Leaving the flow
// alive lets them correct it without a second BankID round trip.
return NextResponse.json(
{
error: 'account_exists',
@@ -1009,14 +1254,14 @@ export const ticExtension: Extension = {
// All-or-nothing signup: if any step after createUser fails, delete
// the just-created user so the same email/BankID can retry cleanly.
// Leaving the half-created account behind strands the user — a retry
// Leaving the half-created account behind strands the user: a retry
// hits account_exists/already_linked, but the account only has a
// random password they never saw, so "log in instead" requires a
// password reset. bankid_identities cascades on user delete.
const rollbackSignup = async (step: string) => {
const { error: deleteError } = await supabase.auth.admin.deleteUser(userId)
if (deleteError) {
log.error(`signup rollback after failed ${step} could not delete user — orphaned account`, {
log.error(`signup rollback after failed ${step} could not delete user: orphaned account`, {
userId,
message: deleteError.message,
})
@@ -1060,6 +1305,17 @@ export const ticExtension: Extension = {
)
}
// Claim the session before minting. Placed after createUser so the
// recoverable account_exists path above leaves the flow reusable,
// and before generateLink so two tabs cannot both mint.
if (!await consumeBankIdSession(supabase, sessionId)) {
await rollbackSignup('session already consumed')
return settle(NextResponse.json(
{ error: 'session_invalid', message: 'BankID-sessionen är inte längre giltig. Försök igen.' },
{ status: 400 }
))
}
// Generate magic link for session
const { data: link, error: linkError } = await supabase.auth.admin.generateLink({
type: 'magiclink',
@@ -1069,22 +1325,26 @@ export const ticExtension: Extension = {
if (linkError || !link?.properties?.hashed_token) {
log.error('generateLink failed for signup', { message: linkError?.message, code: linkError?.code })
await rollbackSignup('generateLink')
return NextResponse.json(
// The session was already consumed above, so this flow cannot be
// retried; settle() clears it rather than leaving a spent,
// rolled-back flow to be re-offered as resumable.
return settle(NextResponse.json(
{ error: 'internal_error', message: 'Kunde inte skapa kontot. Försök igen.' },
{ status: 500 }
)
))
}
// Enrichment (CompanyRoles): pre-fills /select-company picker.
await fetchAndStoreEnrichment(sessionId, userId, supabase)
return NextResponse.json({
// settle(): account created and magic link minted. The flow is spent.
return settle(NextResponse.json({
data: {
tokenHash: link.properties.hashed_token,
type: 'magiclink',
isNewUser: true,
},
})
}))
} catch (error) {
if (error instanceof TICAPIError) {
log.error('complete failed: TIC API error', { statusCode: error.statusCode, code: error.code, message: error.message })
@@ -1109,23 +1369,34 @@ export const ticExtension: Extension = {
},
{
method: 'DELETE',
path: '/bankid/:sessionId',
method: 'POST',
// Was DELETE /bankid/:sessionId. The id is no longer something the
// client knows, so cancelling is now "end whatever flow this browser
// holds": it cannot be aimed at anyone else's session.
path: '/bankid/cancel',
skipAuth: true,
handler: async (request: Request) => {
try {
const url = new URL(request.url)
const sessionId = url.searchParams.get('_sessionId')
if (!sessionId) {
return NextResponse.json({ error: 'sessionId is required' }, { status: 400 })
}
// A malformed cookie must still be clearable rather than turning
// Avbryt into a 500.
const flow = await readBankIdFlow(request).catch(() => null)
await cancelBankIdSession(sessionId)
return NextResponse.json({ data: { cancelled: true } })
} catch (error) {
log.error('cancel failed', error)
return NextResponse.json({ error: 'Failed to cancel session' }, { status: 500 })
if (flow && request.headers.get(BANKID_FLOW_ID_HEADER) !== flow.flowId) {
// A newer tab replaced the shared cookie. This caller may settle its
// own stale UI, but it must not cancel or clear the newer flow.
return NextResponse.json({ data: { cancelled: false, replaced: true } })
}
const response = NextResponse.json({ data: { cancelled: true } })
clearBankIdFlowCookies(response)
if (flow) {
try {
await cancelBankIdSession(flow.sessionId)
} catch (error) {
log.error('cancel failed', error)
}
}
return response
},
},
@@ -1146,20 +1417,52 @@ export const ticExtension: Extension = {
if (auth.error) return auth.error
const userId = auth.user.id
const body = await request.json()
const { sessionId } = body
// Cookie, not body, and the mode must be the one the session was
// opened for. Otherwise a session started to sign SOMEONE ELSE in
// could be redirected into binding their personnummer to whoever is
// currently logged in on this browser.
const flow = await readBankIdFlow(request)
if (!flow || flow.mode !== 'link') {
return NextResponse.json(
{ error: 'session_invalid', message: 'BankID session is not complete' },
{ status: 400 }
)
}
if (!sessionId) {
return NextResponse.json({ error: 'sessionId is required' }, { status: 400 })
if (request.headers.get(BANKID_FLOW_ID_HEADER) !== flow.flowId) {
return NextResponse.json(
{ error: 'session_invalid', message: 'BankID session is not complete' },
{ status: 400 }
)
}
// The flow must belong to the caller. Mode alone is not enough: this
// route binds a personnummer to whoever is authenticated right now,
// so a link flow that someone else started and abandoned in this
// browser would otherwise bind THEIR identity to THIS account, and
// they could then sign in as this user with their own BankID.
if (flow.userId !== userId) {
log.warn('bankid link rejected: flow belongs to another user')
return NextResponse.json(
{ error: 'session_invalid', message: 'BankID session is not complete' },
{ status: 400 }
)
}
const { sessionId } = flow
/** Linking is single-use for the same reason completing is. */
const settle = (response: NextResponse): NextResponse => {
clearBankIdFlowCookies(response)
return response
}
// Verify BankID session
const session = await collectBankIdResult(sessionId)
if (session.status !== 'complete' || !session.user) {
return NextResponse.json(
return settle(NextResponse.json(
{ error: 'session_invalid', message: 'BankID session is not complete' },
{ status: 400 }
)
))
}
const { personalNumber, givenName, surname } = session.user
@@ -1174,14 +1477,23 @@ export const ticExtension: Extension = {
.single()
if (existing && existing.user_id !== userId) {
return NextResponse.json(
return settle(NextResponse.json(
{ error: 'already_linked', message: 'This BankID is already linked to another account' },
{ status: 409 }
)
))
}
if (existing && existing.user_id === userId) {
return NextResponse.json({ data: { linked: true, alreadyLinked: true } })
return settle(NextResponse.json({ data: { linked: true, alreadyLinked: true } }))
}
// Single-use, same reason as /complete: two tabs sharing this
// browser's flow must not both act on one identification.
if (!await consumeBankIdSession(supabase, sessionId)) {
return settle(NextResponse.json(
{ error: 'session_invalid', message: 'BankID session is not complete' },
{ status: 400 }
))
}
// Link BankID to current user
@@ -1197,10 +1509,11 @@ export const ticExtension: Extension = {
if (insertError) {
log.error('link insert failed', { message: insertError.message, code: insertError.code })
return NextResponse.json(
// Session already consumed above, so the flow is spent; clear it.
return settle(NextResponse.json(
{ error: 'Failed to link BankID' },
{ status: 500 }
)
))
}
// Read-merge-write: updateUserById REPLACES app_metadata wholesale
@@ -1214,7 +1527,7 @@ export const ticExtension: Extension = {
app_metadata: { ...priorMeta, bankid_linked: true },
})
return NextResponse.json({ data: { linked: true } })
return settle(NextResponse.json({ data: { linked: true } }))
} catch (error) {
if (error instanceof TICAPIError) {
log.error('link failed: TIC API error', { statusCode: error.statusCode, code: error.code, message: error.message })
@@ -1261,7 +1574,7 @@ export const ticExtension: Extension = {
// Clear app_metadata.bankid_linked so MFA enforcement resumes.
// Read-merge-write: updateUserById REPLACES app_metadata wholesale
// (same rationale as /bankid/link above). Writing only
// { bankid_linked: false } would wipe has_password — a BankID-only
// { bankid_linked: false } would wipe has_password: a BankID-only
// user (has_password: false) would then be inferred as HAVING a
// password (lib/auth/has-password.ts) and could strand themselves
// with no working login method.
@@ -0,0 +1,364 @@
/**
* Server-held state for an in-flight BankID flow.
*
* Why the session id is not allowed near the browser's JavaScript
* -------------------------------------------------------------
* A TIC `sessionId` is an unauthenticated bearer credential. Anyone holding
* one can POST it to /bankid/poll (skipAuth) and read the holder's
* personnummer, or POST it to /bankid/complete with mode 'login' and receive a
* `tokenHash` that `verifyOtp` turns into a full Supabase session, with MFA
* skipped because BankID accounts carry `bankid_linked`. It used to be handed
* to the client and kept in `sessionStorage`, which made every one of those a
* single XSS away, and made the obvious fix for the cross-tab bug (move it to
* `localStorage` so the tab BankID returns to can resume) a straight upgrade
* of any same-origin XSS into a login-fixation primitive.
*
* So the id never leaves the server. It lives in an HttpOnly cookie that the
* browser attaches to the BankID endpoints and nothing else:
*
* • HttpOnly script cannot read it, so XSS cannot steal a session.
* • signed script cannot FORGE one. It does not stop a script from
* planting a cookie the server genuinely minted (an attacker
* can fetch one with curl), and it does not bind the flow to
* a browser or a person. Planting a completed identification
* is what login fixation is, so the protection against that
* is not here: it is the client refusing to consume a flow
* this browsing context did not start without an explicit
* confirmation. See BankIdAuth's resume handling.
* • __Host- forbids Domain and forces Path=/, which leaves exactly one
* possible (name, domain, path) for this cookie. Without it a
* script can plant the same name at a LONGER path, which the
* browser sends first and the server's deletion cannot reach.
* • SameSite=Lax the BankID app returns the user by top-level navigation
* from outside the site; Strict would drop the cookie there
* and strand exactly the flow this exists to serve.
* • short Max-Age a BankID order is good for ~3 minutes. An abandoned flow
* should not outlive it by much.
*
* Being a cookie rather than client storage is also what fixes the original
* bug: cookies are shared by every tab of the origin, so whichever tab BankID
* returns the user to, new or reloaded, simply polls and continues. No
* client-side handoff, no cross-tab lock, no heartbeat.
*
* `mode` is pinned here at /start and read back at /complete, so the flow a
* session was opened for is the only flow that can finish it. The client
* cannot ask to complete a 'link' session as a 'login'.
*/
import { NextResponse } from 'next/server'
export type BankIdFlowMode = 'login' | 'signup' | 'link'
/**
* HttpOnly, signed. Holds the session id, and is never readable by scripts.
*
* The `__Host-` prefix is load-bearing, not decoration. Browsers only refuse a
* `document.cookie` write when it collides with an existing HttpOnly cookie on
* the exact (name, domain, path) triple, so without the prefix a script could
* set the SAME NAME at a longer path; RFC 6265 §5.4 serialises longer paths
* first, so the planted one would win, and a Max-Age=0 written to the shorter
* path could never delete it. `__Host-` forbids `Domain` and forces `Path=/`,
* which leaves exactly one possible (name, domain, path) for this cookie: the
* one the server owns. That also blocks cookie-tossing from a sibling
* white-label subdomain.
*
* Losing the narrow Path is the price. It is worth it: the narrow Path only
* ever bought log hygiene, whereas the shadowing it permitted was a way to
* plant a completed session in someone else's browser.
*/
export const BANKID_FLOW_COOKIE = '__Host-accounted-bankid-flow'
/**
* Non-secret identifier that binds one browser tab to the flow it started or
* explicitly resumed. The signed cookie remains the credential; this header
* only prevents a stale tab from silently acting on a newer flow that replaced
* the shared cookie.
*/
export const BANKID_FLOW_ID_HEADER = 'x-bankid-flow-id'
/**
* How long a fresh order may be resumed. A BankID order is good for ~3 minutes;
* the rest covers the app switch and a slow return.
*/
export const FLOW_WINDOW_SECONDS = 300
/**
* Replaces the window above once the identification has actually happened. The
* signup flow then asks for an e-mail, and a user hunting for the right address
* (or switching to a password manager and back) must not have the session
* expire under them: on `main` this step was bounded only by TIC's own
* retention, so a short shared budget would have been a real regression.
*/
export const FLOW_VERIFIED_WINDOW_SECONDS = 900
/** Sanity bound on a decoded expiry, so no cookie can claim an unbounded life. */
const MAX_WINDOW_MS = FLOW_VERIFIED_WINDOW_SECONDS * 1000
/**
* Ceiling on a whole flow, measured from /start. Bounds the re-issue chain:
* an identification cannot be kept resumable indefinitely by polling.
*/
export const MAX_TOTAL_LIFE_SECONDS = FLOW_WINDOW_SECONDS + FLOW_VERIFIED_WINDOW_SECONDS
const MAX_TOTAL_LIFE_MS = MAX_TOTAL_LIFE_SECONDS * 1000
const SIGNING_CONTEXT = 'accounted-bankid-flow-v1:'
export interface BankIdFlowState {
version: 1
sessionId: string
/** Random, non-secret tab binding. The BankID session id remains HttpOnly. */
flowId: string
mode: BankIdFlowMode
/**
* Who opened a `link` flow. Linking binds a personnummer to whoever is
* authenticated when /bankid/link runs, so without this a flow started by one
* person and left unfinished could be picked up by the next person to use the
* browser and bind the FIRST person's identity to the SECOND person's
* account. Absent for login and signup, which have no user yet.
*/
userId?: string
/**
* When /start opened this flow. Carried so the total life can be capped:
* /poll extends `expiresAt` when it observes completion, and without a fixed
* origin a caller could keep polling to push the window forward forever,
* leaving a usable identification in the jar for as long as TIC retains it.
*/
startedAt: number
/** Absolute expiry, enforced server-side; the browser's Max-Age only mirrors it. */
expiresAt: number
}
type Environment = Record<string, string | undefined>
export function isBankIdFlowMode(value: unknown): value is BankIdFlowMode {
return value === 'login' || value === 'signup' || value === 'link'
}
/**
* Unlike the session-timeout cookie, which degrades to unsigned-and-ignored
* when misconfigured, this one throws: a BankID flow that cannot be bound to
* the browser that started it must not run at all.
*/
function getSigningSecret(env: Environment): string {
const dedicated = env.BANKID_ENCRYPTION_KEY?.trim()
if (dedicated) return dedicated
const sessionSecret = env.SESSION_TIMEOUT_SECRET?.trim()
if (sessionSecret) return sessionSecret
const serviceRole = env.SUPABASE_SERVICE_ROLE_KEY?.trim()
if (serviceRole) return serviceRole
throw new Error(
'BankID flow cookie requires BANKID_ENCRYPTION_KEY, SESSION_TIMEOUT_SECRET or SUPABASE_SERVICE_ROLE_KEY',
)
}
function bytesToBase64Url(bytes: Uint8Array): string {
let binary = ''
for (const byte of bytes) binary += String.fromCharCode(byte)
return btoa(binary).replaceAll('+', '-').replaceAll('/', '_').replace(/=+$/u, '')
}
// The explicit ArrayBuffer parameter matters: a bare Uint8Array is
// Uint8Array<ArrayBufferLike>, which crypto.subtle rejects as a BufferSource
// because it could be backed by a SharedArrayBuffer. Same annotation as
// lib/auth/session-timeout.ts, for the same reason.
function base64UrlToBytes(value: string): Uint8Array<ArrayBuffer> | null {
try {
const base64 = value.replaceAll('-', '+').replaceAll('_', '/')
const padded = base64.padEnd(Math.ceil(base64.length / 4) * 4, '=')
const binary = atob(padded)
const bytes = new Uint8Array(binary.length)
for (let index = 0; index < binary.length; index += 1) {
bytes[index] = binary.charCodeAt(index)
}
return bytes
} catch {
return null
}
}
async function importSigningKey(secret: string): Promise<CryptoKey> {
// HKDF-derived with a purpose-bound info string, never the raw secret: the
// same key material also encrypts personnummer at rest (lib/auth/bankid.ts)
// and the SUPABASE_SERVICE_ROLE_KEY fallback is a privileged credential.
// Neither may double as an HMAC key directly.
const baseKey = await crypto.subtle.importKey(
'raw',
new TextEncoder().encode(secret),
'HKDF',
false,
['deriveKey'],
)
return crypto.subtle.deriveKey(
{
name: 'HKDF',
hash: 'SHA-256',
salt: new Uint8Array(32),
info: new TextEncoder().encode(SIGNING_CONTEXT),
},
baseKey,
{ name: 'HMAC', hash: 'SHA-256', length: 256 },
false,
['sign', 'verify'],
)
}
export async function signBankIdFlow(
state: BankIdFlowState,
env: Environment = process.env,
): Promise<string> {
const payload = bytesToBase64Url(new TextEncoder().encode(JSON.stringify(state)))
const key = await importSigningKey(getSigningSecret(env))
const signature = await crypto.subtle.sign(
'HMAC',
key,
new TextEncoder().encode(`${SIGNING_CONTEXT}${payload}`),
)
return `${payload}.${bytesToBase64Url(new Uint8Array(signature))}`
}
/**
* Verify and decode a flow cookie. Returns null for anything that is not a
* cookie this server minted and still considers live: bad signature, wrong
* shape, unknown mode, an unowned `link` flow, a `startedAt` in the future,
* one whose `expiresAt` is past or claims more than MAX_WINDOW, or a whole
* flow older than MAX_TOTAL_LIFE. Expiry is re-checked here rather than
* trusted to the browser's Max-Age, which a client controls.
*/
export async function verifyBankIdFlow(
value: string | undefined,
env: Environment = process.env,
now: number = Date.now(),
): Promise<BankIdFlowState | null> {
if (!value) return null
const [payload, signature, extra] = value.split('.')
if (!payload || !signature || extra !== undefined) return null
const signatureBytes = base64UrlToBytes(signature)
if (!signatureBytes) return null
try {
const key = await importSigningKey(getSigningSecret(env))
const valid = await crypto.subtle.verify(
'HMAC',
key,
signatureBytes,
new TextEncoder().encode(`${SIGNING_CONTEXT}${payload}`),
)
if (!valid) return null
} catch {
return null
}
const decoded = base64UrlToBytes(payload)
if (!decoded) return null
let parsed: unknown
try {
parsed = JSON.parse(new TextDecoder().decode(decoded))
} catch {
return null
}
if (!parsed || typeof parsed !== 'object') return null
const state = parsed as Partial<BankIdFlowState>
if (state.version !== 1) return null
if (typeof state.sessionId !== 'string' || !state.sessionId) return null
if (typeof state.flowId !== 'string' || !state.flowId) return null
if (!isBankIdFlowMode(state.mode)) return null
if (state.userId !== undefined && (typeof state.userId !== 'string' || !state.userId)) return null
// A `link` flow with no owner cannot be validated against the caller, and an
// unowned link is exactly the shape that binds the wrong identity.
if (state.mode === 'link' && !state.userId) return null
if (typeof state.startedAt !== 'number' || !Number.isFinite(state.startedAt)) return null
if (state.startedAt > now) return null
if (typeof state.expiresAt !== 'number' || !Number.isFinite(state.expiresAt)) return null
if (now > state.expiresAt) return null
// Expiry is enforced here rather than trusted to the browser's Max-Age, which
// a client controls. The upper bound stops any cookie claiming a longer life
// than the longest window this server ever issues.
if (state.expiresAt - now > MAX_WINDOW_MS) return null
// Hard cap on the whole flow, not just this cookie. /poll re-issues with a
// longer window when it sees a completed identification; without a cap
// measured from the original start, polling in a loop would keep a usable
// identification alive for as long as TIC retains the session.
if (now - state.startedAt > MAX_TOTAL_LIFE_MS) return null
return state as BankIdFlowState
}
/**
* `__Host-` requires Secure, Path=/ and no Domain; a cookie missing any of them
* is rejected outright by the browser. Secure is therefore unconditional here,
* and that costs nothing: isBankIdEnabled() (lib/auth/bankid.ts) returns false
* whenever NEXT_PUBLIC_SELF_HOSTED is set, so there is no plain-http BankID
* deployment to accommodate. An earlier version made Secure conditional on
* x-forwarded-proto for that imagined case, which only meant a proxy that omits
* the header would silently ship this cookie unprotected on a real HTTPS site.
*/
const FLOW_COOKIE_OPTIONS = {
httpOnly: true,
secure: true,
sameSite: 'lax',
path: '/',
} as const
/** Attach a flow to the response, replacing any flow already there. */
export async function setBankIdFlowCookies(
response: NextResponse,
state: BankIdFlowState,
env: Environment = process.env,
now: number = Date.now(),
): Promise<void> {
response.cookies.set(BANKID_FLOW_COOKIE, await signBankIdFlow(state, env), {
...FLOW_COOKIE_OPTIONS,
// Mirrors the signed expiry so an abandoned flow also disappears from the
// jar; the server-side check in verifyBankIdFlow is the real bound.
maxAge: Math.max(1, Math.ceil((state.expiresAt - now) / 1000)),
})
}
/** End the flow. Called on every terminal outcome. */
export function clearBankIdFlowCookies(response: NextResponse): void {
// Same name, same path, same attributes: a deletion written to a different
// path would leave the real cookie in place.
response.cookies.set(BANKID_FLOW_COOKIE, '', { ...FLOW_COOKIE_OPTIONS, maxAge: 0 })
}
/**
* Read and verify the flow attached to an incoming request.
*
* Fails closed when the header carries more than one cookie of this name.
* `__Host-` should make that impossible, but the cost of being wrong about a
* browser's prefix handling is that a planted duplicate gets used instead of
* the real one, so ambiguity is treated as no flow rather than resolved by
* picking a winner.
*/
export async function readBankIdFlow(
request: Request,
env: Environment = process.env,
): Promise<BankIdFlowState | null> {
const header = request.headers.get('cookie')
if (!header) return null
const values: string[] = []
for (const part of header.split(';')) {
const separator = part.indexOf('=')
if (separator === -1) continue
if (part.slice(0, separator).trim() !== BANKID_FLOW_COOKIE) continue
const raw = part.slice(separator + 1).trim()
// A malformed percent-escape throws URIError. Treat it as an unusable
// cookie rather than letting it become a 500 in every handler that reads
// the flow.
try {
values.push(decodeURIComponent(raw))
} catch {
return null
}
}
if (values.length !== 1) return null
return verifyBankIdFlow(values[0], env)
}