diff --git a/apps/web/server/lib/auth/login/getServerSideProps.tsx b/apps/web/server/lib/auth/login/getServerSideProps.tsx index b7e7841a792..134f798f568 100644 --- a/apps/web/server/lib/auth/login/getServerSideProps.tsx +++ b/apps/web/server/lib/auth/login/getServerSideProps.tsx @@ -14,6 +14,9 @@ export async function getServerSideProps(context: GetServerSidePropsContext) { const session = await getServerSession({ req }); const verifyJwt = (jwt: string) => { + // A missing key would encode to a zero-length secret, which jose happily + // verifies against - fail loudly instead (same pattern as next.config.ts). + if (!process.env.CALENDSO_ENCRYPTION_KEY) throw new Error("Please set CALENDSO_ENCRYPTION_KEY"); const secret = new TextEncoder().encode(process.env.CALENDSO_ENCRYPTION_KEY); return jwtVerify(jwt, secret, { diff --git a/packages/features/auth/lib/signJwt.ts b/packages/features/auth/lib/signJwt.ts index f068d0f8a38..bba0708aef2 100644 --- a/packages/features/auth/lib/signJwt.ts +++ b/packages/features/auth/lib/signJwt.ts @@ -3,6 +3,9 @@ import { SignJWT } from "jose"; import { WEBSITE_URL } from "@calcom/lib/constants"; const signJwt = async (payload: { email: string }) => { + // A missing key would encode to a zero-length secret, which jose happily + // signs with - fail loudly instead (same pattern as next.config.ts). + if (!process.env.CALENDSO_ENCRYPTION_KEY) throw new Error("Please set CALENDSO_ENCRYPTION_KEY"); const secret = new TextEncoder().encode(process.env.CALENDSO_ENCRYPTION_KEY); return new SignJWT(payload) .setProtectedHeader({ alg: "HS256" }) diff --git a/packages/features/auth/lib/verifyCodeUnAuthenticated.ts b/packages/features/auth/lib/verifyCodeUnAuthenticated.ts index d17acdcee80..9378ce87f4f 100644 --- a/packages/features/auth/lib/verifyCodeUnAuthenticated.ts +++ b/packages/features/auth/lib/verifyCodeUnAuthenticated.ts @@ -14,8 +14,11 @@ export const verifyCodeUnAuthenticated = async (email: string, code: string) => identifier: `emailVerifyCode.${hashEmail(email)}`, }); + // A missing key would degrade the seed to a pure function of the victim + // email (audit LO-05); fail loudly instead (same pattern as next.config.ts). + if (!process.env.CALENDSO_ENCRYPTION_KEY) throw new Error("Please set CALENDSO_ENCRYPTION_KEY"); const secret = createHash("md5") - .update(email + (process.env.CALENDSO_ENCRYPTION_KEY || "")) + .update(email + process.env.CALENDSO_ENCRYPTION_KEY) .digest("hex"); const isValidToken = totpRawCheck(code, secret, { step: 900 }); diff --git a/packages/platform/atoms/static/Stripe secrets.png b/packages/platform/atoms/static/Stripe secrets.png deleted file mode 100644 index 29758fcfe1f..00000000000 Binary files a/packages/platform/atoms/static/Stripe secrets.png and /dev/null differ