"use server" import { redirect } from "next/navigation" import { headers } from "next/headers" import { APIError } from "better-auth/api" import { auth } from "@/lib/auth" import { verifyTurnstile } from "@/lib/turnstile" const APP_URL = process.env.NEXT_PUBLIC_APP_URL ?? "http://localhost:3000" const CAPTCHA_ERROR = "Please complete the verification challenge and try again." /** Post-auth destination — only same-site relative paths (blocks open redirects). */ function safeNext(formData: FormData): string { const next = formData.get("next") if (typeof next === "string" && next.startsWith("/") && !next.startsWith("//") && !next.startsWith("/\\")) { return next } return "/dashboard" } export async function signUp(formData: FormData) { const email = formData.get("email") as string const password = formData.get("password") as string const fullName = formData.get("full_name") as string const captchaToken = formData.get("cf-turnstile-response") as string | null const h = await headers() if (!(await verifyTurnstile(captchaToken, h.get("x-forwarded-for")))) { redirect(`/signup?error=${encodeURIComponent(CAPTCHA_ERROR)}`) } try { await auth.api.signUpEmail({ // callbackURL is where the verification link lands the user after confirming. body: { email, password, name: fullName, callbackURL: "/dashboard" }, headers: h, }) } catch (e) { const raw = e instanceof APIError ? e.message : "Sign up failed" // Don't reveal that an email is already registered (user enumeration) — the // "already exists" path must not be distinguishable from other failures. const msg = /exist|registered|already|taken/i.test(raw) ? "We couldn't complete your sign-up. Please try a different email or sign in." : raw redirect(`/signup?error=${encodeURIComponent(msg)}`) } // When email verification is required, the account isn't usable until confirmed — // send the user to the "check your email" screen instead of the dashboard. if (process.env.REQUIRE_EMAIL_VERIFICATION === "true") { redirect("/signup?success=check-email") } redirect(safeNext(formData)) } export async function signIn(formData: FormData) { const email = formData.get("email") as string const password = formData.get("password") as string const captchaToken = formData.get("cf-turnstile-response") as string | null const h = await headers() if (!(await verifyTurnstile(captchaToken, h.get("x-forwarded-for")))) { redirect(`/login?error=${encodeURIComponent(CAPTCHA_ERROR)}`) } try { await auth.api.signInEmail({ body: { email, password }, headers: h, }) } catch (e) { const msg = e instanceof APIError ? e.message : "Invalid email or password" redirect(`/login?error=${encodeURIComponent(msg)}`) } redirect(safeNext(formData)) } export async function signInWithGoogle() { let url: string | undefined try { const res = await auth.api.signInSocial({ body: { provider: "google", callbackURL: "/dashboard" }, headers: await headers(), }) url = res?.url ?? undefined } catch (e) { const msg = e instanceof APIError ? e.message : "Google sign-in failed" redirect(`/login?error=${encodeURIComponent(msg)}`) } if (url) redirect(url) redirect("/login?error=google_failed") } export async function resetPassword(formData: FormData) { const email = formData.get("email") as string const captchaToken = formData.get("cf-turnstile-response") as string | null const h = await headers() if (!(await verifyTurnstile(captchaToken, h.get("x-forwarded-for")))) { redirect(`/forgot-password?error=${encodeURIComponent(CAPTCHA_ERROR)}`) } try { await auth.api.requestPasswordReset({ body: { email, redirectTo: `${APP_URL}/update-password` }, headers: h, }) } catch { // Always report success so we don't reveal whether an account exists. } redirect("/forgot-password?success=email-sent") } export async function signOut() { try { await auth.api.signOut({ headers: await headers() }) } catch { // ignore } redirect("/login") } export async function updatePassword(formData: FormData) { const password = formData.get("password") as string const token = formData.get("token") as string if (!token) { redirect(`/update-password?error=${encodeURIComponent("Reset link is invalid or expired.")}`) } try { await auth.api.resetPassword({ body: { newPassword: password, token }, headers: await headers(), }) } catch (e) { const msg = e instanceof APIError ? e.message : "Could not update password" redirect(`/update-password?error=${encodeURIComponent(msg)}&token=${encodeURIComponent(token)}`) } redirect("/login?success=password-updated") }