diff --git a/src/captcha/captcha-challenge.service.ts b/src/captcha/captcha-challenge.service.ts index 91833fa..7c0574c 100644 --- a/src/captcha/captcha-challenge.service.ts +++ b/src/captcha/captcha-challenge.service.ts @@ -12,49 +12,40 @@ import { HashService } from "src/utils/hash/hash.service"; @Injectable() export class CaptchaChallengeService { + private readonly isDev: boolean; + constructor( private readonly captchaService: CaptchaService, private readonly hashService: HashService, private readonly captchaChallengeDbService: CaptchaChallengeDbService, private readonly configService: ConfigService, - ) {} + ) { + this.isDev = this.configService.get("NODE_ENV") === "development"; + } async issue(): Promise { const generated = this.captchaService.generate(); const captchaId = randomUUID(); - if (this.configService.get("NODE_ENV") === "development") { - const answerHash = await this.hashService.hash( - this.captchaService.normalizeAnswer(generated.text), - ); - const result = { - captchaId, - answerHash: - this.configService.get("NODE_ENV") === "development" - ? answerHash - : "", - image: generated.image, - expiresAt: generated.expiresAt, - expireAt: new Date(generated.expiresAt), - usedAt: null, - }; - } + // Always hash and persist the answer — the env check was the root bug + const answerHash = await this.hashService.hash( + this.captchaService.normalizeAnswer(generated.text), + ); - const result = { + await this.captchaChallengeDbService.create({ captchaId, + answerHash, image: generated.image, expiresAt: generated.expiresAt, expireAt: new Date(generated.expiresAt), usedAt: null, - }; - - await this.captchaChallengeDbService.create(result); + }); return { captchaId, - text: generated.text /* TODO: REMOVE THIS FOR PROD*/, image: generated.image, expiresAt: generated.expiresAt, + ...(this.isDev && { text: generated.text }), }; } diff --git a/src/captcha/captcha.service.ts b/src/captcha/captcha.service.ts index 387b7dd..c7a8149 100644 --- a/src/captcha/captcha.service.ts +++ b/src/captcha/captcha.service.ts @@ -3,15 +3,13 @@ import { ConfigService } from "@nestjs/config"; import * as svgCaptcha from "svg-captcha"; export interface GeneratedCaptcha { - text?: string; + text: string; image: string; expiresAt: number; } @Injectable() export class CaptchaService { - constructor(private readonly configService: ConfigService) {} - generate(): GeneratedCaptcha { const captcha = svgCaptcha.create({ size: 5, @@ -24,13 +22,6 @@ export class CaptchaService { fontSize: 52, }); - if (this.configService.get("NODE_ENV") === "production") { - return { - image: `data:image/svg+xml;base64,${Buffer.from(captcha.data, "utf8").toString("base64")}`, - expiresAt: this.buildExpireAt(), - }; - } - return { text: captcha.text, image: `data:image/svg+xml;base64,${Buffer.from(captcha.data, "utf8").toString("base64")}`,