feat(auth): finish Turnstile coverage across every auth entry point

Turnstile protected sign-in, sign-up and password-reset, but three gaps
remained:

- updatePassword had no verification and its page had no widget, so the
  final step of the reset flow was unprotected. The reset token is now
  carried through the failure redirect so a failed challenge doesn't
  strand the user on a form whose emailed link can't be replayed.

- /api/auth/[...all] exposed better-auth's handler directly, accepting
  unlimited credential guesses and email sends with no bot protection --
  a full bypass of the page-level checks. Credential-bearing POSTs now
  require a verified token. The gate lives in the route handler, so the
  server actions (which call auth.api.* in-process) are unaffected. GET
  is untouched for OAuth callbacks and verify-email links, and
  /sign-in/social stays open since it only redirects to the provider.

- Turnstile tokens expire after ~5 minutes and the widget never reset,
  so a form left open submitted a stale token and failed with "complete
  the verification challenge" despite the challenge visibly passing.

Verified with Cloudflare's test keys: all four auth forms block an
invalid token, pass a valid one through to real auth logic, and the API
gate returns 403 without a token and 401 with one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-09-05 16:26:16 -04:00
co-authored by Claude Opus 5
parent 595a5e3e04
commit 8f90347659
4 changed files with 103 additions and 2 deletions
+11
View File
@@ -1,7 +1,16 @@
import type { Metadata } from "next"
import Link from "next/link"
import { Logo } from "@/components/shared/logo"
import { TurnstileWidget } from "@/components/shared/turnstile-widget"
import { updatePassword } from "@/app/actions/auth"
// A password-reset form reached from a one-time emailed link — nothing here
// should ever enter the index.
export const metadata: Metadata = {
title: "Set a new password",
robots: { index: false, follow: false },
}
export default async function UpdatePasswordPage({
searchParams,
}: {
@@ -43,6 +52,8 @@ export default async function UpdatePasswordPage({
/>
</div>
<TurnstileWidget />
<button
type="submit"
className="w-full rounded-lg bg-indigo-600 px-4 py-2.5 text-sm font-semibold text-white transition hover:bg-indigo-500 active:scale-[0.98]"