fix: allow refresh tokens in AuthMiddleware for refresh route and dispatch auth_error on 401s to force login redirect
All checks were successful
Automated Container Build / build-and-push (push) Successful in 1m23s
All checks were successful
Automated Container Build / build-and-push (push) Successful in 1m23s
This commit is contained in:
parent
4c8e6b814c
commit
fbad71cbf2
3 changed files with 19 additions and 2 deletions
|
|
@ -59,8 +59,14 @@ func AuthMiddleware(jwtSecret string) fiber.Handler {
|
||||||
return c.Status(fiber.StatusUnauthorized).JSON(fiber.Map{"error": "invalid token type for query parameter"})
|
return c.Status(fiber.StatusUnauthorized).JSON(fiber.Map{"error": "invalid token type for query parameter"})
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
if tokenType != "access" {
|
if c.Path() == "/api/auth/refresh" {
|
||||||
return c.Status(fiber.StatusUnauthorized).JSON(fiber.Map{"error": "invalid token type for authorization header"})
|
if tokenType != "refresh" {
|
||||||
|
return c.Status(fiber.StatusUnauthorized).JSON(fiber.Map{"error": "invalid token type for refresh endpoint"})
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
if tokenType != "access" {
|
||||||
|
return c.Status(fiber.StatusUnauthorized).JSON(fiber.Map{"error": "invalid token type for authorization header"})
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -13,6 +13,13 @@ export default function Home() {
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
checkState();
|
checkState();
|
||||||
|
|
||||||
|
const handleAuthError = () => {
|
||||||
|
api.clearTokens();
|
||||||
|
setState('login');
|
||||||
|
};
|
||||||
|
window.addEventListener('auth_error', handleAuthError);
|
||||||
|
return () => window.removeEventListener('auth_error', handleAuthError);
|
||||||
}, []);
|
}, []);
|
||||||
|
|
||||||
async function checkState() {
|
async function checkState() {
|
||||||
|
|
|
||||||
|
|
@ -81,6 +81,9 @@ class ApiClient {
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!response.ok && endpoint !== '/api/auth/refresh') {
|
if (!response.ok && endpoint !== '/api/auth/refresh') {
|
||||||
|
if (response.status === 401) {
|
||||||
|
if (typeof window !== 'undefined') window.dispatchEvent(new Event('auth_error'));
|
||||||
|
}
|
||||||
let errorMsg = `HTTP ${response.status}`;
|
let errorMsg = `HTTP ${response.status}`;
|
||||||
try {
|
try {
|
||||||
const errData = await response.clone().json();
|
const errData = await response.clone().json();
|
||||||
|
|
@ -111,6 +114,7 @@ class ApiClient {
|
||||||
}
|
}
|
||||||
|
|
||||||
this.clearTokens();
|
this.clearTokens();
|
||||||
|
if (typeof window !== 'undefined') window.dispatchEvent(new Event('auth_error'));
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Reference in a new issue