fix(auth): add bearer token auth as fallback for Android WebView third-party cookie blocking
Android WebView blocks third-party cookies by default. This patch: - Returns session token in login/register response body - Stores token in localStorage, sends via Authorization: Bearer header - Backend getCurrentUser supports Authorization header fallback Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -61,6 +61,19 @@ export function readSessionToken(cookieHeader: string | null | undefined) {
|
||||
return decodeURIComponent(sessionCookie.slice(sessionCookieName.length + 1));
|
||||
}
|
||||
|
||||
/**
|
||||
* Extract bearer token from Authorization header.
|
||||
* Used as fallback when cookies are blocked (e.g. Android WebView third-party blocking).
|
||||
*/
|
||||
export function readBearerToken(headers?: { get(name: string): string | null }) {
|
||||
if (!headers) return null;
|
||||
const auth = headers.get('authorization');
|
||||
if (!auth) return null;
|
||||
const parts = auth.split(' ');
|
||||
if (parts.length !== 2 || parts[0] !== 'Bearer') return null;
|
||||
return parts[1];
|
||||
}
|
||||
|
||||
export async function createSession(userId: string) {
|
||||
const db = createDbClient();
|
||||
const token = randomBytes(32).toString('base64url');
|
||||
@@ -83,8 +96,12 @@ export async function deleteSession(token: string | null) {
|
||||
await db.delete(sessions).where(eq(sessions.tokenHash, hashToken(token)));
|
||||
}
|
||||
|
||||
export async function getCurrentUser(cookieHeader: string | null | undefined): Promise<CurrentUser | null> {
|
||||
const token = readSessionToken(cookieHeader);
|
||||
export async function getCurrentUser(
|
||||
cookieHeader: string | null | undefined,
|
||||
headers?: { get(name: string): string | null },
|
||||
): Promise<CurrentUser | null> {
|
||||
// Try cookie first, then Authorization header (for Android WebView where 3rd-party cookies are blocked)
|
||||
const token = readSessionToken(cookieHeader) ?? readBearerToken(headers);
|
||||
if (!token) return null;
|
||||
|
||||
const db = createDbClient();
|
||||
|
||||
@@ -32,7 +32,7 @@ function validatePassword(password: unknown) {
|
||||
|
||||
export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
||||
.get('/me', async ({ request }) => {
|
||||
const user = await getCurrentUser(request.headers.get('cookie'));
|
||||
const user = await getCurrentUser(request.headers.get('cookie'), request.headers);
|
||||
return {
|
||||
user,
|
||||
features: getAuthFeatures(),
|
||||
@@ -73,6 +73,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
||||
name: user.name,
|
||||
role: 'user' as const,
|
||||
},
|
||||
token,
|
||||
features: getAuthFeatures(),
|
||||
};
|
||||
} catch (error) {
|
||||
@@ -109,6 +110,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
||||
name: user.name,
|
||||
role: user.role === 'expert' ? 'expert' as const : 'user' as const,
|
||||
},
|
||||
token,
|
||||
features: getAuthFeatures(),
|
||||
};
|
||||
} catch (error) {
|
||||
|
||||
Reference in New Issue
Block a user