fix(auth): add bearer token auth as fallback for Android WebView third-party cookie blocking

Android WebView blocks third-party cookies by default. This patch:
- Returns session token in login/register response body
- Stores token in localStorage, sends via Authorization: Bearer header
- Backend getCurrentUser supports Authorization header fallback

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
MythEclipse
2026-06-15 19:43:02 +07:00
co-authored by Claude
parent 528a1622d0
commit 7693a02c98
4 changed files with 66 additions and 7 deletions
+19 -2
View File
@@ -61,6 +61,19 @@ export function readSessionToken(cookieHeader: string | null | undefined) {
return decodeURIComponent(sessionCookie.slice(sessionCookieName.length + 1));
}
/**
* Extract bearer token from Authorization header.
* Used as fallback when cookies are blocked (e.g. Android WebView third-party blocking).
*/
export function readBearerToken(headers?: { get(name: string): string | null }) {
if (!headers) return null;
const auth = headers.get('authorization');
if (!auth) return null;
const parts = auth.split(' ');
if (parts.length !== 2 || parts[0] !== 'Bearer') return null;
return parts[1];
}
export async function createSession(userId: string) {
const db = createDbClient();
const token = randomBytes(32).toString('base64url');
@@ -83,8 +96,12 @@ export async function deleteSession(token: string | null) {
await db.delete(sessions).where(eq(sessions.tokenHash, hashToken(token)));
}
export async function getCurrentUser(cookieHeader: string | null | undefined): Promise<CurrentUser | null> {
const token = readSessionToken(cookieHeader);
export async function getCurrentUser(
cookieHeader: string | null | undefined,
headers?: { get(name: string): string | null },
): Promise<CurrentUser | null> {
// Try cookie first, then Authorization header (for Android WebView where 3rd-party cookies are blocked)
const token = readSessionToken(cookieHeader) ?? readBearerToken(headers);
if (!token) return null;
const db = createDbClient();