Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
250355562f | ||
|
|
d47c73308e | ||
|
|
4b1d70d1c4 |
@@ -179,6 +179,9 @@ jobs:
|
||||
SESSION_SECRET=${{ secrets.SESSION_SECRET }}
|
||||
WEB_APP_URL=https://zeavisedu.asepharyana.my.id
|
||||
ML_SERVICE_URL=http://zeavis-ml:8000
|
||||
GOOGLE_CLIENT_ID=${{ secrets.GOOGLE_CLIENT_ID }}
|
||||
GOOGLE_CLIENT_SECRET=${{ secrets.GOOGLE_CLIENT_SECRET }}
|
||||
GOOGLE_REDIRECT_URI=https://zeavisedu.asepharyana.my.id/api/v1/auth/google/callback
|
||||
ENVEOF
|
||||
} > .env
|
||||
|
||||
|
||||
@@ -186,7 +186,8 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
||||
prompt: 'select_account',
|
||||
});
|
||||
|
||||
set.redirect = `https://accounts.google.com/o/oauth2/v2/auth?${params.toString()}`;
|
||||
set.status = 302;
|
||||
set.headers['Location'] = `https://accounts.google.com/o/oauth2/v2/auth?${params.toString()}`;
|
||||
})
|
||||
.get('/google/callback', async ({ query, set, request }) => {
|
||||
if (!env.googleOAuthEnabled) {
|
||||
@@ -199,7 +200,8 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
||||
|
||||
// User denied or Google returned an error
|
||||
if (error || !code) {
|
||||
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent(error ?? 'missing_code')}`;
|
||||
set.status = 302;
|
||||
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent(error ?? 'missing_code')}`;
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -210,13 +212,15 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
||||
idPayload = decodeGoogleIdToken(tokens.id_token);
|
||||
} catch (err) {
|
||||
const msg = err instanceof Error ? err.message : 'Google auth failed';
|
||||
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent(msg)}`;
|
||||
set.status = 302;
|
||||
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent(msg)}`;
|
||||
return;
|
||||
}
|
||||
|
||||
// Validate email
|
||||
if (!idPayload.email_verified || !idPayload.email) {
|
||||
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent('Email not verified by Google')}`;
|
||||
set.status = 302;
|
||||
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent('Email not verified by Google')}`;
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -256,8 +260,10 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
||||
authCounter.labels('login', 'true').inc();
|
||||
|
||||
// Redirect to web app with token in URL for localStorage fallback
|
||||
set.redirect = `${env.webAppUrl}/login?token=${encodeURIComponent(token)}`;
|
||||
set.status = 302;
|
||||
set.headers['Location'] = `${env.webAppUrl}/login?token=${encodeURIComponent(token)}`;
|
||||
} catch (err) {
|
||||
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent('Database unavailable')}`;
|
||||
set.status = 302;
|
||||
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent('Database unavailable')}`;
|
||||
}
|
||||
});
|
||||
|
||||
@@ -1,23 +1,28 @@
|
||||
import { useState, useEffect, useRef } from "react";
|
||||
import { Link, useNavigate, useSearchParams } from "react-router-dom";
|
||||
import { Link, useNavigate } from "react-router-dom";
|
||||
import { useMutation, useQuery, useQueryClient } from "@tanstack/react-query";
|
||||
import { AuthForm } from "@/components/auth-form";
|
||||
import { apiClient, setAuthToken } from "@/lib/api-client";
|
||||
import { useAuthStore } from "@/store/auth-store";
|
||||
|
||||
function getUrlParam(name: string): string | null {
|
||||
return new URLSearchParams(window.location.search).get(name);
|
||||
}
|
||||
|
||||
export function LoginPage() {
|
||||
const navigate = useNavigate();
|
||||
const queryClient = useQueryClient();
|
||||
const setUser = useAuthStore((state) => state.setUser);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [searchParams] = useSearchParams();
|
||||
const oauthTokenConsumed = useRef(false);
|
||||
const [oauthProcessing, setOauthProcessing] = useState(false);
|
||||
|
||||
// Handle OAuth callback: the API redirects to /login?token=<session_token>
|
||||
useEffect(() => {
|
||||
const token = searchParams.get("token");
|
||||
const token = getUrlParam("token");
|
||||
if (!token || oauthTokenConsumed.current) return;
|
||||
oauthTokenConsumed.current = true;
|
||||
setOauthProcessing(true);
|
||||
|
||||
// Store token for future API calls and fetch user
|
||||
setAuthToken(token);
|
||||
@@ -31,12 +36,13 @@ export function LoginPage() {
|
||||
})
|
||||
.catch((err) => {
|
||||
setAuthToken(null);
|
||||
setOauthProcessing(false);
|
||||
setError(err instanceof Error ? err.message : "Google login gagal");
|
||||
});
|
||||
}, [searchParams, setUser, queryClient, navigate]);
|
||||
}, [setUser, queryClient, navigate]);
|
||||
|
||||
// Show OAuth error from query param
|
||||
const oauthError = searchParams.get("error");
|
||||
const oauthError = getUrlParam("error");
|
||||
const meQuery = useQuery({
|
||||
queryKey: ["auth", "me"],
|
||||
queryFn: () => apiClient.getMe(),
|
||||
@@ -53,6 +59,18 @@ export function LoginPage() {
|
||||
setError(err instanceof Error ? err.message : "Login gagal"),
|
||||
});
|
||||
|
||||
// Show loading spinner while OAuth token is being processed
|
||||
if (oauthProcessing) {
|
||||
return (
|
||||
<main className="flex min-h-screen items-center justify-center px-6 py-12">
|
||||
<div className="flex flex-col items-center gap-3">
|
||||
<div className="h-10 w-10 border-4 border-green-500 border-t-transparent rounded-full animate-spin" />
|
||||
<p className="text-gray-500 text-sm">Menyelesaikan login dengan Google...</p>
|
||||
</div>
|
||||
</main>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<main className="flex min-h-screen items-center justify-center px-6 py-12">
|
||||
<div className="w-full max-w-sm md:max-w-md space-y-4">
|
||||
|
||||
Reference in New Issue
Block a user