Compare commits

...
4 Commits
Author SHA1 Message Date
MythEclipseandClaude 787acf077f fix(vite): add data-cfasync="false" to script tags to prevent Cloudflare Rocket Loader breaking JS
Cloudflare Rocket Loader rewrites <script type="module"> to
<script type="randomhash-module"> which browsers can't parse,
causing complete blank page. data-cfasync="false" disables this.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 23:00:30 +07:00
MythEclipseandClaude 250355562f fix(login): replace useSearchParams with native URLSearchParams + loading spinner
- useSearchParams can lose params during re-renders, causing blank page
- Use native window.location.search + URLSearchParams instead (always accessible)
- Add oauthProcessing spinner state so user sees 'Menyelesaikan login...'
  instead of blank page while /auth/me is being called

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 22:38:11 +07:00
MythEclipseandClaude d47c73308e fix(auth): replace deprecated set.redirect with manual 302 Location header
Elysia's set.redirect returns 200 OK instead of 302 redirect on the
current version. Use set.status = 302 + set.headers['Location'] instead
for both /auth/google (Google OAuth redirect) and /auth/google/callback
(all redirect paths: errors, success token delivery).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 22:06:59 +07:00
MythEclipseandClaude 4b1d70d1c4 ci(deploy): inject Google OAuth env vars into VPS .env
Add GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, and GOOGLE_REDIRECT_URI
to the deploy workflow so the API can use Google OAuth on production.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-15 21:57:12 +07:00
4 changed files with 54 additions and 12 deletions
+3
View File
@@ -179,6 +179,9 @@ jobs:
SESSION_SECRET=${{ secrets.SESSION_SECRET }}
WEB_APP_URL=https://zeavisedu.asepharyana.my.id
ML_SERVICE_URL=http://zeavis-ml:8000
GOOGLE_CLIENT_ID=${{ secrets.GOOGLE_CLIENT_ID }}
GOOGLE_CLIENT_SECRET=${{ secrets.GOOGLE_CLIENT_SECRET }}
GOOGLE_REDIRECT_URI=https://zeavisedu.asepharyana.my.id/api/v1/auth/google/callback
ENVEOF
} > .env
+12 -6
View File
@@ -186,7 +186,8 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
prompt: 'select_account',
});
set.redirect = `https://accounts.google.com/o/oauth2/v2/auth?${params.toString()}`;
set.status = 302;
set.headers['Location'] = `https://accounts.google.com/o/oauth2/v2/auth?${params.toString()}`;
})
.get('/google/callback', async ({ query, set, request }) => {
if (!env.googleOAuthEnabled) {
@@ -199,7 +200,8 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
// User denied or Google returned an error
if (error || !code) {
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent(error ?? 'missing_code')}`;
set.status = 302;
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent(error ?? 'missing_code')}`;
return;
}
@@ -210,13 +212,15 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
idPayload = decodeGoogleIdToken(tokens.id_token);
} catch (err) {
const msg = err instanceof Error ? err.message : 'Google auth failed';
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent(msg)}`;
set.status = 302;
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent(msg)}`;
return;
}
// Validate email
if (!idPayload.email_verified || !idPayload.email) {
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent('Email not verified by Google')}`;
set.status = 302;
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent('Email not verified by Google')}`;
return;
}
@@ -256,8 +260,10 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
authCounter.labels('login', 'true').inc();
// Redirect to web app with token in URL for localStorage fallback
set.redirect = `${env.webAppUrl}/login?token=${encodeURIComponent(token)}`;
set.status = 302;
set.headers['Location'] = `${env.webAppUrl}/login?token=${encodeURIComponent(token)}`;
} catch (err) {
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent('Database unavailable')}`;
set.status = 302;
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent('Database unavailable')}`;
}
});
+23 -5
View File
@@ -1,23 +1,28 @@
import { useState, useEffect, useRef } from "react";
import { Link, useNavigate, useSearchParams } from "react-router-dom";
import { Link, useNavigate } from "react-router-dom";
import { useMutation, useQuery, useQueryClient } from "@tanstack/react-query";
import { AuthForm } from "@/components/auth-form";
import { apiClient, setAuthToken } from "@/lib/api-client";
import { useAuthStore } from "@/store/auth-store";
function getUrlParam(name: string): string | null {
return new URLSearchParams(window.location.search).get(name);
}
export function LoginPage() {
const navigate = useNavigate();
const queryClient = useQueryClient();
const setUser = useAuthStore((state) => state.setUser);
const [error, setError] = useState<string | null>(null);
const [searchParams] = useSearchParams();
const oauthTokenConsumed = useRef(false);
const [oauthProcessing, setOauthProcessing] = useState(false);
// Handle OAuth callback: the API redirects to /login?token=<session_token>
useEffect(() => {
const token = searchParams.get("token");
const token = getUrlParam("token");
if (!token || oauthTokenConsumed.current) return;
oauthTokenConsumed.current = true;
setOauthProcessing(true);
// Store token for future API calls and fetch user
setAuthToken(token);
@@ -31,12 +36,13 @@ export function LoginPage() {
})
.catch((err) => {
setAuthToken(null);
setOauthProcessing(false);
setError(err instanceof Error ? err.message : "Google login gagal");
});
}, [searchParams, setUser, queryClient, navigate]);
}, [setUser, queryClient, navigate]);
// Show OAuth error from query param
const oauthError = searchParams.get("error");
const oauthError = getUrlParam("error");
const meQuery = useQuery({
queryKey: ["auth", "me"],
queryFn: () => apiClient.getMe(),
@@ -53,6 +59,18 @@ export function LoginPage() {
setError(err instanceof Error ? err.message : "Login gagal"),
});
// Show loading spinner while OAuth token is being processed
if (oauthProcessing) {
return (
<main className="flex min-h-screen items-center justify-center px-6 py-12">
<div className="flex flex-col items-center gap-3">
<div className="h-10 w-10 border-4 border-green-500 border-t-transparent rounded-full animate-spin" />
<p className="text-gray-500 text-sm">Menyelesaikan login dengan Google...</p>
</div>
</main>
);
}
return (
<main className="flex min-h-screen items-center justify-center px-6 py-12">
<div className="w-full max-w-sm md:max-w-md space-y-4">
+16 -1
View File
@@ -9,7 +9,22 @@ export default defineConfig(({ mode }) => {
const apiProxyTarget = env.VITE_API_PROXY_TARGET || 'http://localhost:3000';
return {
plugins: [react(), tsconfigPaths(), metricsPlugin()],
plugins: [
react(),
tsconfigPaths(),
metricsPlugin(),
{
name: 'cloudflare-rocket-loader-fix',
transformIndexHtml(html) {
// Prevent Cloudflare Rocket Loader from mangling <script type="module">
// which breaks the entire JS bundle (blank page)
return html.replace(
/<script type="module"/g,
'<script data-cfasync="false" type="module"',
);
},
},
],
server: {
proxy: {
'/api': apiProxyTarget,