Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
528a1622d0 | ||
|
|
51a4cb9ed2 | ||
|
|
22307d44de |
@@ -11,6 +11,7 @@ const webAppUrl = Bun.env.WEB_APP_URL ?? 'http://localhost:5173';
|
|||||||
const allowedOrigins = [
|
const allowedOrigins = [
|
||||||
webAppUrl,
|
webAppUrl,
|
||||||
'https://tauri.localhost',
|
'https://tauri.localhost',
|
||||||
|
'http://tauri.localhost',
|
||||||
'tauri://localhost',
|
'tauri://localhost',
|
||||||
'http://localhost:5173',
|
'http://localhost:5173',
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -28,14 +28,26 @@ function hashToken(token: string) {
|
|||||||
return createHash('sha256').update(`${env.sessionSecret}:${token}`).digest('hex');
|
return createHash('sha256').update(`${env.sessionSecret}:${token}`).digest('hex');
|
||||||
}
|
}
|
||||||
|
|
||||||
export function createSessionCookie(token: string) {
|
function isSecureRequest(headers?: { get(name: string): string | null }) {
|
||||||
|
if (env.secureCookies) return true;
|
||||||
|
// Detect HTTPS behind proxy (X-Forwarded-Proto)
|
||||||
|
const proto = headers?.get('x-forwarded-proto');
|
||||||
|
if (proto === 'https') return true;
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
function buildSameSite(headers?: { get(name: string): string | null }) {
|
||||||
|
return isSecureRequest(headers) ? 'SameSite=None; Secure' : 'SameSite=Lax';
|
||||||
|
}
|
||||||
|
|
||||||
|
export function createSessionCookie(token: string, headers?: { get(name: string): string | null }) {
|
||||||
const maxAge = 60 * 60 * 24 * 30;
|
const maxAge = 60 * 60 * 24 * 30;
|
||||||
const sameSite = env.secureCookies ? 'SameSite=None; Secure' : 'SameSite=Lax';
|
const sameSite = buildSameSite(headers);
|
||||||
return `${sessionCookieName}=${token}; HttpOnly; Path=/; ${sameSite}; Max-Age=${maxAge}`;
|
return `${sessionCookieName}=${token}; HttpOnly; Path=/; ${sameSite}; Max-Age=${maxAge}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
export function clearSessionCookie() {
|
export function clearSessionCookie(headers?: { get(name: string): string | null }) {
|
||||||
const sameSite = env.secureCookies ? 'SameSite=None; Secure' : 'SameSite=Lax';
|
const sameSite = buildSameSite(headers);
|
||||||
return `${sessionCookieName}=; HttpOnly; Path=/; ${sameSite}; Max-Age=0`;
|
return `${sessionCookieName}=; HttpOnly; Path=/; ${sameSite}; Max-Age=0`;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
features: getAuthFeatures(),
|
features: getAuthFeatures(),
|
||||||
};
|
};
|
||||||
})
|
})
|
||||||
.post('/register', async ({ body, set }) => {
|
.post('/register', async ({ body, set, request }) => {
|
||||||
const req = body as Partial<RegisterRequest> | undefined;
|
const req = body as Partial<RegisterRequest> | undefined;
|
||||||
const email = normalizeEmail(req?.email);
|
const email = normalizeEmail(req?.email);
|
||||||
const name = normalizeName(req?.name);
|
const name = normalizeName(req?.name);
|
||||||
@@ -62,7 +62,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
|
|
||||||
const user = inserted[0];
|
const user = inserted[0];
|
||||||
const token = await createSession(user.id);
|
const token = await createSession(user.id);
|
||||||
set.headers['Set-Cookie'] = createSessionCookie(token);
|
set.headers['Set-Cookie'] = createSessionCookie(token, request.headers);
|
||||||
|
|
||||||
authCounter.labels('register', 'true').inc();
|
authCounter.labels('register', 'true').inc();
|
||||||
|
|
||||||
@@ -79,7 +79,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
return serviceUnavailable('Database unavailable');
|
return serviceUnavailable('Database unavailable');
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
.post('/login', async ({ body, set }) => {
|
.post('/login', async ({ body, set, request }) => {
|
||||||
const req = body as Partial<AuthRequest> | undefined;
|
const req = body as Partial<AuthRequest> | undefined;
|
||||||
const email = normalizeEmail(req?.email);
|
const email = normalizeEmail(req?.email);
|
||||||
|
|
||||||
@@ -98,7 +98,7 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
}
|
}
|
||||||
|
|
||||||
const token = await createSession(user.id);
|
const token = await createSession(user.id);
|
||||||
set.headers['Set-Cookie'] = createSessionCookie(token);
|
set.headers['Set-Cookie'] = createSessionCookie(token, request.headers);
|
||||||
|
|
||||||
authCounter.labels('login', 'true').inc();
|
authCounter.labels('login', 'true').inc();
|
||||||
|
|
||||||
@@ -116,8 +116,9 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
}
|
}
|
||||||
})
|
})
|
||||||
.post('/logout', async ({ request, set }) => {
|
.post('/logout', async ({ request, set }) => {
|
||||||
await deleteSession(readSessionToken(request.headers.get('cookie')));
|
const cookieHeader = request.headers.get('cookie');
|
||||||
set.headers['Set-Cookie'] = clearSessionCookie();
|
await deleteSession(readSessionToken(cookieHeader));
|
||||||
|
set.headers['Set-Cookie'] = clearSessionCookie(request.headers);
|
||||||
return { ok: true };
|
return { ok: true };
|
||||||
})
|
})
|
||||||
.get('/google', ({ set }) => {
|
.get('/google', ({ set }) => {
|
||||||
|
|||||||
Generated
+3
@@ -0,0 +1,3 @@
|
|||||||
|
# Default ignored files
|
||||||
|
/shelf/
|
||||||
|
/workspace.xml
|
||||||
+1870
File diff suppressed because it is too large
Load Diff
Generated
+13
@@ -0,0 +1,13 @@
|
|||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<project version="4">
|
||||||
|
<component name="DeviceTable">
|
||||||
|
<option name="columnSorters">
|
||||||
|
<list>
|
||||||
|
<ColumnSorterState>
|
||||||
|
<option name="column" value="Name" />
|
||||||
|
<option name="order" value="ASCENDING" />
|
||||||
|
</ColumnSorterState>
|
||||||
|
</list>
|
||||||
|
</option>
|
||||||
|
</component>
|
||||||
|
</project>
|
||||||
Generated
+17
@@ -0,0 +1,17 @@
|
|||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<project version="4">
|
||||||
|
<component name="DiscordProjectSettings">
|
||||||
|
<option name="show" value="ASK" />
|
||||||
|
<option name="description" value="" />
|
||||||
|
<option name="applicationTheme" value="default" />
|
||||||
|
<option name="iconsTheme" value="default" />
|
||||||
|
<option name="button1Title" value="" />
|
||||||
|
<option name="button1Url" value="" />
|
||||||
|
<option name="button2Title" value="" />
|
||||||
|
<option name="button2Url" value="" />
|
||||||
|
<option name="customApplicationId" value="" />
|
||||||
|
</component>
|
||||||
|
<component name="ProjectRootManager" version="2">
|
||||||
|
<output url="file://$PROJECT_DIR$/out" />
|
||||||
|
</component>
|
||||||
|
</project>
|
||||||
Generated
+8
@@ -0,0 +1,8 @@
|
|||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<project version="4">
|
||||||
|
<component name="ProjectModuleManager">
|
||||||
|
<modules>
|
||||||
|
<module fileurl="file://$PROJECT_DIR$/.idea/tauri.iml" filepath="$PROJECT_DIR$/.idea/tauri.iml" />
|
||||||
|
</modules>
|
||||||
|
</component>
|
||||||
|
</project>
|
||||||
Generated
+9
@@ -0,0 +1,9 @@
|
|||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<module type="JAVA_MODULE" version="4">
|
||||||
|
<component name="NewModuleRootManager" inherit-compiler-output="true">
|
||||||
|
<exclude-output />
|
||||||
|
<content url="file://$MODULE_DIR$" />
|
||||||
|
<orderEntry type="inheritedJdk" />
|
||||||
|
<orderEntry type="sourceFolder" forTests="false" />
|
||||||
|
</component>
|
||||||
|
</module>
|
||||||
Generated
+6
@@ -0,0 +1,6 @@
|
|||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<project version="4">
|
||||||
|
<component name="VcsDirectoryMappings">
|
||||||
|
<mapping directory="$PROJECT_DIR$/../.." vcs="Git" />
|
||||||
|
</component>
|
||||||
|
</project>
|
||||||
@@ -10,27 +10,32 @@ type AuthGuardProps = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
export function AuthGuard({ children, requireExpert = false }: AuthGuardProps) {
|
export function AuthGuard({ children, requireExpert = false }: AuthGuardProps) {
|
||||||
|
const user = useAuthStore((state) => state.user);
|
||||||
const setUser = useAuthStore((state) => state.setUser);
|
const setUser = useAuthStore((state) => state.setUser);
|
||||||
const query = useQuery({
|
const query = useQuery({
|
||||||
queryKey: ['auth', 'me'],
|
queryKey: ['auth', 'me'],
|
||||||
queryFn: () => apiClient.getMe(),
|
queryFn: () => apiClient.getMe(),
|
||||||
|
staleTime: 30_000,
|
||||||
});
|
});
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (query.data) {
|
if (query.data?.user) {
|
||||||
setUser(query.data.user);
|
setUser(query.data.user);
|
||||||
}
|
}
|
||||||
}, [query.data, setUser]);
|
}, [query.data, setUser]);
|
||||||
|
|
||||||
if (query.isLoading) {
|
// Tunjukkan loading hanya jika belum ada user di store
|
||||||
|
if (query.isLoading && !user) {
|
||||||
return <main className="min-h-screen p-8 text-center text-muted-foreground">Memeriksa sesi...</main>;
|
return <main className="min-h-screen p-8 text-center text-muted-foreground">Memeriksa sesi...</main>;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!query.data?.user) {
|
// Cek store dulu, baru query — mencegah redirect saat refetch background
|
||||||
|
const currentUser = query.data?.user ?? user;
|
||||||
|
if (!currentUser) {
|
||||||
return <Navigate to="/login" replace />;
|
return <Navigate to="/login" replace />;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (requireExpert && query.data.user.role !== 'expert') {
|
if (requireExpert && currentUser.role !== 'expert') {
|
||||||
return <Navigate to="/dashboard" replace />;
|
return <Navigate to="/dashboard" replace />;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -9,10 +9,11 @@ export function AuthInitializer() {
|
|||||||
queryKey: ['auth', 'me'],
|
queryKey: ['auth', 'me'],
|
||||||
queryFn: () => apiClient.getMe(),
|
queryFn: () => apiClient.getMe(),
|
||||||
retry: false,
|
retry: false,
|
||||||
|
staleTime: 30_000,
|
||||||
});
|
});
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (query.data) {
|
if (query.data?.user) {
|
||||||
setUser(query.data.user);
|
setUser(query.data.user);
|
||||||
}
|
}
|
||||||
}, [query.data, setUser]);
|
}, [query.data, setUser]);
|
||||||
|
|||||||
Reference in New Issue
Block a user