admin login issue for timeout issue
This commit is contained in:
@@ -1,8 +1,12 @@
|
||||
import {NextResponse} from 'next/server';
|
||||
import {authApi} from '@/services/api/authApi';
|
||||
import {UpstreamError} from '@/services/api/apiClient';
|
||||
import {SESSION_COOKIE, sessionCookieOptions} from '@/features/auth/services/sessionToken';
|
||||
import {TOKEN_COOKIE} from '@/features/auth/services/tokenStore';
|
||||
import {sessionCookieOptions} from '@/features/auth/services/sessionToken';
|
||||
import {
|
||||
sessionCookieFor,
|
||||
tokenCookieFor,
|
||||
} from '@/features/auth/services/tabScope';
|
||||
import {resolveTabId} from '@/features/auth/services/tabScopeRequest';
|
||||
import {NoSessionError, withUpstream} from '@/features/auth/services/upstreamSession';
|
||||
import {toAuthUser} from '@/features/auth/services/userMapper';
|
||||
import type {AuthSession} from '@/features/auth/types/auth';
|
||||
@@ -64,14 +68,37 @@ export async function GET() {
|
||||
{data: null, meta: {generatedAt: new Date().toISOString()}},
|
||||
{headers: {'cache-control': 'no-store'}},
|
||||
);
|
||||
res.cookies.set(SESSION_COOKIE, '', sessionCookieOptions(0));
|
||||
res.cookies.set(TOKEN_COOKIE, '', {
|
||||
httpOnly: true,
|
||||
sameSite: 'lax',
|
||||
secure: process.env.NODE_ENV === 'production',
|
||||
path: '/',
|
||||
maxAge: 0,
|
||||
});
|
||||
|
||||
/**
|
||||
* Clear THIS TAB's cookies, by their tab-scoped names.
|
||||
*
|
||||
* This used to clear `loyaly_session` and `loyaly_tokens` — the unscoped
|
||||
* names from before sessions were per-tab. Those cookies do not exist any
|
||||
* more, so the clear silently did nothing and a confirmed 401 left the
|
||||
* tab's real `loyaly_session_<tabId>` in place. The result was the
|
||||
* half-authenticated state upstreamSession warns about, with a twist: the
|
||||
* client set itself unauthenticated and went to /login, the proxy saw a
|
||||
* still-valid session cookie and sent it straight back, and the two flapped.
|
||||
*
|
||||
* Same two helpers the logout route uses, so there is one naming scheme and
|
||||
* the two paths cannot drift. Scoped to the resolved tab and no other: a
|
||||
* dead session in one tab says nothing about the others, and clearing more
|
||||
* than asked would sign out a tab that is working fine.
|
||||
*
|
||||
* A request with no resolvable tab clears nothing. There is no cookie to
|
||||
* name, and guessing would reach into somebody else's session.
|
||||
*/
|
||||
const tabId = await resolveTabId();
|
||||
if (tabId) {
|
||||
res.cookies.set(sessionCookieFor(tabId), '', sessionCookieOptions(0));
|
||||
res.cookies.set(tokenCookieFor(tabId), '', {
|
||||
httpOnly: true,
|
||||
sameSite: 'lax',
|
||||
secure: process.env.NODE_ENV === 'production',
|
||||
path: '/',
|
||||
maxAge: 0,
|
||||
});
|
||||
}
|
||||
return res;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user