refactor(api): remove auth cookie checks
just get the authorization header
This commit is contained in:
		
							parent
							
								
									ec13656660
								
							
						
					
					
						commit
						4139f6fd58
					
				| @ -1,6 +1,6 @@ | |||||||
| export default eventHandler((event) => { | export default eventHandler((event) => { | ||||||
| 	let ahead = (getHeaders(event).authorization || getCookie(event, "auth:token") || "")?.replace("Bearer ", ""); | 	let ahead = (getHeaders(event).authorization || "")?.replace("Bearer ", ""); | ||||||
| 	if (event.context.currentUser) { | 	if (event.context.currentUser && ahead) { | ||||||
| 		return { | 		return { | ||||||
| 			token: ahead, | 			token: ahead, | ||||||
| 			user: event.context.currentUser, | 			user: event.context.currentUser, | ||||||
|  | |||||||
| @ -2,19 +2,26 @@ import jwt from "jsonwebtoken"; | |||||||
| import { log } from "@server/logger"; | import { log } from "@server/logger"; | ||||||
| import { messages } from "@server/constants"; | import { messages } from "@server/constants"; | ||||||
| import { User } from "@models/user"; | import { User } from "@models/user"; | ||||||
|  | import { AccessToken } from "@models/oauth"; | ||||||
|  | import { IJwt } from "@server/types/authstuff"; | ||||||
| 
 | 
 | ||||||
| export default defineEventHandler(async (event) => { | export default defineEventHandler(async (event) => { | ||||||
| 	let ahead = (getHeaders(event).authorization || getCookie(event, "auth:token") || "")?.replace("Bearer ", ""); | 	let ahead = (getHeaders(event).authorization || "")?.replace("Bearer ", ""); | ||||||
| 	// console.log("in here fucknuts", ahead);
 |  | ||||||
| 	// log.debug(`'${ahead}'`, { label: "idk" });
 |  | ||||||
| 	if (ahead) { | 	if (ahead) { | ||||||
| 		let toktok = jwt.verify( | 		let toktok: jwt.JwtPayload; | ||||||
| 			ahead, | 		try { | ||||||
| 			// ahead.replace("Bearer ", ""),
 | 			toktok = jwt.verify(ahead, useRuntimeConfig().jwt) as IJwt; | ||||||
| 			useRuntimeConfig().jwt, |  | ||||||
| 		) as jwt.JwtPayload; |  | ||||||
| 			let user = await User.findById(toktok.id as number).exec(); | 			let user = await User.findById(toktok.id as number).exec(); | ||||||
| 			if (user && toktok) event.context.currentUser = user; | 			if (user && toktok) event.context.currentUser = user; | ||||||
| 		// setCookie(event, "auth:token", ahead)
 | 		} catch (e) { | ||||||
|  | 			const t = await AccessToken.findOne({ token: ahead }); | ||||||
|  | 			if (!t) | ||||||
|  | 				throw createError({ | ||||||
|  | 					statusCode: 401, | ||||||
|  | 					message: messages[401], | ||||||
|  | 				}); | ||||||
|  | 			let user = await User.findById(t.userID); | ||||||
|  | 			if (user) event.context.currentUser = user; | ||||||
|  | 		} | ||||||
| 	} | 	} | ||||||
| }); | }); | ||||||
|  | |||||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user