fix(auth) : bind Sudloh sessions and stop OAuth redirect loops
CI / Verify (push) Successful in 1m31s
CI / Build immutable images and deploy (push) Successful in 2m4s

This commit is contained in:
2026-10-06 14:28:59 +07:00 Unverified
parent 2f69115a91
commit 445865bf42
13 changed files with 212 additions and 21 deletions
+5 -2
View File
@@ -20,6 +20,7 @@ import { HttpError } from "@/lib/security/http";
import { consumeRateLimit } from "@/lib/security/rate-limit";
import { sendAuthEmail } from "./email";
import { bindSudlohSession, validateSudlohSession } from "./sudloh";
import { isSudlohCallback } from "./sudloh-callback";
function required(name: string): string {
const value = process.env[name];
@@ -65,9 +66,11 @@ function createAuth() {
transaction: true,
}),
...(oidcOnly ? { databaseHooks: { session: { create: { after: async (
session: { id: string; userId: string }, context: { path: string } | null,
session: { id: string; userId: string },
context: { path: string; params?: { id?: string } } | null,
) => {
if (context?.path.endsWith("/callback/sudloh")) await bindSudlohSession(session.userId, session.id);
if (isSudlohCallback(context))
await bindSudlohSession(session.userId, session.id);
} } } } } : {}),
baseURL: required("BETTER_AUTH_URL"),
trustedOrigins: process.env.BETTER_AUTH_TRUSTED_ORIGINS