fix(auth) : keep Guide sessions beyond Sudloh token expiry
CI / Verify (push) Successful in 1m31s
CI / Build immutable images and deploy (push) Successful in 2m16s

This commit is contained in:
2026-10-06 18:00:42 +07:00 Unverified
parent 41014ef654
commit 4b16941e11
14 changed files with 74 additions and 236 deletions
+3 -6
View File
@@ -1,5 +1,5 @@
import { getCustomerSession, isSudlohOidcEnabled } from "@/lib/auth/server";
import { refreshLinkedSudlohProfile, validateSudlohSession } from "@/lib/auth/sudloh";
import { getCustomerSession } from "@/lib/auth/server";
import { refreshLinkedSudlohProfile } from "@/lib/auth/sudloh";
import { errorResponse, HttpError, requireSameOrigin } from "@/lib/security/http";
export async function POST(request: Request) {
@@ -7,10 +7,7 @@ export async function POST(request: Request) {
requireSameOrigin(request);
const session = await getCustomerSession();
if (!session) throw new HttpError(401, "unauthorized");
if (isSudlohOidcEnabled() && process.env.SUDLOH_OIDC_ONLY === "true") {
if (!await validateSudlohSession(session.user.id, session.session.id, true))
throw new HttpError(401, "sudloh-session-expired");
} else await refreshLinkedSudlohProfile(session.user.id);
await refreshLinkedSudlohProfile(session.user.id);
return Response.json({ ok: true }, { headers: { "Cache-Control": "no-store" } });
} catch (cause) { return errorResponse(cause); }
}