feat(auth) : sync Sudloh profiles and validate sessions
This commit is contained in:
@@ -1,17 +1,54 @@
|
||||
import { toNextJsHandler } from "better-auth/next-js";
|
||||
import { and, eq } from "drizzle-orm";
|
||||
|
||||
import { getAuth } from "@/lib/auth/server";
|
||||
import { getAuth, isSudlohOidcEnabled } from "@/lib/auth/server";
|
||||
import { validateSudlohSession } from "@/lib/auth/sudloh";
|
||||
import { getDb } from "@/db";
|
||||
import { accounts } from "@/db/schema";
|
||||
import { errorResponse, HttpError, readJson, requireSameOrigin } from "@/lib/security/http";
|
||||
|
||||
const handlers = toNextJsHandler((request) => getAuth().handler(request));
|
||||
|
||||
export const GET = handlers.GET;
|
||||
async function hasActiveSudlohSession(request: Request): Promise<boolean | null> {
|
||||
if (!isSudlohOidcEnabled() || process.env.SUDLOH_OIDC_ONLY !== "true") return null;
|
||||
const session = await getAuth().api.getSession({ headers: request.headers });
|
||||
if (!session) return null;
|
||||
return validateSudlohSession(session.user.id, session.session.id);
|
||||
}
|
||||
|
||||
export async function GET(request: Request) {
|
||||
const path = new URL(request.url).pathname;
|
||||
if (!path.endsWith("/callback/sudloh")) {
|
||||
try {
|
||||
const active = await hasActiveSudlohSession(request);
|
||||
if (active === false) {
|
||||
if (path.endsWith("/get-session"))
|
||||
return Response.json(null, { headers: { "Cache-Control": "no-store" } });
|
||||
throw new HttpError(401, "unauthorized");
|
||||
}
|
||||
} catch (cause) { return errorResponse(cause); }
|
||||
}
|
||||
return handlers.GET(request);
|
||||
}
|
||||
|
||||
async function mutate(request: Request) {
|
||||
try {
|
||||
requireSameOrigin(request);
|
||||
const input = await readJson(request.clone());
|
||||
const path = new URL(request.url).pathname;
|
||||
if (!path.endsWith("/sign-in/social") && !path.endsWith("/sign-out") &&
|
||||
await hasActiveSudlohSession(request) === false) throw new HttpError(401, "unauthorized");
|
||||
if (["/update-user", "/change-email"].some((endpoint) => path.endsWith(endpoint))) {
|
||||
if (isSudlohOidcEnabled() && process.env.SUDLOH_OIDC_ONLY === "true")
|
||||
throw new HttpError(403, "manage-profile-at-sudloh");
|
||||
const session = await getAuth().api.getSession({ headers: request.headers });
|
||||
if (session) {
|
||||
const [linked] = await getDb().select({ id: accounts.id }).from(accounts).where(and(
|
||||
eq(accounts.userId, session.user.id), eq(accounts.providerId, "sudloh"),
|
||||
)).limit(1);
|
||||
if (linked) throw new HttpError(403, "manage-profile-at-sudloh");
|
||||
}
|
||||
}
|
||||
if (["/admin/create-user", "/admin/set-user-password"].some((endpoint) => path.endsWith(endpoint))) {
|
||||
const password = input && typeof input === "object" && "password" in input ? input.password : undefined;
|
||||
const newPassword = input && typeof input === "object" && "newPassword" in input ? input.newPassword : undefined;
|
||||
|
||||
Reference in New Issue
Block a user