Replace the hybrid flow (frontend PKCE + POST /auth/session token exchange, access token in sessionStorage) with a classic backend-driven BFF: the browser only ever navigates to GET /api/v1/auth/login and is redirected straight to the IdP; PKCE verifier/state live server-side in Redis (SessionStoreService); GET /api/v1/auth/callback (now the registered IdP redirect URI, replacing the frontend's /auth/callback route, which is deleted) verifies the id_token, JIT-provisions the user, creates a Redis-backed session, and sets one httpOnly SameSite=Lax cookie before redirecting into the app. No token material of any kind ever reaches the browser. OidcAuthGuard (per-request bearer JWT verification) is replaced by SessionAuthGuard (cookie -> Redis session lookup) across every controller that used it. cookie-parser is now wired into main.ts. Frontend AuthService shrinks to login()/logout()/ensureSessionChecked(); pkce.ts, auth.interceptor.ts, and the callback component/route are all removed as dead code under this model. New required env var: APP_BASE_URL (source of truth for the OIDC redirect_uri and the post-login redirect target). Verified end-to-end against the real API, Redis, and a mocked IdP: login redirect shape, callback cookie + redirect, state-replay rejection, /users/me 401<->200 around the cookie, and logout.
69 lines
1.9 KiB
TypeScript
69 lines
1.9 KiB
TypeScript
import {
|
|
Body,
|
|
Controller,
|
|
Delete,
|
|
Get,
|
|
Param,
|
|
Post,
|
|
UseGuards,
|
|
} from '@nestjs/common';
|
|
import { SessionAuthGuard } from '../../../../libs/auth/src';
|
|
import type { SessionUser } from '../../../../libs/auth/src';
|
|
import {
|
|
TripInvitationsService,
|
|
TripMembershipGuard,
|
|
TripRoles,
|
|
} from '../../../../libs/trips/src';
|
|
import type { TripInvitation, TripMember } from '../../../../libs/trips/src';
|
|
import { CurrentUser } from '../auth/current-user.decorator';
|
|
|
|
interface CreateTripInvitationDto {
|
|
email: string;
|
|
}
|
|
|
|
@Controller()
|
|
export class TripInvitationsController {
|
|
constructor(private readonly invitationsService: TripInvitationsService) {}
|
|
|
|
@Post('trips/:tripId/invitations')
|
|
@UseGuards(SessionAuthGuard, TripMembershipGuard)
|
|
@TripRoles('OWNER')
|
|
create(
|
|
@Param('tripId') tripId: string,
|
|
@CurrentUser() currentUser: SessionUser,
|
|
@Body() dto: CreateTripInvitationDto,
|
|
): Promise<{ invitation: TripInvitation; rawToken: string }> {
|
|
return this.invitationsService.createInvitation(
|
|
tripId,
|
|
currentUser.id,
|
|
dto.email,
|
|
);
|
|
}
|
|
|
|
@Get('trips/:tripId/invitations')
|
|
@UseGuards(SessionAuthGuard, TripMembershipGuard)
|
|
@TripRoles('OWNER')
|
|
list(@Param('tripId') tripId: string): Promise<TripInvitation[]> {
|
|
return this.invitationsService.listInvitations(tripId);
|
|
}
|
|
|
|
@Delete('trips/:tripId/invitations/:invitationId')
|
|
@UseGuards(SessionAuthGuard, TripMembershipGuard)
|
|
@TripRoles('OWNER')
|
|
remove(
|
|
@Param('tripId') tripId: string,
|
|
@Param('invitationId') invitationId: string,
|
|
): Promise<void> {
|
|
return this.invitationsService.removeInvitation(tripId, invitationId);
|
|
}
|
|
|
|
@Post('invitations/:token/accept')
|
|
@UseGuards(SessionAuthGuard)
|
|
accept(
|
|
@Param('token') token: string,
|
|
@CurrentUser() currentUser: SessionUser,
|
|
): Promise<TripMember> {
|
|
return this.invitationsService.acceptInvitation(token, currentUser.id);
|
|
}
|
|
}
|