New API + API Token Updates
This commit is contained in:
@@ -1,12 +1,27 @@
|
||||
import { defineMiddleware } from 'astro/middleware';
|
||||
import { validateSession } from './lib/auth';
|
||||
import { defineMiddleware } from "astro/middleware";
|
||||
import { validateSession } from "./lib/auth";
|
||||
import { validateApiToken } from "./lib/api-auth";
|
||||
|
||||
export const onRequest = defineMiddleware(async (context, next) => {
|
||||
const sessionId = context.cookies.get('session_id')?.value;
|
||||
const authHeader = context.request.headers.get("Authorization");
|
||||
if (authHeader?.startsWith("Bearer ")) {
|
||||
const token = authHeader.substring(7);
|
||||
const result = await validateApiToken(token);
|
||||
|
||||
if (result) {
|
||||
context.locals.user = result.user;
|
||||
context.locals.session = null;
|
||||
context.locals.scopes = result.scopes;
|
||||
return next();
|
||||
}
|
||||
}
|
||||
|
||||
const sessionId = context.cookies.get("session_id")?.value;
|
||||
|
||||
if (!sessionId) {
|
||||
context.locals.user = null;
|
||||
context.locals.session = null;
|
||||
context.locals.scopes = null;
|
||||
return next();
|
||||
}
|
||||
|
||||
@@ -15,10 +30,12 @@ export const onRequest = defineMiddleware(async (context, next) => {
|
||||
if (result) {
|
||||
context.locals.user = result.user;
|
||||
context.locals.session = result.session;
|
||||
context.locals.scopes = null;
|
||||
} else {
|
||||
context.locals.user = null;
|
||||
context.locals.session = null;
|
||||
context.cookies.delete('session_id');
|
||||
context.locals.scopes = null;
|
||||
context.cookies.delete("session_id");
|
||||
}
|
||||
|
||||
return next();
|
||||
|
||||
Reference in New Issue
Block a user