diff --git a/src/app/api/auth/auth.ts b/src/app/api/auth/auth.ts index dc92c34..fa28cea 100644 --- a/src/app/api/auth/auth.ts +++ b/src/app/api/auth/auth.ts @@ -1,11 +1,11 @@ import { StringMap } from "@/types/typeUtils"; type ServerAuth = { - server_ip: string; - user_id: number; + server_ip: string; + user_id: number; }; // { token: userid } export const CLIENT_AUTH_TOKENS: StringMap = {}; -export const SERVER_AUTH_TOKENS: StringMap = {}; \ No newline at end of file +export const SERVER_AUTH_TOKENS: StringMap = {}; diff --git a/src/app/api/auth/route.ts b/src/app/api/auth/route.ts index c7b86c4..d87a16d 100644 --- a/src/app/api/auth/route.ts +++ b/src/app/api/auth/route.ts @@ -1,25 +1,39 @@ import { NextRequest, NextResponse } from "next/server"; import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth"; import { StatusCodes } from "http-status-codes"; +import axios from "axios"; export async function GET(req: NextRequest) { const url = new URL(req.url); - const token = url.searchParams.get('token'); + const token = url.searchParams.get("token"); if (!token) - return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.BAD_REQUEST }); + return NextResponse.json( + { message: "There should be a token parameter" }, + { status: StatusCodes.BAD_REQUEST } + ); const auth = SERVER_AUTH_TOKENS[token]; if (!auth) - return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND }); + return NextResponse.json( + { message: "Invalid token" }, + { status: StatusCodes.NOT_FOUND } + ); - const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1'); + const ip = + req.headers.get("x-real-ip") || + req.headers.get("x-forwarded-for")?.split(",")[0] || + "127.0.0.1"; - if (auth.server_ip !== ip) { - return NextResponse.json({ message: "Invalid address" }, { status: StatusCodes.UNAUTHORIZED }); + // ::1 for testing + if (auth.server_ip !== ip && ip !== "::1") { + return NextResponse.json( + { message: "Invalid address" }, + { status: StatusCodes.UNAUTHORIZED } + ); } - + delete SERVER_AUTH_TOKENS[token]; return NextResponse.json({ message: "ok", ...auth }); @@ -33,7 +47,10 @@ export async function POST(req: NextRequest) { const user_id = CLIENT_AUTH_TOKENS[session_token]; if (!user_id) - return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND }); + return NextResponse.json( + { message: "Invalid token" }, + { status: StatusCodes.NOT_FOUND } + ); SERVER_AUTH_TOKENS[token] = { user_id, diff --git a/src/app/api/route.ts b/src/app/api/route.ts index 6fb6bca..1248f27 100644 --- a/src/app/api/route.ts +++ b/src/app/api/route.ts @@ -2,4 +2,4 @@ import { NextResponse } from "next/server"; export async function GET() { return NextResponse.json({ message: "ok", version: "0.0.1" }); -} \ No newline at end of file +} diff --git a/src/app/server/[id]/page.tsx b/src/app/server/[id]/page.tsx index 7f0b851..ebef06f 100644 --- a/src/app/server/[id]/page.tsx +++ b/src/app/server/[id]/page.tsx @@ -23,8 +23,8 @@ export default function Server() { async function auth() { const server_auth = ( ( - await axios.post("http://localhost:3000/api/auth", { - server_ip: ip === "localhost" ? "127.0.0.1" : ip, + await axios.post("/api/auth", { + server_ip: ip, session_token: Cookies.get("token"), }) ).data as any diff --git a/src/hooks/get-user.ts b/src/hooks/get-user.ts index 85cdcb6..2d981ad 100644 --- a/src/hooks/get-user.ts +++ b/src/hooks/get-user.ts @@ -26,7 +26,7 @@ export default function useUser() { try { const res = ( - await axios.get("http://localhost:3000/api/user", { + await axios.get("/api/user", { params: { token }, }) ).data as User;