Bug fixes
This commit is contained in:
@@ -1,11 +1,11 @@
|
|||||||
import { StringMap } from "@/types/typeUtils";
|
import { StringMap } from "@/types/typeUtils";
|
||||||
|
|
||||||
type ServerAuth = {
|
type ServerAuth = {
|
||||||
server_ip: string;
|
server_ip: string;
|
||||||
user_id: number;
|
user_id: number;
|
||||||
};
|
};
|
||||||
|
|
||||||
// { token: userid }
|
// { token: userid }
|
||||||
export const CLIENT_AUTH_TOKENS: StringMap<number> = {};
|
export const CLIENT_AUTH_TOKENS: StringMap<number> = {};
|
||||||
|
|
||||||
export const SERVER_AUTH_TOKENS: StringMap<ServerAuth> = {};
|
export const SERVER_AUTH_TOKENS: StringMap<ServerAuth> = {};
|
||||||
|
|||||||
@@ -1,25 +1,39 @@
|
|||||||
import { NextRequest, NextResponse } from "next/server";
|
import { NextRequest, NextResponse } from "next/server";
|
||||||
import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth";
|
import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth";
|
||||||
import { StatusCodes } from "http-status-codes";
|
import { StatusCodes } from "http-status-codes";
|
||||||
|
import axios from "axios";
|
||||||
|
|
||||||
export async function GET(req: NextRequest) {
|
export async function GET(req: NextRequest) {
|
||||||
const url = new URL(req.url);
|
const url = new URL(req.url);
|
||||||
const token = url.searchParams.get('token');
|
const token = url.searchParams.get("token");
|
||||||
|
|
||||||
if (!token)
|
if (!token)
|
||||||
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.BAD_REQUEST });
|
return NextResponse.json(
|
||||||
|
{ message: "There should be a token parameter" },
|
||||||
|
{ status: StatusCodes.BAD_REQUEST }
|
||||||
|
);
|
||||||
|
|
||||||
const auth = SERVER_AUTH_TOKENS[token];
|
const auth = SERVER_AUTH_TOKENS[token];
|
||||||
|
|
||||||
if (!auth)
|
if (!auth)
|
||||||
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
|
return NextResponse.json(
|
||||||
|
{ message: "Invalid token" },
|
||||||
|
{ status: StatusCodes.NOT_FOUND }
|
||||||
|
);
|
||||||
|
|
||||||
const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1');
|
const ip =
|
||||||
|
req.headers.get("x-real-ip") ||
|
||||||
|
req.headers.get("x-forwarded-for")?.split(",")[0] ||
|
||||||
|
"127.0.0.1";
|
||||||
|
|
||||||
if (auth.server_ip !== ip) {
|
// ::1 for testing
|
||||||
return NextResponse.json({ message: "Invalid address" }, { status: StatusCodes.UNAUTHORIZED });
|
if (auth.server_ip !== ip && ip !== "::1") {
|
||||||
|
return NextResponse.json(
|
||||||
|
{ message: "Invalid address" },
|
||||||
|
{ status: StatusCodes.UNAUTHORIZED }
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
delete SERVER_AUTH_TOKENS[token];
|
delete SERVER_AUTH_TOKENS[token];
|
||||||
|
|
||||||
return NextResponse.json({ message: "ok", ...auth });
|
return NextResponse.json({ message: "ok", ...auth });
|
||||||
@@ -33,7 +47,10 @@ export async function POST(req: NextRequest) {
|
|||||||
const user_id = CLIENT_AUTH_TOKENS[session_token];
|
const user_id = CLIENT_AUTH_TOKENS[session_token];
|
||||||
|
|
||||||
if (!user_id)
|
if (!user_id)
|
||||||
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
|
return NextResponse.json(
|
||||||
|
{ message: "Invalid token" },
|
||||||
|
{ status: StatusCodes.NOT_FOUND }
|
||||||
|
);
|
||||||
|
|
||||||
SERVER_AUTH_TOKENS[token] = {
|
SERVER_AUTH_TOKENS[token] = {
|
||||||
user_id,
|
user_id,
|
||||||
|
|||||||
@@ -2,4 +2,4 @@ import { NextResponse } from "next/server";
|
|||||||
|
|
||||||
export async function GET() {
|
export async function GET() {
|
||||||
return NextResponse.json({ message: "ok", version: "0.0.1" });
|
return NextResponse.json({ message: "ok", version: "0.0.1" });
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -23,8 +23,8 @@ export default function Server() {
|
|||||||
async function auth() {
|
async function auth() {
|
||||||
const server_auth = (
|
const server_auth = (
|
||||||
(
|
(
|
||||||
await axios.post("http://localhost:3000/api/auth", {
|
await axios.post("/api/auth", {
|
||||||
server_ip: ip === "localhost" ? "127.0.0.1" : ip,
|
server_ip: ip,
|
||||||
session_token: Cookies.get("token"),
|
session_token: Cookies.get("token"),
|
||||||
})
|
})
|
||||||
).data as any
|
).data as any
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ export default function useUser() {
|
|||||||
|
|
||||||
try {
|
try {
|
||||||
const res = (
|
const res = (
|
||||||
await axios.get("http://localhost:3000/api/user", {
|
await axios.get("/api/user", {
|
||||||
params: { token },
|
params: { token },
|
||||||
})
|
})
|
||||||
).data as User;
|
).data as User;
|
||||||
|
|||||||
Reference in New Issue
Block a user