Bug fixes

This commit is contained in:
2025-09-27 14:03:48 +02:00
parent 24aefe7838
commit aec851f0d1
5 changed files with 32 additions and 15 deletions
+24 -7
View File
@@ -1,23 +1,37 @@
import { NextRequest, NextResponse } from "next/server";
import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth";
import { StatusCodes } from "http-status-codes";
import axios from "axios";
export async function GET(req: NextRequest) {
const url = new URL(req.url);
const token = url.searchParams.get('token');
const token = url.searchParams.get("token");
if (!token)
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.BAD_REQUEST });
return NextResponse.json(
{ message: "There should be a token parameter" },
{ status: StatusCodes.BAD_REQUEST }
);
const auth = SERVER_AUTH_TOKENS[token];
if (!auth)
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
return NextResponse.json(
{ message: "Invalid token" },
{ status: StatusCodes.NOT_FOUND }
);
const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1');
const ip =
req.headers.get("x-real-ip") ||
req.headers.get("x-forwarded-for")?.split(",")[0] ||
"127.0.0.1";
if (auth.server_ip !== ip) {
return NextResponse.json({ message: "Invalid address" }, { status: StatusCodes.UNAUTHORIZED });
// ::1 for testing
if (auth.server_ip !== ip && ip !== "::1") {
return NextResponse.json(
{ message: "Invalid address" },
{ status: StatusCodes.UNAUTHORIZED }
);
}
delete SERVER_AUTH_TOKENS[token];
@@ -33,7 +47,10 @@ export async function POST(req: NextRequest) {
const user_id = CLIENT_AUTH_TOKENS[session_token];
if (!user_id)
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
return NextResponse.json(
{ message: "Invalid token" },
{ status: StatusCodes.NOT_FOUND }
);
SERVER_AUTH_TOKENS[token] = {
user_id,
+2 -2
View File
@@ -23,8 +23,8 @@ export default function Server() {
async function auth() {
const server_auth = (
(
await axios.post("http://localhost:3000/api/auth", {
server_ip: ip === "localhost" ? "127.0.0.1" : ip,
await axios.post("/api/auth", {
server_ip: ip,
session_token: Cookies.get("token"),
})
).data as any
+1 -1
View File
@@ -26,7 +26,7 @@ export default function useUser() {
try {
const res = (
await axios.get("http://localhost:3000/api/user", {
await axios.get("/api/user", {
params: { token },
})
).data as User;