Websocket and auth fixes
This commit is contained in:
+24
-21
@@ -1,12 +1,6 @@
|
|||||||
import { NextRequest, NextResponse } from "next/server";
|
import { NextRequest, NextResponse } from "next/server";
|
||||||
import { StatusCodes } from "http-status-codes";
|
import { StatusCodes } from "http-status-codes";
|
||||||
import { supabase } from "../supa";
|
import { supabase } from "../supa";
|
||||||
|
|
||||||
const SERVER_AUTH_TOKENS = new Map<
|
|
||||||
string,
|
|
||||||
{ user_id: string; server_id: string }
|
|
||||||
>();
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* GET /api/auth?token=<relayToken>?key=<serverKey>
|
* GET /api/auth?token=<relayToken>?key=<serverKey>
|
||||||
* Called by a (DM node / Server) to verify a temporary relay token.
|
* Called by a (DM node / Server) to verify a temporary relay token.
|
||||||
@@ -16,31 +10,36 @@ export async function GET(req: NextRequest) {
|
|||||||
const token = url.searchParams.get("token");
|
const token = url.searchParams.get("token");
|
||||||
const key = url.searchParams.get("key");
|
const key = url.searchParams.get("key");
|
||||||
|
|
||||||
if (!token || !key) {
|
if (!token || !key)
|
||||||
return NextResponse.json(
|
return NextResponse.json(
|
||||||
{ message: "There should be a token and a key parameter" },
|
{ message: "There should be a token and a key parameter" },
|
||||||
{ status: StatusCodes.BAD_REQUEST }
|
{ status: StatusCodes.BAD_REQUEST }
|
||||||
);
|
);
|
||||||
}
|
|
||||||
|
|
||||||
const { data: server } = await supabase
|
const { data: server } = await supabase
|
||||||
.from("servers")
|
.from("servers")
|
||||||
.select("id, created_at, owner, address")
|
.select("id, created_at, owner, address")
|
||||||
.eq("key", key)
|
.eq("key", key)
|
||||||
.maybeSingle();
|
.maybeSingle();
|
||||||
|
|
||||||
if (!server)
|
if (!server)
|
||||||
return NextResponse.json(
|
return NextResponse.json(
|
||||||
{ message: "Key unauthorized" },
|
{ message: "Key unauthorized" },
|
||||||
{ status: StatusCodes.UNAUTHORIZED }
|
{ status: StatusCodes.UNAUTHORIZED }
|
||||||
);
|
);
|
||||||
|
|
||||||
const auth = SERVER_AUTH_TOKENS.get(token);
|
const { data: auth } = await supabase
|
||||||
if (!auth) {
|
.from("server_auth")
|
||||||
|
.delete()
|
||||||
|
.eq("key", token)
|
||||||
|
.select()
|
||||||
|
.maybeSingle();
|
||||||
|
|
||||||
|
if (!auth)
|
||||||
return NextResponse.json(
|
return NextResponse.json(
|
||||||
{ message: "Invalid or expired token" },
|
{ message: "Invalid or expired token" },
|
||||||
{ status: StatusCodes.NOT_FOUND }
|
{ status: StatusCodes.NOT_FOUND }
|
||||||
);
|
);
|
||||||
}
|
|
||||||
|
|
||||||
if (auth.server_id !== server.id)
|
if (auth.server_id !== server.id)
|
||||||
return NextResponse.json(
|
return NextResponse.json(
|
||||||
@@ -48,8 +47,6 @@ export async function GET(req: NextRequest) {
|
|||||||
{ status: StatusCodes.UNAUTHORIZED }
|
{ status: StatusCodes.UNAUTHORIZED }
|
||||||
);
|
);
|
||||||
|
|
||||||
SERVER_AUTH_TOKENS.delete(token);
|
|
||||||
|
|
||||||
return NextResponse.json({ message: "ok", ...auth });
|
return NextResponse.json({ message: "ok", ...auth });
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -76,12 +73,10 @@ export async function POST(req: NextRequest) {
|
|||||||
{ status: StatusCodes.BAD_REQUEST }
|
{ status: StatusCodes.BAD_REQUEST }
|
||||||
);
|
);
|
||||||
|
|
||||||
const supabaseToken = authHeader.value;
|
|
||||||
|
|
||||||
const {
|
const {
|
||||||
data: { user },
|
data: { user },
|
||||||
error,
|
error,
|
||||||
} = await supabase.auth.getUser(supabaseToken);
|
} = await supabase.auth.getUser(authHeader.value);
|
||||||
|
|
||||||
if (error || !user) {
|
if (error || !user) {
|
||||||
return NextResponse.json(
|
return NextResponse.json(
|
||||||
@@ -90,12 +85,20 @@ export async function POST(req: NextRequest) {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
const relayToken = crypto.randomUUID();
|
const { data: relayToken, error: errorRelay } = await supabase
|
||||||
|
.from("server_auth")
|
||||||
SERVER_AUTH_TOKENS.set(relayToken, {
|
.insert({
|
||||||
user_id: user.id,
|
user_id: user.id,
|
||||||
server_id,
|
server_id,
|
||||||
});
|
})
|
||||||
|
.select()
|
||||||
|
.maybeSingle();
|
||||||
|
|
||||||
return NextResponse.json({ message: "ok", token: relayToken });
|
if (!relayToken || errorRelay)
|
||||||
|
return NextResponse.json(
|
||||||
|
{ message: "Failed to create relay token" },
|
||||||
|
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
|
||||||
|
);
|
||||||
|
|
||||||
|
return NextResponse.json({ message: "ok", token: relayToken.key });
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -84,14 +84,26 @@ export async function GET(req: NextRequest) {
|
|||||||
if (!user_id)
|
if (!user_id)
|
||||||
return NextResponse.json(
|
return NextResponse.json(
|
||||||
{ message: "Invalid token" },
|
{ message: "Invalid token" },
|
||||||
{ status: StatusCodes.NOT_FOUND }
|
{ status: StatusCodes.BAD_REQUEST }
|
||||||
);
|
);
|
||||||
|
|
||||||
const { data: profile } = await supabase
|
const { data: profile, error } = await supabase
|
||||||
.from("profiles")
|
.from("profiles")
|
||||||
.select("id, username, display_name, avatar_url, node_address")
|
.select("id, username, display_name, avatar_url, node_address")
|
||||||
.eq("id", user_id)
|
.eq("id", user_id)
|
||||||
.maybeSingle();
|
.maybeSingle();
|
||||||
|
|
||||||
|
if (error)
|
||||||
|
return NextResponse.json(
|
||||||
|
{ message: error.message },
|
||||||
|
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!profile)
|
||||||
|
return NextResponse.json(
|
||||||
|
{ message: "Profile not found" },
|
||||||
|
{ status: StatusCodes.NOT_FOUND }
|
||||||
|
);
|
||||||
|
|
||||||
return NextResponse.json({ message: "ok", ...profile });
|
return NextResponse.json({ message: "ok", ...profile });
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ function MessageContainer({
|
|||||||
[message.from]: res.data as UserProfile,
|
[message.from]: res.data as UserProfile,
|
||||||
}))
|
}))
|
||||||
)
|
)
|
||||||
.catch(console.error);
|
.catch(() => {});
|
||||||
}, [message.from, setUserList]);
|
}, [message.from, setUserList]);
|
||||||
|
|
||||||
return (
|
return (
|
||||||
|
|||||||
@@ -338,7 +338,5 @@ function getUser(
|
|||||||
|
|
||||||
get(`/api/profile/?id=${id}`, onResponse)
|
get(`/api/profile/?id=${id}`, onResponse)
|
||||||
?.then(onResponse)
|
?.then(onResponse)
|
||||||
.catch((e) => {
|
.catch((e) => {});
|
||||||
console.error(e);
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ import Cookies from "js-cookie";
|
|||||||
import { useRouter } from "next/navigation";
|
import { useRouter } from "next/navigation";
|
||||||
import { useEffect, useState } from "react";
|
import { useEffect, useState } from "react";
|
||||||
import { get } from "@/lib/request";
|
import { get } from "@/lib/request";
|
||||||
|
import { toast } from "sonner";
|
||||||
|
|
||||||
export interface UserProfile extends ProfileSettings {
|
export interface UserProfile extends ProfileSettings {
|
||||||
id: string;
|
id: string;
|
||||||
@@ -24,8 +25,9 @@ export default function useUser() {
|
|||||||
|
|
||||||
try {
|
try {
|
||||||
setUser((await get("/api/profile")).data);
|
setUser((await get("/api/profile")).data);
|
||||||
} catch {
|
} catch (e: any) {
|
||||||
router.push("/login");
|
router.push("/login");
|
||||||
|
toast.error(`Error: ${e}`);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
import { defaultSettings, getClientSettings } from "@/lib/clientSettings";
|
import { defaultSettings, getClientSettings } from "@/lib/clientSettings";
|
||||||
import { ProfileSettings, ClientSettings } from "@/types/settings";
|
import { ProfileSettings, ClientSettings } from "@/types/settings";
|
||||||
|
import axios from "axios";
|
||||||
import { Dispatch, SetStateAction, useEffect, useState } from "react";
|
import { Dispatch, SetStateAction, useEffect, useState } from "react";
|
||||||
|
|
||||||
export function useClientSettings(): [
|
export function useClientSettings(): [
|
||||||
@@ -31,11 +32,8 @@ export function useProfileSettings(): [
|
|||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
async function fetchProfileSettings() {
|
async function fetchProfileSettings() {
|
||||||
try {
|
try {
|
||||||
const res = await fetch("/api/profile");
|
const res = await axios.get("/api/profile");
|
||||||
if (res.ok) {
|
setSettings(res.data as ProfileSettings);
|
||||||
const data = (await res.json()) as ProfileSettings;
|
|
||||||
setSettings(data);
|
|
||||||
}
|
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
console.error("Failed to fetch profile settings:", error);
|
console.error("Failed to fetch profile settings:", error);
|
||||||
}
|
}
|
||||||
|
|||||||
+7
-7
@@ -26,13 +26,6 @@ export default async function auth(
|
|||||||
|
|
||||||
ws.onopen = () => {
|
ws.onopen = () => {
|
||||||
console.log("Connected to WebSocket:", ip);
|
console.log("Connected to WebSocket:", ip);
|
||||||
ws.send(
|
|
||||||
JSON.stringify({
|
|
||||||
version: "0.0.1",
|
|
||||||
auth_token: server_auth,
|
|
||||||
last_message: lastMessage || 0,
|
|
||||||
})
|
|
||||||
);
|
|
||||||
};
|
};
|
||||||
|
|
||||||
ws.onmessage = (m) => {
|
ws.onmessage = (m) => {
|
||||||
@@ -41,6 +34,13 @@ export default async function auth(
|
|||||||
|
|
||||||
if (data.version) {
|
if (data.version) {
|
||||||
setServer({ channels: [], ...data });
|
setServer({ channels: [], ...data });
|
||||||
|
ws.send(
|
||||||
|
JSON.stringify({
|
||||||
|
version: "0.0.1",
|
||||||
|
auth_token: server_auth,
|
||||||
|
last_message: lastMessage || 0,
|
||||||
|
})
|
||||||
|
);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user