Auth finally works for testing other stuff

This commit is contained in:
2025-09-24 18:32:40 +02:00
parent e00a589ae6
commit d2c98bebee
4 changed files with 45 additions and 76 deletions
+23 -52
View File
@@ -1,73 +1,44 @@
import { NextRequest, NextResponse } from "next/server";
import {
StatusCodes,
} from 'http-status-codes';
import { narrow } from "@/types/typeUtils";
import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth";
import { initDb } from "../db";
type Intents = 'server' | 'client';
const narrowIntents = (intents?: string | null) => narrow(intents, 'client', 'server') as Intents;
import { StatusCodes } from "http-status-codes";
export async function GET(req: NextRequest) {
const url = new URL(req.url);
const token = url.searchParams.get('token');
const intents = narrowIntents(url.searchParams.get('intents'));
if (!token)
return NextResponse.json({ message: "token parameter required" });
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.BAD_REQUEST });
switch (intents) {
case "server":
{
const auth = SERVER_AUTH_TOKENS[token];
const auth = SERVER_AUTH_TOKENS[token];
if (!auth)
return NextResponse.json({ message: "Invalid token" });
if (!auth)
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1');
const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1');
if (auth.server_ip !== ip) {
return NextResponse.json({ message: "Invalid address" });
}
delete SERVER_AUTH_TOKENS[token];
return NextResponse.json({ message: "ok", ...auth });
}
case "client":
{
const auth = CLIENT_AUTH_TOKENS[token];
if (!auth)
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
return NextResponse.json({ message: "ok", auth });
}
if (auth.server_ip !== ip) {
return NextResponse.json({ message: "Invalid address" }, { status: StatusCodes.UNAUTHORIZED });
}
delete SERVER_AUTH_TOKENS[token];
return NextResponse.json({ message: "ok", ...auth });
}
export async function POST(req: NextRequest) {
let { intents, server_ip } = await req.json();
intents = String(intents).split('/');
let { server_ip, session_token } = await req.json();
const token = crypto.randomUUID();
const user_id = 12;
const user_id = CLIENT_AUTH_TOKENS[session_token];
switch (narrowIntents(intents[0])) {
case 'server':
SERVER_AUTH_TOKENS[token] = {
user_id,
server_ip: String(server_ip),
};
return NextResponse.json({ message: "ok", token });
case 'client':
CLIENT_AUTH_TOKENS[token] = user_id;
return NextResponse.json({ message: "ok", token });
default:
return NextResponse.json({ message: 'Invalid intentions' }, { status: StatusCodes.BAD_REQUEST });
}
if (!user_id)
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
SERVER_AUTH_TOKENS[token] = {
user_id,
server_ip: String(server_ip),
};
return NextResponse.json({ message: "ok", token });
}
initDb();
+4 -14
View File
@@ -1,20 +1,8 @@
import { NextRequest, NextResponse } from "next/server";
import pool from "../db";
import pool, { initDb } from "../db";
import { StatusCodes } from "http-status-codes";
import { CLIENT_AUTH_TOKENS } from "../auth/auth";
/*
Input:
{
"name": "<Bob Smith>",
"password": "<bobsmith21>"
}
Output:
{
"message": "ok",
"token": "<crypto-uuid>",
}
*/
export async function POST(req: NextRequest) {
let { name, username, email, password } = await req.json();
@@ -40,7 +28,7 @@ export async function POST(req: NextRequest) {
const result = await pool.query("INSERT INTO users (username, email, password_hash) VALUES ($1, $2, $3) RETURNING id;", [username, email, password]);
const token = crypto.randomUUID();
CLIENT_AUTH_TOKENS[token] = result.rows[0].id;
CLIENT_AUTH_TOKENS[token] = parseInt(result.rows[0].id);
return NextResponse.json({ message: "ok", token, user_id: result.rows[0].id });
}
@@ -55,3 +43,5 @@ export async function DELETE(req: NextRequest) {
return NextResponse.json({ message: "ok" });
}
initDb();
+5 -1
View File
@@ -1,8 +1,12 @@
import axios from "axios";
import { getUser } from "./user.js";
const session_token = await getUser();
const res = (await axios.post('http://localhost:3000/api/auth', {
intents: 'server',
server_ip: '127.0.0.1'
server_ip: '127.0.0.1',
session_token,
})).data;
const token = res.token;
+13 -9
View File
@@ -1,12 +1,16 @@
import axios from "axios";
console.log((await axios.delete("http://localhost:3000/api/user", {
data: { username: "leo" },
})).data);
export async function getUser() {
console.log((await axios.delete("http://localhost:3000/api/user", {
data: { username: "leo" },
})).data);
console.log((await axios.post('http://localhost:3000/api/user', {
username: 'leo',
name: 'Leo',
email: '',
password: 'Idk123',
})).data);
return ((await axios.post('http://localhost:3000/api/user', {
username: 'leo',
name: 'Leo',
email: '',
password: 'Idk123',
})).data).token;
}
// await getUser();