diff --git a/src/app/api/account/route.ts b/src/app/api/account/route.ts index 9c628ab..06531c7 100644 --- a/src/app/api/account/route.ts +++ b/src/app/api/account/route.ts @@ -30,14 +30,22 @@ export async function POST(req: NextRequest) { await database.users.insertOne({ email, password, name, platforms: {} }); - const sessionId = (await database.sessions.insertOne({ user: email })) - .insertedId; + const sessionId = await database.sessions.insertOne({ user: email }); - return NextResponse.json( + const response = NextResponse.json( { message: 'ok', - sessionId, }, { status: 200 } ); + + response.cookies.set('session_id', sessionId.toString(), { + httpOnly: true, + secure: process.env.NODE_ENV === 'production', + sameSite: 'strict', + path: '/', + maxAge: 60 * 60 * 24, // 1 day + }); + + return response; } diff --git a/src/app/api/session/route.ts b/src/app/api/session/route.ts index 3582a17..e1ad37c 100644 --- a/src/app/api/session/route.ts +++ b/src/app/api/session/route.ts @@ -53,7 +53,7 @@ export async function GET(req: NextRequest) { export async function POST(req: NextRequest) { const { email, password } = await req.json(); - if (typeof email !== 'string' || typeof password !== 'string') + if (typeof email !== 'string' || typeof password !== 'string') { return NextResponse.json( { message: @@ -61,36 +61,39 @@ export async function POST(req: NextRequest) { }, { status: 400 } ); + } const user = await database.users.findOne({ email }); - if (!user) + if (!user || user.password !== password) { return NextResponse.json( { - message: 'Email does not exist', + message: 'Invalid email or password', }, { status: 401 } ); + } - if (user.password !== password) - return NextResponse.json( - { - message: 'Invalid password', - }, - { status: 401 } - ); + const sessionId = new ObjectId(); + await database.sessions.insertOne({ + _id: sessionId, + user: user._id.toString(), + }); - const _id = new ObjectId(); - - database.sessions - .insertOne({ _id, user: user._id.toString() }) - .then((res) => {}); - - return NextResponse.json( + const response = NextResponse.json( { message: 'ok', - sessionId: _id.toString(), }, { status: 200 } ); + + response.cookies.set('session_id', sessionId.toString(), { + httpOnly: true, + secure: process.env.NODE_ENV === 'production', + sameSite: 'strict', + path: '/', + maxAge: 60 * 60 * 24, // 1 day + }); + + return response; } diff --git a/src/app/login/page.tsx b/src/app/login/page.tsx index 4794b2d..dd795c4 100644 --- a/src/app/login/page.tsx +++ b/src/app/login/page.tsx @@ -7,7 +7,6 @@ import { useToast } from '@/hooks/use-toast'; import axios from 'axios'; import Link from 'next/link'; import { useState } from 'react'; -import cookies from 'js-cookie'; import { useRouter } from 'next/navigation'; export default function Login() { @@ -25,8 +24,6 @@ export default function Login() { }) ).data; - cookies.set('session_id', sessionId); - router.replace('/dashboard'); } catch (err: any) { toast({ diff --git a/src/app/signup/page.tsx b/src/app/signup/page.tsx index 9b66da8..96fb534 100644 --- a/src/app/signup/page.tsx +++ b/src/app/signup/page.tsx @@ -52,7 +52,6 @@ export default function SignUp() { password, }) .then(async (response) => { - document.cookie = `session_id=${response.data.sessionId}`; router.push('/dashboard'); }) .catch((err) => {