fixed issue with login page.

This commit is contained in:
bobbert committed 2025-03-14 23:50:25 +00:00
1 parent 11fc5c8b3d
commit 84f010cb87
6 files changed
+153 -30

No files matched your search

+23 -1
View File
@@ -93,7 +93,29 @@ export function createToken(payload) {
export function verifyToken(token) {
try {
return jwt.verify(token, JWT_SECRET);
if (!token) return null;
const parts = token.split(".");
if (parts.length === 2) {
// Custom token verification
const [encodedData, signature] = parts;
const expectedSignature = Buffer.from(
`${encodedData}.${JWT_SECRET}`
).toString("base64");
if (signature !== expectedSignature) {
console.error("Signature mismatch");
return null;
}
const data = JSON.parse(
Buffer.from(encodedData, "base64").toString("utf-8")
);
if (data.exp && data.exp < Math.floor(Date.now() / 1000)) return null;
return data;
} else if (parts.length === 3) {
// Standard JWT verification
return jwt.verify(token, JWT_SECRET);
} else {
throw new Error("Invalid token format");
}
} catch (error) {
console.error("Token verification error:", error);
return null;
+55
View File
@@ -0,0 +1,55 @@
import { getServerSession } from "next-auth/next";
import { authOptions } from "../[...nextauth]/route";
export async function GET(req) {
try {
const session = await getServerSession(authOptions);
if (!session) {
return new Response(
JSON.stringify({
authenticated: false,
message: "Not authenticated",
}),
{
status: 401,
headers: {
"Content-Type": "application/json",
},
}
);
}
return new Response(
JSON.stringify({
authenticated: true,
user: {
id: session.user.id,
username: session.user.username,
role: session.user.role,
teamId: session.user.teamId,
},
}),
{
status: 200,
headers: {
"Content-Type": "application/json",
},
}
);
} catch (error) {
console.error("Session check error:", error);
return new Response(
JSON.stringify({
error: "Internal server error checking authentication",
}),
{
status: 500,
headers: {
"Content-Type": "application/json",
},
}
);
}
}
+4 -5
View File
@@ -6,15 +6,15 @@ export const dynamic = "force-dynamic"; // Disable caching
export async function GET() {
try {
// Get the token from cookies
const cookieStore = await cookies();
const sessionToken = cookieStore.get("next-auth.session-token")?.value;
const sessionToken =
cookieStore.get("next-auth.session-token")?.value ||
cookieStore.get("__Secure-next-auth.session-token")?.value;
if (!sessionToken) {
return Response.json({ error: "Unauthorized" }, { status: 401 });
}
// Import the token verification function
const { verifyToken } = await import("../auth/[...nextauth]/route");
try {
@@ -24,7 +24,6 @@ export async function GET() {
return Response.json({ error: "Invalid session" }, { status: 401 });
}
// Always fetch the latest user data from the database to ensure it's accurate
const freshUserData = await queryOne(
"SELECT id, username, role, team_id FROM users WHERE id = ?",
[userData.id]
@@ -40,7 +39,7 @@ export async function GET() {
username: freshUserData.username,
role: freshUserData.role,
teamId: freshUserData.team_id,
timestamp: new Date().toISOString(), // Add timestamp for debugging
timestamp: new Date().toISOString(),
},
{
headers: {