Refactor authentication flow; improve error handling, implement token creation and verification, and enhance user session management. Fixed login issue. Currently working on user authorisation for creating teams.

This commit is contained in:
bobbert committed 2025-03-12 18:11:33 +00:00
1 parent ce962162cb
commit b039af238f
5 files changed
+498 -201

No files matched your search

+32 -11
View File
@@ -1,17 +1,38 @@
// app/api/user/route.js
import { getServerSession } from 'next-auth/next';
import { authOptions } from '../auth/[...nextauth]/route';
import { cookies } from "next/headers";
export async function GET() {
const session = await getServerSession(authOptions);
try {
// Get the token from cookies - Fix: await the cookies() call
const cookieStore = await cookies();
const sessionToken = cookieStore.get("next-auth.session-token")?.value;
if (!session) {
return Response.json({ error: 'Unauthorized' }, { status: 401 });
if (!sessionToken) {
return Response.json({ error: "Unauthorized" }, { status: 401 });
}
return Response.json({
id: session.user.id,
username: session.user.username,
role: session.user.role
});
}
// Import the token verification function - using a direct import
const { verifyToken } = await import("../auth/[...nextauth]/route");
try {
const userData = verifyToken(sessionToken);
if (!userData) {
return Response.json({ error: "Invalid session" }, { status: 401 });
}
return Response.json({
id: userData.id,
username: userData.username,
role: userData.role,
teamId: userData.teamId,
});
} catch (tokenError) {
console.error("Token verification error:", tokenError);
return Response.json({ error: "Invalid session token" }, { status: 401 });
}
} catch (error) {
console.error("User API error:", error);
return Response.json({ error: "Server error" }, { status: 500 });
}
}