mirror of
https://github.com/mudabbir-ahmad/peworkshop.git
synced 2026-10-07 19:50:20 +00:00
FIX OF ALL ISSUES WITH LOG IN PAGE. EVERYTHING TO THE POINT OF TESTING THE MAP WORKS SO FAR.
This commit is contained in:
1 parent
84f010cb87
commit
c79a9636a7
10 files changed
+228
-233
No files matched your search
@@ -15,8 +15,8 @@ export default function CreateTeam() {
|
||||
|
||||
useEffect(() => {
|
||||
if (status === "authenticated") {
|
||||
if (session.user.teamId) {
|
||||
router.push(`/team/${session.user.teamId}`);
|
||||
if (session?.user?.teamId) {
|
||||
router.push(`/${session.user.teamId}`);
|
||||
} else {
|
||||
setIsLoading(false);
|
||||
}
|
||||
@@ -31,12 +31,17 @@ export default function CreateTeam() {
|
||||
setError("");
|
||||
|
||||
try {
|
||||
// Add a check to ensure session is valid
|
||||
if (status !== "authenticated") {
|
||||
throw new Error("You must be logged in to create a team");
|
||||
}
|
||||
|
||||
const response = await fetch("/api/teams", {
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
},
|
||||
credentials: "include",
|
||||
credentials: "include", // Important: include credentials
|
||||
body: JSON.stringify({ name: teamName }),
|
||||
});
|
||||
|
||||
@@ -46,12 +51,18 @@ export default function CreateTeam() {
|
||||
throw new Error(data.error || "Failed to create team");
|
||||
}
|
||||
|
||||
// Navigate with the correct URL pattern for the page component
|
||||
console.log("Team created successfully with ID:", data.teamId);
|
||||
|
||||
// Hard navigation to make sure we're going to the page component not the API route
|
||||
// Force a session refresh to update the session with the new teamId
|
||||
await fetch("/api/auth/session", {
|
||||
method: "GET",
|
||||
credentials: "include",
|
||||
});
|
||||
|
||||
// Hard navigation to make sure we're going to the right page
|
||||
window.location.href = `/${data.teamId}`;
|
||||
} catch (err) {
|
||||
console.error("Team creation error:", err);
|
||||
setError(err.message);
|
||||
setIsLoading(false);
|
||||
}
|
||||
|
||||
@@ -1,12 +1,21 @@
|
||||
import { query } from "../../../../lib/db";
|
||||
import { getServerSession } from "next-auth/next";
|
||||
import { authOptions } from "../../auth/[...nextauth]/route";
|
||||
import { cookies } from "next/headers";
|
||||
import { verifyToken } from "@/app/api/auth/[...nextauth]/route";
|
||||
|
||||
export async function GET(request, context) {
|
||||
const session = await getServerSession(authOptions);
|
||||
// Use cookie-based verification instead of getServerSession
|
||||
const cookieStore = await cookies();
|
||||
const sessionToken =
|
||||
cookieStore.get("next-auth.session-token")?.value ||
|
||||
cookieStore.get("__Secure-next-auth.session-token")?.value;
|
||||
|
||||
if (!session) {
|
||||
return Response.json({ error: "Unauthorised" }, { status: 401 });
|
||||
if (!sessionToken) {
|
||||
return Response.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
const userData = verifyToken(sessionToken);
|
||||
if (!userData) {
|
||||
return Response.json({ error: "Invalid session" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
@@ -14,15 +23,15 @@ export async function GET(request, context) {
|
||||
|
||||
// Convert teamId to number for proper comparison
|
||||
const requestedTeamId = parseInt(teamId, 10);
|
||||
const userTeamId = parseInt(session.user.teamId, 10);
|
||||
const userTeamId = parseInt(userData.teamId, 10);
|
||||
|
||||
// Log for debugging
|
||||
console.log("Requested team:", requestedTeamId);
|
||||
console.log("User team:", userTeamId);
|
||||
console.log("User role:", session.user.role);
|
||||
console.log("User role:", userData.role);
|
||||
|
||||
// Ensure the user is requesting their own team or is an admin
|
||||
if (userTeamId !== requestedTeamId && session.user.role !== "admin") {
|
||||
if (userTeamId !== requestedTeamId && userData.role !== "admin") {
|
||||
return Response.json(
|
||||
{ error: "Not authorized to view this team" },
|
||||
{ status: 403 }
|
||||
|
||||
@@ -14,6 +14,9 @@ export default function TeamPage({ params }) {
|
||||
const router = useRouter();
|
||||
const { teamId } = params;
|
||||
|
||||
// Use the authenticated teamId if available
|
||||
const effectiveTeamId = session?.user?.teamId || teamId;
|
||||
|
||||
const checkHuntStatus = useCallback(async () => {
|
||||
try {
|
||||
const response = await fetch("/api/hunt-status", {
|
||||
@@ -33,11 +36,11 @@ export default function TeamPage({ params }) {
|
||||
|
||||
const fetchTeamData = useCallback(async () => {
|
||||
try {
|
||||
if (!teamId || isNaN(parseInt(teamId, 10))) {
|
||||
if (!effectiveTeamId || isNaN(parseInt(effectiveTeamId, 10))) {
|
||||
throw new Error("Invalid team ID");
|
||||
}
|
||||
|
||||
// First check if the user is still part of this team by fetching current user data
|
||||
// Validate current user data against effectiveTeamId
|
||||
const userResponse = await fetch("/api/user", {
|
||||
method: "GET",
|
||||
headers: {
|
||||
@@ -50,26 +53,32 @@ export default function TeamPage({ params }) {
|
||||
const userData = await userResponse.json();
|
||||
|
||||
// If the user is not in this team anymore, redirect to team selection
|
||||
if (!userData.teamId || userData.teamId != teamId) {
|
||||
if (
|
||||
!userData.teamId ||
|
||||
parseInt(userData.teamId, 10) !== parseInt(effectiveTeamId, 10)
|
||||
) {
|
||||
console.log("User no longer in team, redirecting to team selection");
|
||||
window.location.href = "/team-selection";
|
||||
return;
|
||||
}
|
||||
|
||||
console.log("Fetching team data for team ID:", teamId);
|
||||
console.log("Fetching team data for team ID:", effectiveTeamId);
|
||||
|
||||
// Add timestamp to URL to ensure fresh data on every request
|
||||
const timestamp = new Date().getTime();
|
||||
const response = await fetch(`/api/teams/${teamId}?_t=${timestamp}`, {
|
||||
method: "GET",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"Cache-Control": "no-cache, no-store, must-revalidate",
|
||||
Pragma: "no-cache",
|
||||
},
|
||||
credentials: "include",
|
||||
cache: "no-store",
|
||||
});
|
||||
const response = await fetch(
|
||||
`/api/teams/${effectiveTeamId}?_t=${timestamp}`,
|
||||
{
|
||||
method: "GET",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"Cache-Control": "no-cache, no-store, must-revalidate",
|
||||
Pragma: "no-cache",
|
||||
},
|
||||
credentials: "include",
|
||||
cache: "no-store",
|
||||
}
|
||||
);
|
||||
|
||||
if (!response.ok) {
|
||||
const text = await response.text();
|
||||
@@ -95,6 +104,8 @@ export default function TeamPage({ params }) {
|
||||
setTeam(data.team);
|
||||
setTeamMembers(data.members || []);
|
||||
setError("");
|
||||
|
||||
await checkHuntStatus();
|
||||
} catch (err) {
|
||||
console.error("Team page error:", err);
|
||||
setError(err.message);
|
||||
@@ -105,13 +116,11 @@ export default function TeamPage({ params }) {
|
||||
} finally {
|
||||
setLoading(false);
|
||||
}
|
||||
|
||||
await checkHuntStatus();
|
||||
}, [teamId, router, checkHuntStatus]);
|
||||
}, [effectiveTeamId, router, checkHuntStatus]);
|
||||
|
||||
useEffect(() => {
|
||||
// Only attempt to fetch data when session is ready and we have a teamId
|
||||
if (status === "authenticated" && teamId) {
|
||||
if (status === "authenticated" && effectiveTeamId) {
|
||||
console.log("Session authenticated, fetching team data");
|
||||
fetchTeamData();
|
||||
|
||||
@@ -124,7 +133,7 @@ export default function TeamPage({ params }) {
|
||||
console.log("User not authenticated, redirecting to login");
|
||||
router.push("/login");
|
||||
}
|
||||
}, [teamId, status, fetchTeamData, router]);
|
||||
}, [effectiveTeamId, status, fetchTeamData, router]);
|
||||
|
||||
if (status === "loading" || loading) {
|
||||
return (
|
||||
|
||||
@@ -1,24 +1,27 @@
|
||||
import { redirect } from "next/navigation";
|
||||
import { cookies } from "next/headers";
|
||||
import { verifyToken } from "@/app/api/auth/[...nextauth]/route";
|
||||
import { getToken } from "next-auth/jwt";
|
||||
|
||||
export async function GET(_, context) {
|
||||
export async function GET(request, context) {
|
||||
try {
|
||||
// Use our custom token verification instead of getServerSession
|
||||
const cookieStore = await cookies();
|
||||
const sessionToken = cookieStore.get("next-auth.session-token")?.value;
|
||||
|
||||
if (!sessionToken) {
|
||||
const token = await getToken({
|
||||
req: request,
|
||||
secret:
|
||||
process.env.NEXTAUTH_SECRET ||
|
||||
"your-fallback-secret-should-be-at-least-32-chars",
|
||||
});
|
||||
if (!token) {
|
||||
return redirect("/login");
|
||||
}
|
||||
|
||||
const userData = verifyToken(sessionToken);
|
||||
if (!userData) {
|
||||
return redirect("/login");
|
||||
// If the token's teamId matches the requested teamId or the user is admin, redirect accordingly.
|
||||
if (
|
||||
(token.teamId &&
|
||||
parseInt(token.teamId, 10) === parseInt(context.params.teamId, 10)) ||
|
||||
token.role === "admin"
|
||||
) {
|
||||
return redirect(`/${context.params.teamId}`);
|
||||
}
|
||||
|
||||
// Instead of returning JSON, redirect to the page component
|
||||
return redirect(`/${context.params.teamId}`);
|
||||
// If not, the user is not associated with this team.
|
||||
return redirect("/team-selection");
|
||||
} catch (error) {
|
||||
console.error("Team route error:", error);
|
||||
return redirect("/team-selection");
|
||||
|
||||
Reference in new issue
Block a user