feat: enhance security by implementing HttpOnly refresh tokens and in-memory access token management
- Added isomorphic-dompurify for improved XSS protection - Refactored token storage to use in-memory management for access tokens - Implemented server-side route handlers for OAuth token management - Introduced security headers in next.config.js - Removed client-side exposure of client_secret and sensitive tokens - Updated API interceptors to handle token refresh logic - Cleaned up cookie management for refresh tokens
This commit is contained in:
@@ -2,10 +2,23 @@
|
||||
|
||||
import { ThemeProvider } from "next-themes";
|
||||
import { usePathname } from "next/navigation";
|
||||
import { useEffect } from "react";
|
||||
import Cookies from "js-cookie";
|
||||
import { setAccessToken } from "@/lib/tokenStore";
|
||||
|
||||
export function Providers({ children }) {
|
||||
const router = usePathname();
|
||||
|
||||
useEffect(() => {
|
||||
if (!Cookies.get("userInfo")) return;
|
||||
fetch("/api/auth/refresh", { method: "POST" })
|
||||
.then((res) => (res.ok ? res.json() : null))
|
||||
.then((data) => {
|
||||
if (data?.access_token) setAccessToken(data.access_token);
|
||||
})
|
||||
.catch(() => {});
|
||||
}, []);
|
||||
|
||||
return (
|
||||
<ThemeProvider
|
||||
attribute={router.includes("/panel") ? "class" : "data-"}
|
||||
|
||||
Reference in New Issue
Block a user