feat: enhance security by implementing HttpOnly refresh tokens and in-memory access token management

- Added isomorphic-dompurify for improved XSS protection
- Refactored token storage to use in-memory management for access tokens
- Implemented server-side route handlers for OAuth token management
- Introduced security headers in next.config.js
- Removed client-side exposure of client_secret and sensitive tokens
- Updated API interceptors to handle token refresh logic
- Cleaned up cookie management for refresh tokens
This commit is contained in:
hamed
2026-06-20 13:10:17 +03:30
parent a19058d9a2
commit 194ffd889c
29 changed files with 1007 additions and 190 deletions
+34
View File
@@ -0,0 +1,34 @@
const COOKIE_NAME = "refresh_token";
function cookieDomain(host) {
if (!host) return undefined;
const hostname = host.split(":")[0];
if (hostname.includes("localhost") || /^\d+\.\d+\.\d+\.\d+$/.test(hostname)) {
return undefined;
}
return "." + hostname.split(".").slice(-2).join(".");
}
export function setRefreshCookie(response, refreshToken, host, maxAge = 60 * 60 * 24 * 30) {
response.cookies.set(COOKIE_NAME, refreshToken, {
httpOnly: true,
secure: true,
sameSite: "lax",
path: "/",
maxAge,
domain: cookieDomain(host),
});
}
export function clearRefreshCookie(response, host) {
response.cookies.set(COOKIE_NAME, "", {
httpOnly: true,
secure: true,
sameSite: "lax",
path: "/",
maxAge: 0,
domain: cookieDomain(host),
});
}
export { COOKIE_NAME };