feat: enhance security by implementing HttpOnly refresh tokens and in-memory access token management
- Added isomorphic-dompurify for improved XSS protection - Refactored token storage to use in-memory management for access tokens - Implemented server-side route handlers for OAuth token management - Introduced security headers in next.config.js - Removed client-side exposure of client_secret and sensitive tokens - Updated API interceptors to handle token refresh logic - Cleaned up cookie management for refresh tokens
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
const COOKIE_NAME = "refresh_token";
|
||||
|
||||
function cookieDomain(host) {
|
||||
if (!host) return undefined;
|
||||
const hostname = host.split(":")[0];
|
||||
if (hostname.includes("localhost") || /^\d+\.\d+\.\d+\.\d+$/.test(hostname)) {
|
||||
return undefined;
|
||||
}
|
||||
return "." + hostname.split(".").slice(-2).join(".");
|
||||
}
|
||||
|
||||
export function setRefreshCookie(response, refreshToken, host, maxAge = 60 * 60 * 24 * 30) {
|
||||
response.cookies.set(COOKIE_NAME, refreshToken, {
|
||||
httpOnly: true,
|
||||
secure: true,
|
||||
sameSite: "lax",
|
||||
path: "/",
|
||||
maxAge,
|
||||
domain: cookieDomain(host),
|
||||
});
|
||||
}
|
||||
|
||||
export function clearRefreshCookie(response, host) {
|
||||
response.cookies.set(COOKIE_NAME, "", {
|
||||
httpOnly: true,
|
||||
secure: true,
|
||||
sameSite: "lax",
|
||||
path: "/",
|
||||
maxAge: 0,
|
||||
domain: cookieDomain(host),
|
||||
});
|
||||
}
|
||||
|
||||
export { COOKIE_NAME };
|
||||
Reference in New Issue
Block a user