- Added isomorphic-dompurify for improved XSS protection - Refactored token storage to use in-memory management for access tokens - Implemented server-side route handlers for OAuth token management - Introduced security headers in next.config.js - Removed client-side exposure of client_secret and sensitive tokens - Updated API interceptors to handle token refresh logic - Cleaned up cookie management for refresh tokens
123 lines
3.5 KiB
JavaScript
123 lines
3.5 KiB
JavaScript
import { Button, CircularProgress } from "@mui/material";
|
|
import { request } from "@/services/response";
|
|
import Cookies from "js-cookie";
|
|
import { toast } from "react-toastify";
|
|
import { handleTimeExpiresToken } from "@/helper";
|
|
import { setAccessToken } from "@/lib/tokenStore";
|
|
|
|
function SendReq({
|
|
loading,
|
|
setLoading,
|
|
code,
|
|
setIsSendMsg,
|
|
setStep,
|
|
setIsError,
|
|
uuid,
|
|
}) {
|
|
const handleReq = async () => {
|
|
setLoading(true);
|
|
try {
|
|
const res = await fetch("/api/auth/token", {
|
|
method: "POST",
|
|
headers: { "Content-Type": "application/json" },
|
|
body: JSON.stringify({ uuid, code: code.join("") }),
|
|
});
|
|
const response = await res.json();
|
|
if (response.access_token) {
|
|
handleSetCookie(response);
|
|
} else {
|
|
setLoading(false);
|
|
setIsError(true);
|
|
const message = response?.errors?.[0]?.message || "کد تأیید نادرست یا منقضی شده است.";
|
|
toast.error(message);
|
|
}
|
|
} catch {
|
|
setLoading(false);
|
|
setIsError(true);
|
|
toast.error("خطا در برقراری ارتباط. دوباره تلاش کنید.");
|
|
}
|
|
};
|
|
|
|
const handleSetCookie = (response) => {
|
|
const expiresTime = handleTimeExpiresToken(response.expires_in);
|
|
|
|
const hostname = window.location.hostname;
|
|
const isHttps = window.location.protocol === "https:";
|
|
const isLocalhost = hostname.includes("localhost");
|
|
|
|
// فقط دادههای غیرحساس در کوکی JS؛ access_token در memory، refresh_token در کوکی HttpOnly سرور
|
|
let cookieOptions = {
|
|
path: "/",
|
|
sameSite: "lax",
|
|
expires: expiresTime.refreshTokenExpires,
|
|
};
|
|
|
|
if (!isLocalhost && isHttps) {
|
|
cookieOptions = {
|
|
...cookieOptions,
|
|
secure: true,
|
|
domain: ".nobat724.com",
|
|
};
|
|
}
|
|
|
|
setAccessToken(response.access_token);
|
|
Cookies.set("uuid", uuid, cookieOptions);
|
|
|
|
getInfo(response.access_token, cookieOptions);
|
|
};
|
|
|
|
const getInfo = (token, cookieOptions) => {
|
|
request
|
|
.getUserInfo({
|
|
headers: {
|
|
Authorization: `Bearer ${token}`,
|
|
},
|
|
})
|
|
.then((res) => {
|
|
setLoading(false);
|
|
const profile = res?.data;
|
|
if (profile?.uuid) {
|
|
const userInfo = { ...profile, username: profile.mobile_number };
|
|
Cookies.set("userInfo", JSON.stringify(userInfo), cookieOptions);
|
|
// overwrite the OTP uuid set in handleSetCookie with the real user uuid
|
|
Cookies.set("uuid", profile.uuid, cookieOptions);
|
|
|
|
// اگر در صفحه appointment هستیم، به مرحله 3 (Detail) میرویم
|
|
if (setStep) {
|
|
setStep(3);
|
|
} else {
|
|
window.location.href = "/";
|
|
}
|
|
} else {
|
|
setIsError(true);
|
|
toast.error("دریافت اطلاعات کاربر ناموفق بود. دوباره تلاش کنید.");
|
|
}
|
|
})
|
|
.catch(() => {
|
|
setLoading(false);
|
|
setIsError(true);
|
|
});
|
|
};
|
|
|
|
return (
|
|
<Button
|
|
fullWidth
|
|
disabled={loading}
|
|
variant="contained"
|
|
onClick={() => {
|
|
setIsSendMsg && setIsSendMsg(true);
|
|
if (code.join("").length !== 5) {
|
|
setIsError(true);
|
|
} else {
|
|
handleReq();
|
|
}
|
|
}}
|
|
className="!rounded-[8px] !bg-[#5559CE]"
|
|
>
|
|
{loading ? <CircularProgress size={22} sx={{ color: "#fff" }} /> : "تایید"}
|
|
</Button>
|
|
);
|
|
}
|
|
|
|
export default SendReq;
|