A major refactoring for more consistent and stricter flows.
- Force using the dedicated authentication site configured via auth-host - Stricter host validation - Using the restricted app consistently for all access control (instead of the old loginview).
This commit is contained in:
@@ -5,7 +5,6 @@ export const useAuthStore = defineStore('auth', {
|
||||
state: () => ({
|
||||
// Auth State
|
||||
userInfo: null, // Contains the full user info response: {user, credentials, aaguid_info}
|
||||
settings: null, // Server provided settings (/auth/settings)
|
||||
isLoading: false,
|
||||
|
||||
// UI State
|
||||
@@ -17,15 +16,6 @@ export const useAuthStore = defineStore('auth', {
|
||||
},
|
||||
}),
|
||||
getters: {
|
||||
uiBasePath(state) {
|
||||
const configured = state.settings?.ui_base_path || '/auth/'
|
||||
if (!configured.endsWith('/')) return `${configured}/`
|
||||
return configured
|
||||
},
|
||||
adminUiPath() {
|
||||
const base = this.uiBasePath
|
||||
return base === '/' ? '/admin/' : `${base}admin/`
|
||||
},
|
||||
},
|
||||
actions: {
|
||||
setLoading(flag) {
|
||||
@@ -43,15 +33,6 @@ export const useAuthStore = defineStore('auth', {
|
||||
}, duration)
|
||||
}
|
||||
},
|
||||
uiHref(suffix = '') {
|
||||
const trimmed = suffix.startsWith('/') ? suffix.slice(1) : suffix
|
||||
if (!trimmed) return this.uiBasePath
|
||||
if (this.uiBasePath === '/') return `/${trimmed}`
|
||||
return `${this.uiBasePath}${trimmed}`
|
||||
},
|
||||
adminHomeHref() {
|
||||
return this.adminUiPath
|
||||
},
|
||||
async setSessionCookie(sessionToken) {
|
||||
const response = await fetch('/auth/api/set-session', {
|
||||
method: 'POST',
|
||||
@@ -113,19 +94,6 @@ export const useAuthStore = defineStore('auth', {
|
||||
this.userInfo = result
|
||||
console.log('User info loaded:', result)
|
||||
},
|
||||
async loadSettings() {
|
||||
try {
|
||||
const res = await fetch('/auth/api/settings')
|
||||
if (!res.ok) return
|
||||
const data = await res.json()
|
||||
this.settings = data
|
||||
if (data?.rp_name) {
|
||||
document.title = data.rp_name
|
||||
}
|
||||
} catch (_) {
|
||||
// ignore
|
||||
}
|
||||
},
|
||||
async deleteCredential(uuid) {
|
||||
const response = await fetch(`/auth/api/user/credential/${uuid}`, {method: 'Delete'})
|
||||
const result = await response.json()
|
||||
|
||||
Reference in New Issue
Block a user