@@ -3,11 +3,12 @@ import { Controller, Get, Post, Query, Res, Req, Body, HttpCode, HttpStatus } fr
|
||||
import { ApiTags, ApiOperation } from '@nestjs/swagger';
|
||||
import { AuthService } from './auth.service';
|
||||
import { Response, Request } from 'express';
|
||||
import { ConfigService } from '@nestjs/config';
|
||||
|
||||
@ApiTags('Auth')
|
||||
@Controller('auth')
|
||||
export class AuthController {
|
||||
constructor(private readonly authService: AuthService) {}
|
||||
constructor(private readonly authService: AuthService, private readonly config: ConfigService) {}
|
||||
|
||||
@Get('login')
|
||||
@ApiOperation({ summary: 'Start Authorization Code + PKCE login (redirect to Identity Provider)' })
|
||||
@@ -21,13 +22,17 @@ export class AuthController {
|
||||
async callback(@Query('code') code: string, @Query('state') state: string, @Res() res: Response) {
|
||||
const result = await this.authService.handleCallback(code, state);
|
||||
|
||||
// set cookies
|
||||
// set cookies with environment-aware options
|
||||
const isProd = this.config.get<string>('NODE_ENV') === 'production' || process.env.NODE_ENV === 'production';
|
||||
const cookieDomain = this.config.get<string>('RAYLAB_COOKIE_DOMAIN') || (isProd ? '.raylab.site' : undefined);
|
||||
|
||||
const cookieOptions: any = {
|
||||
httpOnly: true,
|
||||
secure: process.env.NODE_ENV === 'production',
|
||||
sameSite: 'lax',
|
||||
secure: isProd, // secure in production
|
||||
sameSite: isProd ? 'none' : 'lax', // cross-site in production
|
||||
path: '/',
|
||||
};
|
||||
if (cookieDomain) cookieOptions.domain = cookieDomain;
|
||||
|
||||
// access token cookie (internal JWT)
|
||||
res.cookie('raylab_jwt', result.accessToken, { ...cookieOptions, maxAge: result.expiresIn * 1000 });
|
||||
|
||||
Reference in New Issue
Block a user