Add authentication check and logout functionality in app.vue
This commit is contained in:
parent
ee00a8018e
commit
733a1e9f47
9 changed files with 1294 additions and 1653 deletions
21
server/api/auth/check.get.js
Normal file
21
server/api/auth/check.get.js
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
export default defineEventHandler(async (event) => {
|
||||
const token = getCookie(event, 'auth-token')
|
||||
|
||||
if (!token) {
|
||||
return { authenticated: false }
|
||||
}
|
||||
|
||||
const session = await useStorage('memory').getItem(`session:${token}`)
|
||||
|
||||
if (!session) {
|
||||
return { authenticated: false }
|
||||
}
|
||||
|
||||
// Check if session has expired
|
||||
if (session.expiresAt && new Date() > new Date(session.expiresAt)) {
|
||||
await useStorage('memory').removeItem(`session:${token}`)
|
||||
return { authenticated: false }
|
||||
}
|
||||
|
||||
return { authenticated: true }
|
||||
})
|
||||
38
server/api/auth/login.post.js
Normal file
38
server/api/auth/login.post.js
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
import crypto from 'crypto'
|
||||
|
||||
export default defineEventHandler(async (event) => {
|
||||
const { password } = await readBody(event)
|
||||
|
||||
if (!password) {
|
||||
throw createError({
|
||||
statusCode: 400,
|
||||
statusMessage: 'Password is required'
|
||||
})
|
||||
}
|
||||
|
||||
const correctPassword = process.env.APP_PASSWORD
|
||||
|
||||
if (password !== correctPassword) {
|
||||
throw createError({
|
||||
statusCode: 401,
|
||||
statusMessage: 'Invalid password'
|
||||
})
|
||||
}
|
||||
|
||||
const sessionToken = crypto.randomBytes(32).toString('hex')
|
||||
|
||||
setCookie(event, 'auth-token', sessionToken, {
|
||||
httpOnly: true,
|
||||
secure: process.env.NODE_ENV === 'production',
|
||||
sameSite: 'lax',
|
||||
maxAge: 60 * 60 * 24 * 7 // 7 days
|
||||
})
|
||||
|
||||
await useStorage('memory').setItem(`session:${sessionToken}`, {
|
||||
authenticated: true,
|
||||
createdAt: new Date().toISOString(),
|
||||
expiresAt: new Date(Date.now() + (60 * 60 * 24 * 7 * 1000)).toISOString() // 7 days
|
||||
})
|
||||
|
||||
return { success: true }
|
||||
})
|
||||
11
server/api/auth/logout.post.js
Normal file
11
server/api/auth/logout.post.js
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
export default defineEventHandler(async (event) => {
|
||||
const token = getCookie(event, 'auth-token')
|
||||
|
||||
if (token) {
|
||||
await useStorage('memory').removeItem(`session:${token}`)
|
||||
}
|
||||
|
||||
deleteCookie(event, 'auth-token')
|
||||
|
||||
return { success: true }
|
||||
})
|
||||
43
server/middleware/auth.js
Normal file
43
server/middleware/auth.js
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
export default defineEventHandler(async (event) => {
|
||||
// Skip auth check for login page and auth API routes
|
||||
if (event.node.req.url?.startsWith('/api/auth/') ||
|
||||
event.node.req.url === '/login' ||
|
||||
event.node.req.url?.startsWith('/_nuxt/') ||
|
||||
event.node.req.url?.startsWith('/__nuxt_devtools__/')) {
|
||||
return
|
||||
}
|
||||
|
||||
// Only check auth for API routes and page requests
|
||||
if (event.node.req.url?.startsWith('/api/') ||
|
||||
!event.node.req.url?.includes('.')) {
|
||||
|
||||
const token = getCookie(event, 'auth-token')
|
||||
|
||||
if (!token) {
|
||||
if (event.node.req.url?.startsWith('/api/')) {
|
||||
throw createError({
|
||||
statusCode: 401,
|
||||
statusMessage: 'Authentication required'
|
||||
})
|
||||
}
|
||||
// Redirect to login for page requests
|
||||
return sendRedirect(event, '/login')
|
||||
}
|
||||
|
||||
const session = await useStorage('memory').getItem(`session:${token}`)
|
||||
|
||||
if (!session || (session.expiresAt && new Date() > new Date(session.expiresAt))) {
|
||||
if (session && session.expiresAt && new Date() > new Date(session.expiresAt)) {
|
||||
await useStorage('memory').removeItem(`session:${token}`)
|
||||
}
|
||||
deleteCookie(event, 'auth-token')
|
||||
if (event.node.req.url?.startsWith('/api/')) {
|
||||
throw createError({
|
||||
statusCode: 401,
|
||||
statusMessage: 'Session expired'
|
||||
})
|
||||
}
|
||||
return sendRedirect(event, '/login')
|
||||
}
|
||||
}
|
||||
})
|
||||
Loading…
Add table
Add a link
Reference in a new issue