fix: use private helcimApiToken for all server-side Helcim API calls
This commit is contained in:
parent
ccd1d0783a
commit
d31b5b4dac
53 changed files with 1755 additions and 572 deletions
|
|
@ -44,6 +44,14 @@ export async function requireAuth(event) {
|
|||
})
|
||||
}
|
||||
|
||||
// Verify session has not been revoked (tokenVersion incremented on logout)
|
||||
if (decoded.tv !== member.tokenVersion) {
|
||||
throw createError({
|
||||
statusCode: 401,
|
||||
statusMessage: 'Session has been revoked'
|
||||
})
|
||||
}
|
||||
|
||||
return member
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue