refactor(api): add same-origin backend proxy for auth cookies
This commit is contained in:
@@ -1,2 +1,5 @@
|
||||
# Backend API base URL (no trailing slash)
|
||||
NEXT_PUBLIC_API_URL=http://localhost:8000/api/v1
|
||||
# Server-only backend origin. Do not expose this as a NEXT_PUBLIC variable.
|
||||
BACKEND_ORIGIN=http://localhost:8000
|
||||
|
||||
# Browser requests stay on the Next.js origin and are rewritten server-side.
|
||||
NEXT_PUBLIC_API_URL=/backend/
|
||||
|
||||
@@ -1,7 +1,21 @@
|
||||
import type { NextConfig } from 'next';
|
||||
|
||||
const backendOrigin = process.env.BACKEND_ORIGIN?.replace(/\/+$/, '');
|
||||
|
||||
if (!backendOrigin) {
|
||||
throw new Error('BACKEND_ORIGIN is required');
|
||||
}
|
||||
|
||||
const nextConfig: NextConfig = {
|
||||
reactStrictMode: false,
|
||||
async rewrites() {
|
||||
return [
|
||||
{
|
||||
source: '/backend/:path*',
|
||||
destination: `${backendOrigin}/:path*`,
|
||||
},
|
||||
];
|
||||
},
|
||||
};
|
||||
|
||||
export default nextConfig;
|
||||
|
||||
@@ -14,9 +14,6 @@ export const authService = {
|
||||
const response = await axiosAuth.post<AuthResponseData>(
|
||||
API_ROUTES.AUTH.LOGIN,
|
||||
payload,
|
||||
{
|
||||
withCredentials: true,
|
||||
},
|
||||
);
|
||||
return response.data;
|
||||
},
|
||||
@@ -24,14 +21,11 @@ export const authService = {
|
||||
const response = await axiosAuth.post<AuthResponseData>(
|
||||
API_ROUTES.AUTH.REFRESH,
|
||||
{},
|
||||
{
|
||||
withCredentials: true,
|
||||
},
|
||||
);
|
||||
return response.data;
|
||||
},
|
||||
logout: async (): Promise<void> => {
|
||||
await axiosAuth.post(API_ROUTES.AUTH.LOGOUT, {}, { withCredentials: true });
|
||||
await axiosAuth.post(API_ROUTES.AUTH.LOGOUT, {});
|
||||
},
|
||||
me: async (): Promise<MeResponse> => {
|
||||
const response = await axiosClient.get<MeResponse>(API_ROUTES.AUTH.ME);
|
||||
|
||||
@@ -7,6 +7,7 @@ const BASE_URL = ENV_CONSTANT.BASE_API_URL;
|
||||
|
||||
const axiosClient = axios.create({
|
||||
baseURL: BASE_URL,
|
||||
withCredentials: true,
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
},
|
||||
@@ -14,6 +15,7 @@ const axiosClient = axios.create({
|
||||
|
||||
export const axiosAuth = axios.create({
|
||||
baseURL: BASE_URL,
|
||||
withCredentials: true,
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
},
|
||||
@@ -30,13 +32,7 @@ const isInvalidSessionResponse = (error: unknown) => {
|
||||
const refreshAccessToken = () => {
|
||||
if (!refreshPromise) {
|
||||
refreshPromise = axiosAuth
|
||||
.post(
|
||||
'api/auth/refresh',
|
||||
{},
|
||||
{
|
||||
withCredentials: true,
|
||||
},
|
||||
)
|
||||
.post('api/auth/refresh', {})
|
||||
.then((response) => {
|
||||
const accessToken = response.data?.access_token;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user