mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-08-30 00:38:11 +00:00
refactor(freight): move the Fayda callback to /fayda/callback
Namespaces the OAuth landing path in all three places it exists: the API's
ack controller, both web apps' routes, and the redirect_uri env values.
A bare /callback claimed a generic top-level path in every app for one
provider's redirect.
The API side needed care. The ack controller moves to @Controller
('fayda/callback'), and the global-prefix exclusion has to name that exact
path — setGlobalPrefix's exclude is an exact route match, not a subtree, so
excluding "fayda" would have left /fayda/callback served at
/api/fayda/callback and 404ing at the registered redirect_uri, while
reading as though it covered everything under /fayda. Naming the full path
also keeps /api/fayda/verification/* prefixed, which every client calls.
Also drops a stale comment on the portal's callback route describing the
popup that no longer exists, and records why the route is public: behind
RequireAuth the onboarding gate redirects to /portal before the code+state
exchange can run.
NOT verified at runtime — this changes route registration, so boot the API
and confirm GET /fayda/callback answers un-prefixed and
/api/fayda/verification/start still resolves before relying on it.
Deploying this requires registering the new redirect_uri with eSignet
first; FAYDA_WEB_REDIRECT_URI, FAYDA_PORTAL_REDIRECT_URI and any mobile
client must be updated in step or verification breaks with a redirect_uri
mismatch.
This commit is contained in:
@@ -5,7 +5,7 @@ import ExternalPortalCallback from "@/external-portal/components/Registration/Ex
|
||||
|
||||
/**
|
||||
* Single FAYDA OIDC callback entry point.
|
||||
* Fayda only allows whitelisted redirect URIs (e.g. /callback) — route
|
||||
* Fayda only allows whitelisted redirect URIs (e.g. /fayda/callback) — route
|
||||
* internally based on the `state` param sent during authorization.
|
||||
*/
|
||||
export default function FaydaCallbackDispatcher() {
|
||||
|
||||
@@ -11,7 +11,7 @@ const PUBLIC_PATHS = [
|
||||
"/set-password",
|
||||
"/verify-otp",
|
||||
"/verification_page",
|
||||
"/callback",
|
||||
"/fayda/callback",
|
||||
"/complaints",
|
||||
"/complaint-form",
|
||||
"/follow-complaint",
|
||||
|
||||
@@ -12,7 +12,7 @@ const DEFAULT_CODE_CHALLENGE = "E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM";
|
||||
const DEFAULT_NONCE = "g4DEuje5Fx57Vb64dO4oqLHXGT8L8G7g";
|
||||
const DEFAULT_STATE = "ptOO76SD";
|
||||
|
||||
/** OIDC state value that routes the shared /callback to the complaint flow (legacy sign-in). */
|
||||
/** OIDC state value that routes the shared /fayda/callback to the complaint flow (legacy sign-in). */
|
||||
export const COMPLAINT_FLOW_STATE = "complaint_flow";
|
||||
|
||||
/** Complaint flow OIDC states — distinguish sign-in vs sign-up endpoints. */
|
||||
@@ -66,9 +66,7 @@ export function startExternalPortalFaydaAuth(): void {
|
||||
export function generateFaydaAuthorizationUrl(
|
||||
options: FaydaOidcOptions = {},
|
||||
): string {
|
||||
const redirectUri =
|
||||
options.redirectUri ||
|
||||
getDefaultFaydaRedirectUri();
|
||||
const redirectUri = options.redirectUri || getDefaultFaydaRedirectUri();
|
||||
|
||||
const params = new URLSearchParams({
|
||||
client_id: import.meta.env.VITE_CLIENT_ID || "",
|
||||
@@ -98,7 +96,7 @@ export function generateFaydaAuthorizationUrl(
|
||||
export function getDefaultFaydaRedirectUri(): string {
|
||||
return (
|
||||
import.meta.env.VITE_REDIRECT_URI ||
|
||||
`${window.location.origin}/callback`
|
||||
`${window.location.origin}/fayda/callback`
|
||||
);
|
||||
}
|
||||
|
||||
@@ -106,13 +104,12 @@ export function getDefaultFaydaRedirectUri(): string {
|
||||
* Returns the redirect URI registered with FAYDA for the complaint flow.
|
||||
*
|
||||
* Must exactly match a URI whitelisted in the FAYDA OIDC client — we reuse
|
||||
* the same /callback path as external-portal registration and distinguish
|
||||
* the same /fayda/callback path as external-portal registration and distinguish
|
||||
* flows via the `state` parameter (see COMPLAINT_FLOW_STATE).
|
||||
*/
|
||||
export function getComplaintFaydaRedirectUri(): string {
|
||||
return (
|
||||
import.meta.env.VITE_COMPLAINT_REDIRECT_URI ||
|
||||
getDefaultFaydaRedirectUri()
|
||||
import.meta.env.VITE_COMPLAINT_REDIRECT_URI || getDefaultFaydaRedirectUri()
|
||||
);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user