mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-08-26 12:41:04 +00:00
Namespaces the OAuth landing path in all three places it exists: the API's
ack controller, both web apps' routes, and the redirect_uri env values.
A bare /callback claimed a generic top-level path in every app for one
provider's redirect.
The API side needed care. The ack controller moves to @Controller
('fayda/callback'), and the global-prefix exclusion has to name that exact
path — setGlobalPrefix's exclude is an exact route match, not a subtree, so
excluding "fayda" would have left /fayda/callback served at
/api/fayda/callback and 404ing at the registered redirect_uri, while
reading as though it covered everything under /fayda. Naming the full path
also keeps /api/fayda/verification/* prefixed, which every client calls.
Also drops a stale comment on the portal's callback route describing the
popup that no longer exists, and records why the route is public: behind
RequireAuth the onboarding gate redirects to /portal before the code+state
exchange can run.
NOT verified at runtime — this changes route registration, so boot the API
and confirm GET /fayda/callback answers un-prefixed and
/api/fayda/verification/start still resolves before relying on it.
Deploying this requires registering the new redirect_uri with eSignet
first; FAYDA_WEB_REDIRECT_URI, FAYDA_PORTAL_REDIRECT_URI and any mobile
client must be updated in step or verification breaks with a redirect_uri
mismatch.
57 lines
1.8 KiB
TypeScript
57 lines
1.8 KiB
TypeScript
import { useEffect, useState } from "react";
|
|
import { Center, Loader, Stack, Text } from "@mantine/core";
|
|
|
|
import type { FaydaCallbackMessage } from "@/services/verifayda.service";
|
|
|
|
/**
|
|
* Landing page for the eSignet redirect_uri (FAYDA_WEB_REDIRECT_URI →
|
|
* http://localhost:5183/fayda/callback). Runs inside the verification popup:
|
|
* relays ?code&state (or ?error) to the window that opened it via
|
|
* postMessage, then closes itself. The opener performs the /complete call
|
|
* so the single-use session is only consumed once, in one place.
|
|
*/
|
|
const FaydaCallbackPage = () => {
|
|
const [standalone, setStandalone] = useState(false);
|
|
|
|
useEffect(() => {
|
|
const params = new URLSearchParams(window.location.search);
|
|
const message: FaydaCallbackMessage = {
|
|
type: "fayda-callback",
|
|
code: params.get("code") ?? undefined,
|
|
state: params.get("state") ?? undefined,
|
|
error: params.get("error") ?? undefined,
|
|
errorDescription: params.get("error_description") ?? undefined,
|
|
};
|
|
|
|
if (window.opener && window.opener !== window) {
|
|
(window.opener as Window).postMessage(message, window.location.origin);
|
|
window.close();
|
|
} else {
|
|
// Opened as a full-page redirect instead of a popup — nothing to relay to.
|
|
setStandalone(true);
|
|
}
|
|
}, []);
|
|
|
|
return (
|
|
<Center h="100vh">
|
|
<Stack align="center" gap="sm">
|
|
{standalone ? (
|
|
<>
|
|
<Text fw={600}>Verification window lost its parent page</Text>
|
|
<Text size="sm" c="dimmed">
|
|
Close this tab and restart the verification from the form.
|
|
</Text>
|
|
</>
|
|
) : (
|
|
<>
|
|
<Loader size="sm" />
|
|
<Text size="sm" c="dimmed">Completing Fayda verification…</Text>
|
|
</>
|
|
)}
|
|
</Stack>
|
|
</Center>
|
|
);
|
|
};
|
|
|
|
export default FaydaCallbackPage;
|