Files
edr-platform/apps/edr-freight-web/backoffice/src/shared/components/FaydaCallbackDispatcher.tsx
Nathnael 3a69b961d4 refactor(freight): move the Fayda callback to /fayda/callback
Namespaces the OAuth landing path in all three places it exists: the API's
ack controller, both web apps' routes, and the redirect_uri env values.
A bare /callback claimed a generic top-level path in every app for one
provider's redirect.

The API side needed care. The ack controller moves to @Controller
('fayda/callback'), and the global-prefix exclusion has to name that exact
path — setGlobalPrefix's exclude is an exact route match, not a subtree, so
excluding "fayda" would have left /fayda/callback served at
/api/fayda/callback and 404ing at the registered redirect_uri, while
reading as though it covered everything under /fayda. Naming the full path
also keeps /api/fayda/verification/* prefixed, which every client calls.

Also drops a stale comment on the portal's callback route describing the
popup that no longer exists, and records why the route is public: behind
RequireAuth the onboarding gate redirects to /portal before the code+state
exchange can run.

NOT verified at runtime — this changes route registration, so boot the API
and confirm GET /fayda/callback answers un-prefixed and
/api/fayda/verification/start still resolves before relying on it.

Deploying this requires registering the new redirect_uri with eSignet
first; FAYDA_WEB_REDIRECT_URI, FAYDA_PORTAL_REDIRECT_URI and any mobile
client must be updated in step or verification breaks with a redirect_uri
mismatch.
2026-08-04 12:43:25 +00:00

21 lines
779 B
TypeScript

import { useSearchParams } from "react-router-dom";
import { isComplaintFaydaState } from "@/shared/utils/faydaOidc";
import ComplaintCallbackPage from "@/complaints/pages/ComplaintCallbackPage";
import ExternalPortalCallback from "@/external-portal/components/Registration/ExternalPortalCallBack";
/**
* Single FAYDA OIDC callback entry point.
* Fayda only allows whitelisted redirect URIs (e.g. /fayda/callback) — route
* internally based on the `state` param sent during authorization.
*/
export default function FaydaCallbackDispatcher() {
const [searchParams] = useSearchParams();
const state = searchParams.get("state");
if (isComplaintFaydaState(state)) {
return <ComplaintCallbackPage />;
}
return <ExternalPortalCallback />;
}