mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-07-26 18:04:45 +10:00
Squashed commit of the following:
commit b2b0470a1d9267d042ec0ac66523c6635bf5b199
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:13:38 2026 +0200
chore: update .gitignore to include .vite-hooks and modify pnpm-lock.yaml for dependencies
commit d28fadb5cd8706c874e616102878b4a394ec84c1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:08:04 2026 +0200
fix: remove timestamp conflict guard
commit c6998d9dbab19d09d3c8054feef1d2e4117555eb
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 12:11:51 2026 +0200
chore(release): v5.1.5
commit f33d168711804880e1f12e88d24290aae16cc258
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:35 2026 +0200
revert: compose.yml
commit d961e6535811a10c335525fb33a08d03e737278d
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:08 2026 +0200
refactor(agent): replace 'revert' terminology with 'restore' for clarity, resolves #3086
commit 17f351171be218e33f01c469d95e4164d4c8dc57
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:10:41 2026 +0200
refactor(pdf): simplify sidebar section filtering and update summary feature logic
commit d55179b9d76879e3204de185e8b53fadd0a107ed
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:53:37 2026 +0200
chore: update pnpm-lock.yaml and turbo.json
commit 7cade6980e1a04352536bd44ef773f338c4ef599
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:38:30 2026 +0200
fix(polyfill): add tested polyfill for Map Upsert methods
commit 26d175bb9c53d93225d1e907678445252c13d660
Merge: 1cf33dc6c 5b1297fa2
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:23:29 2026 +0200
Merge remote-tracking branch 'origin/main' into feat/explore-hono-orpc-migration
# Conflicts:
# packages/api/src/services/agent-url.ts
# packages/runtime-externals/package.json
commit 1cf33dc6c9d81735730ad656e16dab6501c6d6a1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:22:12 2026 +0200
chore: preserve branch changes before main sync
commit b380a4b00fdbcdd81ff4f8ef72b330fd027ccda5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Mon May 18 07:50:28 2026 +0200
chore: lot of fixes for monorepo migration
commit 8fcf0ec64e1c29572ebaff494338368bfcf75760
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 13:57:17 2026 +0200
chore: update knip version and refine web app routing with new SEO endpoints
commit 234e68086ff15610a93877354c98e2c020364533
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 12:10:06 2026 +0200
refactor(auth): update OAuth routes to include API prefix and remove unused schema endpoint
commit 91c84b9a8496b0ce21d71cae9f8b2a027638c9ac
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:54:29 2026 +0200
chore: update dependencies and enhance PWA metadata in web app
commit 150117d4a5a9dd6cd92c64891aad8cae90f6a7af
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:12:35 2026 +0200
docs: revise manifest-only pwa testing scope
commit 6b939a55661aec9dd8122b184e4b60a5c7325fb5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:11:33 2026 +0200
docs: add manifest-only pwa design
commit 1422e1fc96c400948b273210a1067251087d15d4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:05:04 2026 +0200
chore(dev): simplify server proxy config
commit bc2ff5a9f6fda41e6c40333c8f163aa23a6c5e48
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:50 2026 +0200
docs: add unsafe oauth redirect plan
commit 445359ebe9b96c1515bf1c4c3f73ba8a8448ec12
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:34 2026 +0200
feat(auth): add unsafe oauth redirect flag
commit 73fffdd24598e56b2793f7657919bc794835892e
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:55:02 2026 +0200
docs: design unsafe oauth redirect flag
commit c0066aa19c15fc8a4c8e5179ed49889c117519f4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:22:04 2026 +0200
chore: update translation source paths
commit 9033da082418d252aafd6c2eed72f71f014be3d9
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:09:25 2026 +0200
refactor(arch): react spa + hono migration
commit 6f27936c11bda895977dc63ee550c3346d4ce24b
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 01:10:47 2026 +0200
docs: add docker nightly tagging design
commit ecc1fd9a88a0ee1dca2f1977dfc17f74527fe1da
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Thu May 14 20:05:44 2026 +0200
feat: migrate to hono spa server
This commit is contained in:
+11
-16
@@ -24,7 +24,8 @@ import { sendEmail } from "@reactive-resume/email/transport";
|
||||
import { env } from "@reactive-resume/env/server";
|
||||
import { rateLimitConfig, TRUSTED_IP_HEADERS } from "@reactive-resume/utils/rate-limit";
|
||||
import { generateId, toUsername } from "@reactive-resume/utils/string";
|
||||
import { isAllowedOAuthRedirectUri, parseAllowedHostList } from "@reactive-resume/utils/url-security.node";
|
||||
import { isAllowedOAuthRedirectUri } from "@reactive-resume/utils/url-security.node";
|
||||
import { getTrustedOrigins } from "./trusted-origins";
|
||||
|
||||
const authBaseUrl = env.APP_URL;
|
||||
const isRateLimitEnabled = process.env.NODE_ENV === "production";
|
||||
@@ -55,17 +56,7 @@ function isCustomOAuthProviderEnabled() {
|
||||
return Boolean(env.OAUTH_CLIENT_ID) && Boolean(env.OAUTH_CLIENT_SECRET) && (hasDiscovery || hasManual);
|
||||
}
|
||||
|
||||
function getTrustedOrigins(): string[] {
|
||||
const normalizeOrigin = (origin: string): string => origin.replace(/\/$/, "");
|
||||
const trustedOrigins = new Set<string>(["http://localhost:3000", "http://127.0.0.1:3000"]);
|
||||
|
||||
trustedOrigins.add(normalizeOrigin(new URL(env.APP_URL).origin));
|
||||
|
||||
return Array.from(trustedOrigins);
|
||||
}
|
||||
|
||||
const TRUSTED_ORIGINS = getTrustedOrigins();
|
||||
const OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS = parseAllowedHostList(env.OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS);
|
||||
const TRUSTED_ORIGINS = getTrustedOrigins(env.APP_URL);
|
||||
const oauthProviderRateLimit = isRateLimitEnabled
|
||||
? rateLimitConfig.betterAuth.oauthProvider
|
||||
: ({
|
||||
@@ -261,7 +252,11 @@ const getAuthConfig = () => {
|
||||
if (typeof uri !== "string") {
|
||||
throw new APIError("BAD_REQUEST", { message: "redirect_uris entries must be strings" });
|
||||
}
|
||||
if (!isAllowedOAuthRedirectUri(uri, TRUSTED_ORIGINS, OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS)) {
|
||||
if (
|
||||
!isAllowedOAuthRedirectUri(uri, TRUSTED_ORIGINS, {
|
||||
allowUnsafe: env.FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI,
|
||||
})
|
||||
) {
|
||||
throw new APIError("BAD_REQUEST", {
|
||||
message: "redirect_uri is not allowed for dynamic client registration",
|
||||
});
|
||||
@@ -390,12 +385,12 @@ const getAuthConfig = () => {
|
||||
},
|
||||
}),
|
||||
oauthProvider({
|
||||
loginPage: "/auth/oauth",
|
||||
consentPage: "/auth/oauth",
|
||||
loginPage: "/api/auth/oauth",
|
||||
consentPage: "/api/auth/oauth",
|
||||
validAudiences: OAUTH_AUDIENCES,
|
||||
allowDynamicClientRegistration: true,
|
||||
// Required for MCP client onboarding (RFC 7591). Phishing vector is closed by the
|
||||
// redirect_uri allowlist in the hooks.before middleware above and in src/routes/api/auth.$.ts.
|
||||
// redirect_uri policy in the hooks.before middleware above and server auth preflight.
|
||||
allowUnauthenticatedClientRegistration: true,
|
||||
rateLimit: oauthProviderRateLimit,
|
||||
silenceWarnings: { oauthAuthServerConfig: true },
|
||||
|
||||
@@ -5,22 +5,17 @@ const authMock = vi.hoisted(() => ({
|
||||
getSession: vi.fn(),
|
||||
},
|
||||
}));
|
||||
const headersMock = vi.hoisted(() => vi.fn(() => new Headers()));
|
||||
|
||||
vi.mock("./config", () => ({ auth: authMock }));
|
||||
vi.mock("@tanstack/react-start/server", () => ({
|
||||
getRequestHeaders: headersMock,
|
||||
}));
|
||||
|
||||
const { getSession } = await import("./functions");
|
||||
|
||||
describe("getSession", () => {
|
||||
it("delegates to auth.api.getSession with the current request headers", async () => {
|
||||
it("delegates to auth.api.getSession with the provided request headers", async () => {
|
||||
const headers = new Headers({ authorization: "Bearer abc" });
|
||||
headersMock.mockReturnValueOnce(headers);
|
||||
authMock.api.getSession.mockResolvedValueOnce({ user: { id: "u1" }, session: { id: "s1" } });
|
||||
|
||||
const result = await getSession();
|
||||
const result = await getSession(headers);
|
||||
|
||||
expect(authMock.api.getSession).toHaveBeenCalledWith({ headers });
|
||||
expect(result).toMatchObject({ user: { id: "u1" } });
|
||||
@@ -29,7 +24,7 @@ describe("getSession", () => {
|
||||
it("returns null when better-auth returns no session", async () => {
|
||||
authMock.api.getSession.mockResolvedValueOnce(null);
|
||||
|
||||
const result = await getSession();
|
||||
const result = await getSession(new Headers());
|
||||
|
||||
expect(result).toBeNull();
|
||||
});
|
||||
|
||||
@@ -1,8 +1,7 @@
|
||||
import type { AuthSession } from "./types";
|
||||
import { getRequestHeaders } from "@tanstack/react-start/server";
|
||||
import { auth } from "./config";
|
||||
|
||||
export async function getSession(): Promise<AuthSession | null> {
|
||||
const result = await auth.api.getSession({ headers: getRequestHeaders() });
|
||||
export async function getSession(headers: Headers): Promise<AuthSession | null> {
|
||||
const result = await auth.api.getSession({ headers });
|
||||
return result as AuthSession | null;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { getTrustedOrigins } from "./trusted-origins";
|
||||
|
||||
describe("getTrustedOrigins", () => {
|
||||
it("trusts the localhost alias for a 127.0.0.1 app URL on the same port", () => {
|
||||
expect(getTrustedOrigins("http://127.0.0.1:3100")).toEqual(
|
||||
expect.arrayContaining(["http://127.0.0.1:3100", "http://localhost:3100"]),
|
||||
);
|
||||
});
|
||||
|
||||
it("trusts the 127.0.0.1 alias for a localhost app URL on the same port", () => {
|
||||
expect(getTrustedOrigins("http://localhost:3100")).toEqual(
|
||||
expect.arrayContaining(["http://localhost:3100", "http://127.0.0.1:3100"]),
|
||||
);
|
||||
});
|
||||
|
||||
it("does not add a loopback alias for non-localhost app URLs", () => {
|
||||
expect(getTrustedOrigins("https://example.com")).not.toContain("https://localhost");
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,15 @@
|
||||
export function getTrustedOrigins(appUrl: string): string[] {
|
||||
const normalizeOrigin = (origin: string): string => origin.replace(/\/$/, "");
|
||||
const trustedOrigins = new Set<string>(["http://localhost:3000", "http://127.0.0.1:3000"]);
|
||||
|
||||
const configuredUrl = new URL(appUrl);
|
||||
trustedOrigins.add(normalizeOrigin(configuredUrl.origin));
|
||||
|
||||
if (configuredUrl.hostname === "localhost" || configuredUrl.hostname === "127.0.0.1") {
|
||||
const loopbackAlias = configuredUrl.hostname === "localhost" ? "127.0.0.1" : "localhost";
|
||||
configuredUrl.hostname = loopbackAlias;
|
||||
trustedOrigins.add(normalizeOrigin(configuredUrl.origin));
|
||||
}
|
||||
|
||||
return Array.from(trustedOrigins);
|
||||
}
|
||||
Reference in New Issue
Block a user