fix(security): harden auth and secret handling (HH-444) (#101)
* fix(security): harden auth and credential handling (HH-444) * fix(security): address HH-444 review blockers * fix(security): close remaining HH-444 review blockers --------- Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
@@ -14,29 +14,13 @@ export default {
|
||||
},
|
||||
logout() {
|
||||
const urlData = endPoints('logout');
|
||||
const fetchPromise = new Promise((resolve, reject) => {
|
||||
axios
|
||||
.delete(urlData.url)
|
||||
.then(response => {
|
||||
deleteIndexedDBOnLogout();
|
||||
clearCookiesOnLogout();
|
||||
resolve(response);
|
||||
})
|
||||
.catch(error => {
|
||||
reject(error);
|
||||
});
|
||||
return axios.delete(urlData.url).finally(() => {
|
||||
deleteIndexedDBOnLogout();
|
||||
clearCookiesOnLogout();
|
||||
});
|
||||
return fetchPromise;
|
||||
},
|
||||
hasAuthCookie() {
|
||||
return !!Cookies.get('cw_d_session_info');
|
||||
},
|
||||
getAuthData() {
|
||||
if (this.hasAuthCookie()) {
|
||||
const savedAuthInfo = Cookies.get('cw_d_session_info');
|
||||
return JSON.parse(savedAuthInfo || '{}');
|
||||
}
|
||||
return false;
|
||||
return !!Cookies.get('cw_d_session_state');
|
||||
},
|
||||
profileUpdate({ displayName, avatar, ...profileAttributes }) {
|
||||
const formData = new FormData();
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
import * as APIUtils from '../store/utils/api';
|
||||
import Auth from './auth';
|
||||
|
||||
vi.spyOn(APIUtils, 'clearCookiesOnLogout').mockImplementation(() => {});
|
||||
vi.spyOn(APIUtils, 'deleteIndexedDBOnLogout').mockResolvedValue();
|
||||
|
||||
describe('Auth.logout', () => {
|
||||
it('clears browser credentials even when the server rejects logout', async () => {
|
||||
globalThis.axios = {
|
||||
delete: vi.fn().mockRejectedValue({ response: { status: 401 } }),
|
||||
};
|
||||
|
||||
await expect(Auth.logout()).rejects.toEqual({ response: { status: 401 } });
|
||||
expect(APIUtils.deleteIndexedDBOnLogout).toHaveBeenCalledOnce();
|
||||
expect(APIUtils.clearCookiesOnLogout).toHaveBeenCalledOnce();
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user