fix(security): harden auth and secret handling (HH-444) (#101)

* fix(security): harden auth and credential handling (HH-444)

* fix(security): address HH-444 review blockers

* fix(security): close remaining HH-444 review blockers

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-22 15:45:06 +08:00
committed by GitHub
co-authored by rogee
parent e1557e7f21
commit f719529d66
81 changed files with 2149 additions and 474 deletions
+4 -20
View File
@@ -14,29 +14,13 @@ export default {
},
logout() {
const urlData = endPoints('logout');
const fetchPromise = new Promise((resolve, reject) => {
axios
.delete(urlData.url)
.then(response => {
deleteIndexedDBOnLogout();
clearCookiesOnLogout();
resolve(response);
})
.catch(error => {
reject(error);
});
return axios.delete(urlData.url).finally(() => {
deleteIndexedDBOnLogout();
clearCookiesOnLogout();
});
return fetchPromise;
},
hasAuthCookie() {
return !!Cookies.get('cw_d_session_info');
},
getAuthData() {
if (this.hasAuthCookie()) {
const savedAuthInfo = Cookies.get('cw_d_session_info');
return JSON.parse(savedAuthInfo || '{}');
}
return false;
return !!Cookies.get('cw_d_session_state');
},
profileUpdate({ displayName, avatar, ...profileAttributes }) {
const formData = new FormData();
@@ -0,0 +1,17 @@
import * as APIUtils from '../store/utils/api';
import Auth from './auth';
vi.spyOn(APIUtils, 'clearCookiesOnLogout').mockImplementation(() => {});
vi.spyOn(APIUtils, 'deleteIndexedDBOnLogout').mockResolvedValue();
describe('Auth.logout', () => {
it('clears browser credentials even when the server rejects logout', async () => {
globalThis.axios = {
delete: vi.fn().mockRejectedValue({ response: { status: 401 } }),
};
await expect(Auth.logout()).rejects.toEqual({ response: { status: 401 } });
expect(APIUtils.deleteIndexedDBOnLogout).toHaveBeenCalledOnce();
expect(APIUtils.clearCookiesOnLogout).toHaveBeenCalledOnce();
});
});