Repository navigation
[#197][#201] fix: centralize Bearer auth across non-/api requests - #199
Conversation
|
@Mohamed-Alkafory Thanks for working on this! Few suggestions:
|
4c61385 to
cd70344
Compare
|
@Mohamed-Alkafory Remember to squash |
cd70344 to
c8ed1b0
Compare
|
@jesperpedersen Thanks for the reminder — done, squashed into a single commit. |
|
@sksingh2005 Thanks for the detailed review! Addressed all points:
PTAL whenever you get a chance! |
sksingh2005
left a comment
There was a problem hiding this comment.
LGTM. Two non-fetch paths still bypass auth: utils/forms.ts:66 (submitBrowserForm, fallback in CompanyFormPage.tsx:277 will 403) and ticket PDF anchors in SupportTicketDetailPage.tsx:1341,1359 (plain href GETs carry no Bearer). Worth a follow-up.
[mnemosyne-systems#201] fix: attach auth token to form POST requests Attach Bearer token to read-hook requests (useJson/useText) [mnemosyne-systems#197][mnemosyne-systems#201] fix: centralize Bearer auth in AuthProvider fetch interceptor Widen the global fetch patch from /api/* to all same-origin paths so form POSTs, report exports, and alarm/read hooks share one token path. Drop the per-caller withAuthHeader helper (api.ts, useJson, useText) and the manual refresh in ReportsPage export, and use relative export paths (Quinoa serves dev on :8080, so :5173 cross-origin is dead code).
c8ed1b0 to
84870be
Compare
|
@sksingh2005 Addressed both:
PTAL! |
|
@Mohamed-Alkafory Please rebase |
|
@sksingh2005 Double-checked on my end — the branch is already rebased |
|
Merged. Thanks for your contribution :) |
Closes #197, Closes #201
What this does
After the Keycloak migration, requests outside /api/* weren't carrying the auth token (backend no longer reads cookies). This affected report export, form POSTs (Add User, Create Ticket, etc.), and read hooks (useJson/useText, e.g. the ticket alarm status poll).
Approach (per review feedback)
Instead of patching each call site separately, centralized the fix: AuthProvider's existing fetch interceptor now covers all same-origin requests (previously /api/* only), not just a widened set of individual helpers. This eliminated duplicate token-refresh logic and let me delete the per-file workarounds entirely — api.ts, useJson, and useText are now back to plain fetch calls with no special auth wiring of their own.
Also removed the BACKEND_ORIGIN cross-origin logic in ReportsPage.tsx (unnecessary — dev runs through Quarkus Quinoa on :8080, so :5173 is never hit directly) in favor of a relative path, consistent with the rest of the frontend.