Avoid account feedback 401 before auth
This commit is contained in:
@@ -7,6 +7,10 @@ import {
|
|||||||
feedbackStatusLabel,
|
feedbackStatusLabel,
|
||||||
feedbackStatusTone,
|
feedbackStatusTone,
|
||||||
} from "@/components/dashboard/scan-terminal/feedback-status";
|
} from "@/components/dashboard/scan-terminal/feedback-status";
|
||||||
|
import {
|
||||||
|
getSupabaseBrowserClient,
|
||||||
|
hasSupabasePublicEnv,
|
||||||
|
} from "@/lib/supabase/client";
|
||||||
|
|
||||||
function compactDate(value?: string) {
|
function compactDate(value?: string) {
|
||||||
if (!value) return "--";
|
if (!value) return "--";
|
||||||
@@ -97,9 +101,27 @@ export function AccountFeedbackPanel({
|
|||||||
setLoading(true);
|
setLoading(true);
|
||||||
setError("");
|
setError("");
|
||||||
try {
|
try {
|
||||||
|
if (!hasSupabasePublicEnv()) {
|
||||||
|
setAvailable(false);
|
||||||
|
setEntries([]);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const {
|
||||||
|
data: { session },
|
||||||
|
} = await getSupabaseBrowserClient().auth.getSession();
|
||||||
|
if (signal?.aborted) return;
|
||||||
|
const accessToken = String(session?.access_token || "").trim();
|
||||||
|
if (!accessToken) {
|
||||||
|
setAvailable(false);
|
||||||
|
setEntries([]);
|
||||||
|
return;
|
||||||
|
}
|
||||||
const res = await fetch("/api/feedback?limit=10", {
|
const res = await fetch("/api/feedback?limit=10", {
|
||||||
cache: "no-store",
|
cache: "no-store",
|
||||||
headers: { Accept: "application/json" },
|
headers: {
|
||||||
|
Accept: "application/json",
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
},
|
||||||
signal,
|
signal,
|
||||||
});
|
});
|
||||||
if (res.status === 401 || res.status === 403) {
|
if (res.status === 401 || res.status === 403) {
|
||||||
|
|||||||
@@ -31,6 +31,20 @@ export function runTests() {
|
|||||||
!feedbackPanelSource.includes("setInterval"),
|
!feedbackPanelSource.includes("setInterval"),
|
||||||
"account feedback panel must load the current user's feedback once, support manual refresh, and avoid polling",
|
"account feedback panel must load the current user's feedback once, support manual refresh, and avoid polling",
|
||||||
);
|
);
|
||||||
|
const sessionLookupIndex = feedbackPanelSource.indexOf(".auth.getSession()");
|
||||||
|
const feedbackFetchIndex = feedbackPanelSource.indexOf("/api/feedback?limit=10");
|
||||||
|
assert(
|
||||||
|
feedbackPanelSource.includes("getSupabaseBrowserClient") &&
|
||||||
|
feedbackPanelSource.includes("hasSupabasePublicEnv") &&
|
||||||
|
sessionLookupIndex >= 0 &&
|
||||||
|
feedbackFetchIndex >= 0 &&
|
||||||
|
sessionLookupIndex < feedbackFetchIndex &&
|
||||||
|
feedbackPanelSource.includes("accessToken") &&
|
||||||
|
feedbackPanelSource.includes("Authorization: `Bearer ${accessToken}`") &&
|
||||||
|
feedbackPanelSource.includes("if (!accessToken)") &&
|
||||||
|
feedbackPanelSource.includes("setAvailable(false)"),
|
||||||
|
"account feedback panel must avoid unauthenticated 401 requests by checking the browser session before fetching feedback",
|
||||||
|
);
|
||||||
assert(
|
assert(
|
||||||
feedbackPanelSource.includes("reward_points") &&
|
feedbackPanelSource.includes("reward_points") &&
|
||||||
feedbackPanelSource.includes("reward_reason") &&
|
feedbackPanelSource.includes("reward_reason") &&
|
||||||
|
|||||||
Reference in New Issue
Block a user