fix(oauth): use separate Set-Cookie headers for multiple cookies
Browser cannot parse multiple cookies from a single Set-Cookie header joined by comma (RFC 6265). Use Headers.append() to send each cookie in its own Set-Cookie header. Fixes state/verifier cookie mismatch.
This commit is contained in:
@@ -106,17 +106,14 @@ export const GET: APIRoute = async ({ url, request }) => {
|
|||||||
expiresAt,
|
expiresAt,
|
||||||
});
|
});
|
||||||
|
|
||||||
const cookies = [
|
const headers = new Headers();
|
||||||
`${COOKIE_NAME}=${sessionToken}; HttpOnly; SameSite=Strict; Max-Age=604800; Path=/`,
|
headers.set('Location', '/dm/');
|
||||||
`${VERIFIER_COOKIE_NAME}=; HttpOnly; SameSite=Strict; Max-Age=0; Path=/`,
|
headers.append('Set-Cookie', `${COOKIE_NAME}=${sessionToken}; HttpOnly; SameSite=Strict; Max-Age=604800; Path=/`);
|
||||||
`oauth_state=; HttpOnly; SameSite=Strict; Max-Age=0; Path=/`,
|
headers.append('Set-Cookie', `${VERIFIER_COOKIE_NAME}=; HttpOnly; SameSite=Strict; Max-Age=0; Path=/`);
|
||||||
];
|
headers.append('Set-Cookie', `oauth_state=; HttpOnly; SameSite=Strict; Max-Age=0; Path=/`);
|
||||||
|
|
||||||
return new Response(null, {
|
return new Response(null, {
|
||||||
status: 302,
|
status: 302,
|
||||||
headers: {
|
headers,
|
||||||
Location: '/dm/',
|
|
||||||
'Set-Cookie': cookies.join(', '),
|
|
||||||
},
|
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -107,17 +107,14 @@ export const GET: APIRoute = async ({ url, request }) => {
|
|||||||
expiresAt,
|
expiresAt,
|
||||||
});
|
});
|
||||||
|
|
||||||
const cookies = [
|
const headers = new Headers();
|
||||||
`${COOKIE_NAME}=${sessionToken}; HttpOnly; SameSite=Strict; Max-Age=604800; Path=/`,
|
headers.set('Location', '/dm/');
|
||||||
`${VERIFIER_COOKIE_NAME}=; HttpOnly; SameSite=Strict; Max-Age=0; Path=/`,
|
headers.append('Set-Cookie', `${COOKIE_NAME}=${sessionToken}; HttpOnly; SameSite=Strict; Max-Age=604800; Path=/`);
|
||||||
`oauth_state=; HttpOnly; SameSite=Strict; Max-Age=0; Path=/`,
|
headers.append('Set-Cookie', `${VERIFIER_COOKIE_NAME}=; HttpOnly; SameSite=Strict; Max-Age=0; Path=/`);
|
||||||
];
|
headers.append('Set-Cookie', `oauth_state=; HttpOnly; SameSite=Strict; Max-Age=0; Path=/`);
|
||||||
|
|
||||||
return new Response(null, {
|
return new Response(null, {
|
||||||
status: 302,
|
status: 302,
|
||||||
headers: {
|
headers,
|
||||||
Location: '/dm/',
|
|
||||||
'Set-Cookie': cookies.join(', '),
|
|
||||||
},
|
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -22,16 +22,13 @@ export const GET: APIRoute = async ({ url }) => {
|
|||||||
|
|
||||||
const redirectUrl = `${vkOAuthConfig.authUrl}?${params.toString()}`;
|
const redirectUrl = `${vkOAuthConfig.authUrl}?${params.toString()}`;
|
||||||
|
|
||||||
const cookies = [
|
const headers = new Headers();
|
||||||
`${VERIFIER_COOKIE_NAME}=${encodeURIComponent(verifier)}; HttpOnly; Secure; SameSite=Lax; Max-Age=600; Path=/`,
|
headers.set('Location', redirectUrl);
|
||||||
`oauth_state=${encodeURIComponent(state)}; HttpOnly; Secure; SameSite=Lax; Max-Age=600; Path=/`,
|
headers.append('Set-Cookie', `${VERIFIER_COOKIE_NAME}=${encodeURIComponent(verifier)}; HttpOnly; Secure; SameSite=Lax; Max-Age=600; Path=/`);
|
||||||
];
|
headers.append('Set-Cookie', `oauth_state=${encodeURIComponent(state)}; HttpOnly; Secure; SameSite=Lax; Max-Age=600; Path=/`);
|
||||||
|
|
||||||
return new Response(null, {
|
return new Response(null, {
|
||||||
status: 302,
|
status: 302,
|
||||||
headers: {
|
headers,
|
||||||
Location: redirectUrl,
|
|
||||||
'Set-Cookie': cookies.join(', '),
|
|
||||||
},
|
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -22,16 +22,13 @@ export const GET: APIRoute = async ({ url }) => {
|
|||||||
|
|
||||||
const redirectUrl = `${yandexOAuthConfig.authUrl}?${params.toString()}`;
|
const redirectUrl = `${yandexOAuthConfig.authUrl}?${params.toString()}`;
|
||||||
|
|
||||||
const cookies = [
|
const headers = new Headers();
|
||||||
`${VERIFIER_COOKIE_NAME}=${encodeURIComponent(verifier)}; HttpOnly; Secure; SameSite=Lax; Max-Age=600; Path=/`,
|
headers.set('Location', redirectUrl);
|
||||||
`oauth_state=${encodeURIComponent(state)}; HttpOnly; Secure; SameSite=Lax; Max-Age=600; Path=/`,
|
headers.append('Set-Cookie', `${VERIFIER_COOKIE_NAME}=${encodeURIComponent(verifier)}; HttpOnly; Secure; SameSite=Lax; Max-Age=600; Path=/`);
|
||||||
];
|
headers.append('Set-Cookie', `oauth_state=${encodeURIComponent(state)}; HttpOnly; Secure; SameSite=Lax; Max-Age=600; Path=/`);
|
||||||
|
|
||||||
return new Response(null, {
|
return new Response(null, {
|
||||||
status: 302,
|
status: 302,
|
||||||
headers: {
|
headers,
|
||||||
Location: redirectUrl,
|
|
||||||
'Set-Cookie': cookies.join(', '),
|
|
||||||
},
|
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user