From 743c721e7b577cbe99ca0e777d0d4b43ebc505fd Mon Sep 17 00:00:00 2001 From: Kalle <38327916+Sendouc@users.noreply.github.com> Date: Tue, 26 Sep 2023 19:44:23 +0300 Subject: [PATCH] Token call behind GW --- .env.example | 4 ++-- app/modules/auth/DiscordStrategy.server.ts | 17 ++++++----------- 2 files changed, 8 insertions(+), 13 deletions(-) diff --git a/.env.example b/.env.example index 2f5103a8a..2dbf69c8e 100644 --- a/.env.example +++ b/.env.example @@ -7,8 +7,8 @@ SESSION_SECRET=secret // Auth https://discord.com/developers DISCORD_CLIENT_ID= DISCORD_CLIENT_SECRET= -AUTH_GATEWAY_URL= -AUTH_GATEWAY_SECRET= +AUTH_GATEWAY_PROFILE_URL= +AUTH_GATEWAY_TOKEN_URL= // Patreon integration https://www.patreon.com/portal/registration/register-clients PATREON_ACCESS_TOKEN= diff --git a/app/modules/auth/DiscordStrategy.server.ts b/app/modules/auth/DiscordStrategy.server.ts index 19341856d..2445bc7d2 100644 --- a/app/modules/auth/DiscordStrategy.server.ts +++ b/app/modules/auth/DiscordStrategy.server.ts @@ -47,7 +47,9 @@ export class DiscordStrategy extends OAuth2Strategy< super( { authorizationURL: "https://discord.com/api/oauth2/authorize", - tokenURL: "https://discord.com/api/oauth2/token", + tokenURL: + process.env["AUTH_GATEWAY_TOKEN_URL"] ?? + "https://discord.com/api/oauth2/token", clientID: envVars.DISCORD_CLIENT_ID, clientSecret: envVars.DISCORD_CLIENT_SECRET, callbackURL: new URL("/auth/callback", envVars.BASE_URL).toString(), @@ -77,9 +79,7 @@ export class DiscordStrategy extends OAuth2Strategy< } private authGatewayEnabled() { - return Boolean( - process.env["AUTH_GATEWAY_URL"] && process.env["AUTH_GATEWAY_SECRET"], - ); + return Boolean(process.env["AUTH_GATEWAY_TOKEN_URL"]); } private async fetchProfileViaDiscordApi(token: string) { @@ -98,14 +98,9 @@ export class DiscordStrategy extends OAuth2Strategy< private async fetchProfileViaGateway(token: string) { console.log("authenticating via gateway..."); - const url = `${process.env["AUTH_GATEWAY_URL"]}?token=${token}`; + const url = `${process.env["AUTH_GATEWAY_PROFILE_URL"]}?token=${token}`; - const options: RequestInit = { - method: "GET", - headers: { "X-Require-Whisk-Auth": process.env["AUTH_GATEWAY_SECRET"]! }, - }; - - return fetch(url, options).then(this.jsonIfOk); + return fetch(url).then(this.jsonIfOk); } private jsonIfOk(res: Response) {