mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 20:35:07 +03:00
fix: update apiAuthenticate to use gotrue
This commit is contained in:
1 parent
3293c5f3c0
commit
5fb21c085e
1 file changed
+42
-15
@@ -4,6 +4,8 @@ import { readOnly } from './supabaseClient'
|
||||
import { SupaResponse, User } from 'types'
|
||||
import { auth0 } from './auth0'
|
||||
import { flattenNamespaceOnUser } from './apiHelpers'
|
||||
import { config } from 'process'
|
||||
import { getAuth0Id, getAuthUser, getIdentity, GOTRUE_ENABLED } from 'lib/gotrue'
|
||||
|
||||
/**
|
||||
* Use this method on api routes to check if user is authenticated and having required permissions.
|
||||
@@ -32,7 +34,7 @@ export async function apiAuthenticate(
|
||||
try {
|
||||
// Check that they are logged in
|
||||
// If no error throw from getAccessToken. That's good, we can continue
|
||||
await auth0.getAccessToken(req, res)
|
||||
if (!(GOTRUE_ENABLED)) await auth0.getAccessToken(req, res)
|
||||
|
||||
const user = await fetchUser(req, res)
|
||||
if (!user) {
|
||||
@@ -53,16 +55,41 @@ export async function apiAuthenticate(
|
||||
* user with only id prop or detail object. It depends on requireUserDetail config
|
||||
*/
|
||||
async function fetchUser(req: NextApiRequest, res: NextApiResponse): Promise<any> {
|
||||
const session = auth0.getSession(req, res)
|
||||
let user_id_supabase = null
|
||||
let user_id_auth0 = null
|
||||
let gotrue_id = null
|
||||
let email = null
|
||||
if (GOTRUE_ENABLED) {
|
||||
const token = req.headers.authorization
|
||||
if (!token) {
|
||||
return res.status(401).end('Unauthorized: missing access token')
|
||||
}
|
||||
let { user: gotrue_user, error: authError } = await getAuthUser(token)
|
||||
if (authError) {
|
||||
throw authError
|
||||
}
|
||||
if (gotrue_user !== null) {
|
||||
gotrue_id = gotrue_user?.id
|
||||
email = gotrue_user.email
|
||||
|
||||
if (!session) {
|
||||
return null
|
||||
let { identity, error } = getIdentity(gotrue_user)
|
||||
if (error) throw error
|
||||
if (identity?.provider !== undefined) {
|
||||
user_id_auth0 = getAuth0Id(identity?.provider, identity?.id)
|
||||
}
|
||||
}
|
||||
} else {
|
||||
const session = auth0.getSession(req, res)
|
||||
if (!session) {
|
||||
return null
|
||||
}
|
||||
const { user: auth0_user } = session
|
||||
const flattened = flattenNamespaceOnUser('https://supabase.io', auth0_user)
|
||||
user_id_supabase = flattened.user_id_supabase
|
||||
user_id_auth0 = flattened.user_id_auth0
|
||||
email = flattened.email
|
||||
}
|
||||
|
||||
const { user: auth0_user } = session
|
||||
const flattened = flattenNamespaceOnUser('https://supabase.io', auth0_user)
|
||||
const { user_id_supabase, user_id_auth0, email } = flattened
|
||||
|
||||
if (user_id_supabase) {
|
||||
return {
|
||||
id: user_id_supabase,
|
||||
@@ -70,15 +97,15 @@ async function fetchUser(req: NextApiRequest, res: NextApiResponse): Promise<any
|
||||
}
|
||||
}
|
||||
|
||||
const { data } = await readOnly
|
||||
.from('users')
|
||||
.select(
|
||||
`
|
||||
const query = readOnly.from('users').select(
|
||||
`
|
||||
id, auth0_id, primary_email, username, first_name, last_name, mobile, is_alpha_user
|
||||
`
|
||||
)
|
||||
.eq('auth0_id', user_id_auth0)
|
||||
.single()
|
||||
)
|
||||
|
||||
const { data } = process.env.GOTRUE_ENABLED
|
||||
? await query.eq('gotrue_id', gotrue_id).single()
|
||||
: await await query.eq('auth0_id', user_id_auth0).single()
|
||||
|
||||
return data
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user