fix: webapp session

This commit is contained in:
3252a8
2026-04-27 20:50:24 +03:00
parent b39fb73c30
commit b87b6cd378
2 changed files with 38 additions and 81 deletions
+38 -2
View File
@@ -92,6 +92,7 @@ const MOCK = (() => {
const CFG = readJsonScript('webapp-config') || (MOCK && MOCK.config) || {}; const CFG = readJsonScript('webapp-config') || (MOCK && MOCK.config) || {};
const tg = window.Telegram && window.Telegram.WebApp ? window.Telegram.WebApp : null; const tg = window.Telegram && window.Telegram.WebApp ? window.Telegram.WebApp : null;
const TELEGRAM_LOGIN_WIDGET_URL = './telegram-widget.js'; const TELEGRAM_LOGIN_WIDGET_URL = './telegram-widget.js';
const MANUAL_LOGOUT_FLAG_KEY = 'rw_webapp_manual_logout';
const state = { const state = {
token: MOCK ? 'local-preview' : (localStorage.getItem('rw_webapp_token') || ''), token: MOCK ? 'local-preview' : (localStorage.getItem('rw_webapp_token') || ''),
csrfToken: MOCK ? '' : (readCookie('rw_webapp_csrf') || ''), csrfToken: MOCK ? '' : (readCookie('rw_webapp_csrf') || ''),
@@ -510,6 +511,12 @@ const MOCK = (() => {
return; return;
} }
// Explicit logout should survive refresh, even if the old cookie session is still valid.
if (isManuallyLoggedOut()) {
await startExternalAuth();
return;
}
const widgetAuthData = readTelegramLoginWidgetAuthData(); const widgetAuthData = readTelegramLoginWidgetAuthData();
if (widgetAuthData) { if (widgetAuthData) {
const authenticated = await finalizeTelegramAuth(widgetAuthData); const authenticated = await finalizeTelegramAuth(widgetAuthData);
@@ -2212,6 +2219,7 @@ const MOCK = (() => {
} }
function setToken(token, csrfToken = '') { function setToken(token, csrfToken = '') {
clearManualLogoutFlag();
state.token = token; state.token = token;
state.csrfToken = csrfToken || readCookie('rw_webapp_csrf') || state.csrfToken || ''; state.csrfToken = csrfToken || readCookie('rw_webapp_csrf') || state.csrfToken || '';
} }
@@ -2222,6 +2230,30 @@ const MOCK = (() => {
localStorage.removeItem('rw_webapp_token'); localStorage.removeItem('rw_webapp_token');
} }
function clearReadableAuthCookie() {
document.cookie = 'rw_webapp_csrf=; Max-Age=0; path=/; SameSite=None; Secure';
}
function isManuallyLoggedOut() {
try {
return localStorage.getItem(MANUAL_LOGOUT_FLAG_KEY) === '1';
} catch (e) {
return false;
}
}
function markManualLogout() {
try {
localStorage.setItem(MANUAL_LOGOUT_FLAG_KEY, '1');
} catch (e) { }
}
function clearManualLogoutFlag() {
try {
localStorage.removeItem(MANUAL_LOGOUT_FLAG_KEY);
} catch (e) { }
}
function readCookie(name) { function readCookie(name) {
const prefix = name + '='; const prefix = name + '=';
const cookie = document.cookie.split('; ').find(part => part.startsWith(prefix)); const cookie = document.cookie.split('; ').find(part => part.startsWith(prefix));
@@ -2251,13 +2283,17 @@ const MOCK = (() => {
if (button) button.disabled = Boolean(busy); if (button) button.disabled = Boolean(busy);
} }
function logout() { async function logout() {
toggleUserMenu(false); toggleUserMenu(false);
void publicApi('/auth/logout', {}).catch(() => {}); markManualLogout();
clearReadableAuthCookie();
clearToken(); clearToken();
closePaymentFlow(); closePaymentFlow();
closeEmailLoginCodeModal(); closeEmailLoginCodeModal();
startExternalAuth(); startExternalAuth();
try {
await publicApi('/auth/logout', {keepalive: true});
} catch (e) { }
} }
function showLoader() { function showLoader() {
File diff suppressed because one or more lines are too long