fix: webapp session
This commit is contained in:
@@ -92,6 +92,7 @@ const MOCK = (() => {
|
|||||||
const CFG = readJsonScript('webapp-config') || (MOCK && MOCK.config) || {};
|
const CFG = readJsonScript('webapp-config') || (MOCK && MOCK.config) || {};
|
||||||
const tg = window.Telegram && window.Telegram.WebApp ? window.Telegram.WebApp : null;
|
const tg = window.Telegram && window.Telegram.WebApp ? window.Telegram.WebApp : null;
|
||||||
const TELEGRAM_LOGIN_WIDGET_URL = './telegram-widget.js';
|
const TELEGRAM_LOGIN_WIDGET_URL = './telegram-widget.js';
|
||||||
|
const MANUAL_LOGOUT_FLAG_KEY = 'rw_webapp_manual_logout';
|
||||||
const state = {
|
const state = {
|
||||||
token: MOCK ? 'local-preview' : (localStorage.getItem('rw_webapp_token') || ''),
|
token: MOCK ? 'local-preview' : (localStorage.getItem('rw_webapp_token') || ''),
|
||||||
csrfToken: MOCK ? '' : (readCookie('rw_webapp_csrf') || ''),
|
csrfToken: MOCK ? '' : (readCookie('rw_webapp_csrf') || ''),
|
||||||
@@ -510,6 +511,12 @@ const MOCK = (() => {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Explicit logout should survive refresh, even if the old cookie session is still valid.
|
||||||
|
if (isManuallyLoggedOut()) {
|
||||||
|
await startExternalAuth();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
const widgetAuthData = readTelegramLoginWidgetAuthData();
|
const widgetAuthData = readTelegramLoginWidgetAuthData();
|
||||||
if (widgetAuthData) {
|
if (widgetAuthData) {
|
||||||
const authenticated = await finalizeTelegramAuth(widgetAuthData);
|
const authenticated = await finalizeTelegramAuth(widgetAuthData);
|
||||||
@@ -2212,6 +2219,7 @@ const MOCK = (() => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function setToken(token, csrfToken = '') {
|
function setToken(token, csrfToken = '') {
|
||||||
|
clearManualLogoutFlag();
|
||||||
state.token = token;
|
state.token = token;
|
||||||
state.csrfToken = csrfToken || readCookie('rw_webapp_csrf') || state.csrfToken || '';
|
state.csrfToken = csrfToken || readCookie('rw_webapp_csrf') || state.csrfToken || '';
|
||||||
}
|
}
|
||||||
@@ -2222,6 +2230,30 @@ const MOCK = (() => {
|
|||||||
localStorage.removeItem('rw_webapp_token');
|
localStorage.removeItem('rw_webapp_token');
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function clearReadableAuthCookie() {
|
||||||
|
document.cookie = 'rw_webapp_csrf=; Max-Age=0; path=/; SameSite=None; Secure';
|
||||||
|
}
|
||||||
|
|
||||||
|
function isManuallyLoggedOut() {
|
||||||
|
try {
|
||||||
|
return localStorage.getItem(MANUAL_LOGOUT_FLAG_KEY) === '1';
|
||||||
|
} catch (e) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function markManualLogout() {
|
||||||
|
try {
|
||||||
|
localStorage.setItem(MANUAL_LOGOUT_FLAG_KEY, '1');
|
||||||
|
} catch (e) { }
|
||||||
|
}
|
||||||
|
|
||||||
|
function clearManualLogoutFlag() {
|
||||||
|
try {
|
||||||
|
localStorage.removeItem(MANUAL_LOGOUT_FLAG_KEY);
|
||||||
|
} catch (e) { }
|
||||||
|
}
|
||||||
|
|
||||||
function readCookie(name) {
|
function readCookie(name) {
|
||||||
const prefix = name + '=';
|
const prefix = name + '=';
|
||||||
const cookie = document.cookie.split('; ').find(part => part.startsWith(prefix));
|
const cookie = document.cookie.split('; ').find(part => part.startsWith(prefix));
|
||||||
@@ -2251,13 +2283,17 @@ const MOCK = (() => {
|
|||||||
if (button) button.disabled = Boolean(busy);
|
if (button) button.disabled = Boolean(busy);
|
||||||
}
|
}
|
||||||
|
|
||||||
function logout() {
|
async function logout() {
|
||||||
toggleUserMenu(false);
|
toggleUserMenu(false);
|
||||||
void publicApi('/auth/logout', {}).catch(() => {});
|
markManualLogout();
|
||||||
|
clearReadableAuthCookie();
|
||||||
clearToken();
|
clearToken();
|
||||||
closePaymentFlow();
|
closePaymentFlow();
|
||||||
closeEmailLoginCodeModal();
|
closeEmailLoginCodeModal();
|
||||||
startExternalAuth();
|
startExternalAuth();
|
||||||
|
try {
|
||||||
|
await publicApi('/auth/logout', {keepalive: true});
|
||||||
|
} catch (e) { }
|
||||||
}
|
}
|
||||||
|
|
||||||
function showLoader() {
|
function showLoader() {
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user