Skip to content

Commit

Permalink
fix: access token was using encoded refresh token instead of refresh …
Browse files Browse the repository at this point in the history
…token id
  • Loading branch information
clostao committed Nov 25, 2024
1 parent ed1a107 commit e61a390
Showing 1 changed file with 10 additions and 3 deletions.
13 changes: 10 additions & 3 deletions backend/src/services/authManager/providers/custom.ts
Original file line number Diff line number Diff line change
Expand Up @@ -57,9 +57,16 @@ const createRefreshToken = async (user: OAuthUser) => {
})
}

const getIdFromRefreshToken = (refreshToken: string) => {
const decoded = jwt.decode(refreshToken) as CustomRefreshTokenPayload
return decoded.id
}

const createSessionTokens = async (user: OAuthUser) => {
const refreshToken = await createRefreshToken(user)
const accessToken = createAccessToken(user, refreshToken)
const refreshTokenId = getIdFromRefreshToken(refreshToken)

const accessToken = createAccessToken(user, refreshTokenId)

return { accessToken, refreshToken }
}
Expand Down Expand Up @@ -91,13 +98,13 @@ const getUserFromRefreshToken = async (
}
}

const refreshAccessToken = async (refreshToken: string) => {
const refreshAccessToken = async (refreshToken: string): Promise<string> => {
const decoded = jwt.verify(
refreshToken,
JWT_SECRET,
) as CustomRefreshTokenPayload
if (typeof decoded === 'string') {
return null
throw new Error('Invalid refresh token')
}

const user = await getUserFromRefreshToken(refreshToken)
Expand Down

0 comments on commit e61a390

Please sign in to comment.