mirror of
https://github.com/fosrl/pangolin.git
synced 2026-07-30 09:15:19 +02:00
fix: redirect to /auth/initial-setup after hitting auth rate limit (#3408)
This commit is contained in:
@@ -1338,6 +1338,12 @@ authenticated.get("/ws/round-trip-message/:messageId", checkRoundTripMessage);
|
|||||||
// Auth routes
|
// Auth routes
|
||||||
export const authRouter = Router();
|
export const authRouter = Router();
|
||||||
unauthenticated.use("/auth", authRouter);
|
unauthenticated.use("/auth", authRouter);
|
||||||
|
|
||||||
|
// Register setup-check BEFORE the global auth rate limiter.
|
||||||
|
// This endpoint is called on every dashboard root page load (pure boolean
|
||||||
|
// read, no secrets) and must not consume the auth rate-limit budget.
|
||||||
|
authRouter.get("/initial-setup-complete", auth.initialSetupComplete);
|
||||||
|
|
||||||
authRouter.use(
|
authRouter.use(
|
||||||
rateLimit({
|
rateLimit({
|
||||||
windowMs:
|
windowMs:
|
||||||
@@ -1642,7 +1648,6 @@ authRouter.post("/idp/:idpId/oidc/generate-url", idp.generateOidcUrl);
|
|||||||
authRouter.post("/idp/:idpId/oidc/validate-callback", idp.validateOidcCallback);
|
authRouter.post("/idp/:idpId/oidc/validate-callback", idp.validateOidcCallback);
|
||||||
|
|
||||||
authRouter.put("/set-server-admin", auth.setServerAdmin);
|
authRouter.put("/set-server-admin", auth.setServerAdmin);
|
||||||
authRouter.get("/initial-setup-complete", auth.initialSetupComplete);
|
|
||||||
authRouter.post("/validate-setup-token", auth.validateSetupToken);
|
authRouter.post("/validate-setup-token", auth.validateSetupToken);
|
||||||
|
|
||||||
// Security Key routes
|
// Security Key routes
|
||||||
|
|||||||
+8
-3
@@ -30,14 +30,19 @@ export default async function Page(props: {
|
|||||||
const getUser = cache(verifySession);
|
const getUser = cache(verifySession);
|
||||||
const user = await getUser({ skipCheckVerifyEmail: true });
|
const user = await getUser({ skipCheckVerifyEmail: true });
|
||||||
|
|
||||||
let complete = false;
|
let complete: boolean | null = null; // null means "unknown" (request errored)
|
||||||
try {
|
try {
|
||||||
const setupRes = await internal.get<
|
const setupRes = await internal.get<
|
||||||
AxiosResponse<InitialSetupCompleteResponse>
|
AxiosResponse<InitialSetupCompleteResponse>
|
||||||
>(`/auth/initial-setup-complete`, await authCookieHeader());
|
>(`/auth/initial-setup-complete`, await authCookieHeader());
|
||||||
complete = setupRes.data.data.complete;
|
complete = setupRes.data.data.complete;
|
||||||
} catch (e) {}
|
} catch (e) {
|
||||||
if (!complete) {
|
// Swallow errors (e.g. 429 rate limit, 500, network failure).
|
||||||
|
// Only redirect to initial-setup when the server *confirms* setup
|
||||||
|
// is incomplete (complete === false). If the request itself failed we
|
||||||
|
// cannot tell, so fall through to the login redirect instead.
|
||||||
|
}
|
||||||
|
if (complete === false) {
|
||||||
redirect("/auth/initial-setup");
|
redirect("/auth/initial-setup");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user