WIP - BFF
This commit is contained in:
75
frontend/server/utils/session.ts
Normal file
75
frontend/server/utils/session.ts
Normal file
@@ -0,0 +1,75 @@
|
||||
import type { H3Event } from 'h3'
|
||||
import { getCookie, setCookie, deleteCookie } from 'h3'
|
||||
|
||||
const SESSION_COOKIE_NAME = 'routebox_session'
|
||||
const SESSION_MAX_AGE = 60 * 60 * 24 * 7 // 7 days
|
||||
|
||||
export interface SessionData {
|
||||
token: string
|
||||
tenantId: string
|
||||
userId: string
|
||||
email: string
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the session token from HTTP-only cookie
|
||||
*/
|
||||
export function getSessionToken(event: H3Event): string | null {
|
||||
return getCookie(event, SESSION_COOKIE_NAME) || null
|
||||
}
|
||||
|
||||
/**
|
||||
* Set the session token in an HTTP-only cookie
|
||||
*/
|
||||
export function setSessionCookie(event: H3Event, token: string): void {
|
||||
const isProduction = process.env.NODE_ENV === 'production'
|
||||
|
||||
setCookie(event, SESSION_COOKIE_NAME, token, {
|
||||
httpOnly: true,
|
||||
secure: isProduction,
|
||||
sameSite: 'lax',
|
||||
maxAge: SESSION_MAX_AGE,
|
||||
path: '/',
|
||||
})
|
||||
}
|
||||
|
||||
/**
|
||||
* Clear the session cookie
|
||||
*/
|
||||
export function clearSessionCookie(event: H3Event): void {
|
||||
deleteCookie(event, SESSION_COOKIE_NAME, {
|
||||
path: '/',
|
||||
})
|
||||
}
|
||||
|
||||
/**
|
||||
* Get tenant ID from a separate cookie (for SSR access)
|
||||
* This is NOT the auth token - just tenant context
|
||||
*/
|
||||
export function getTenantIdFromCookie(event: H3Event): string | null {
|
||||
return getCookie(event, 'routebox_tenant') || null
|
||||
}
|
||||
|
||||
/**
|
||||
* Set tenant ID cookie (readable by client for context)
|
||||
*/
|
||||
export function setTenantIdCookie(event: H3Event, tenantId: string): void {
|
||||
const isProduction = process.env.NODE_ENV === 'production'
|
||||
|
||||
setCookie(event, 'routebox_tenant', tenantId, {
|
||||
httpOnly: false, // Allow client to read tenant context
|
||||
secure: isProduction,
|
||||
sameSite: 'lax',
|
||||
maxAge: SESSION_MAX_AGE,
|
||||
path: '/',
|
||||
})
|
||||
}
|
||||
|
||||
/**
|
||||
* Clear tenant ID cookie
|
||||
*/
|
||||
export function clearTenantIdCookie(event: H3Event): void {
|
||||
deleteCookie(event, 'routebox_tenant', {
|
||||
path: '/',
|
||||
})
|
||||
}
|
||||
39
frontend/server/utils/tenant.ts
Normal file
39
frontend/server/utils/tenant.ts
Normal file
@@ -0,0 +1,39 @@
|
||||
import type { H3Event } from 'h3'
|
||||
import { getHeader } from 'h3'
|
||||
|
||||
/**
|
||||
* Extract subdomain from the request Host header
|
||||
* Handles production domains (tenant1.routebox.co) and development (tenant1.localhost)
|
||||
*/
|
||||
export function getSubdomainFromRequest(event: H3Event): string | null {
|
||||
const host = getHeader(event, 'host') || ''
|
||||
const hostname = host.split(':')[0] // Remove port if present
|
||||
|
||||
const parts = hostname.split('.')
|
||||
|
||||
// For production domains with 3+ parts (e.g., tenant1.routebox.co)
|
||||
if (parts.length >= 3) {
|
||||
const subdomain = parts[0]
|
||||
// Ignore www subdomain
|
||||
if (subdomain === 'www') {
|
||||
return null
|
||||
}
|
||||
return subdomain
|
||||
}
|
||||
|
||||
// For development (e.g., tenant1.localhost)
|
||||
if (parts.length === 2 && parts[1] === 'localhost') {
|
||||
return parts[0]
|
||||
}
|
||||
|
||||
return null
|
||||
}
|
||||
|
||||
/**
|
||||
* Check if the subdomain is a central/admin subdomain
|
||||
*/
|
||||
export function isCentralSubdomain(subdomain: string | null): boolean {
|
||||
if (!subdomain) return false
|
||||
const centralSubdomains = (process.env.CENTRAL_SUBDOMAINS || 'central,admin').split(',')
|
||||
return centralSubdomains.includes(subdomain)
|
||||
}
|
||||
Reference in New Issue
Block a user