Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d292bc4b3c | ||
|
|
787acf077f | ||
|
|
250355562f | ||
|
|
d47c73308e | ||
|
|
4b1d70d1c4 |
@@ -179,6 +179,9 @@ jobs:
|
|||||||
SESSION_SECRET=${{ secrets.SESSION_SECRET }}
|
SESSION_SECRET=${{ secrets.SESSION_SECRET }}
|
||||||
WEB_APP_URL=https://zeavisedu.asepharyana.my.id
|
WEB_APP_URL=https://zeavisedu.asepharyana.my.id
|
||||||
ML_SERVICE_URL=http://zeavis-ml:8000
|
ML_SERVICE_URL=http://zeavis-ml:8000
|
||||||
|
GOOGLE_CLIENT_ID=${{ secrets.GOOGLE_CLIENT_ID }}
|
||||||
|
GOOGLE_CLIENT_SECRET=${{ secrets.GOOGLE_CLIENT_SECRET }}
|
||||||
|
GOOGLE_REDIRECT_URI=https://zeavisedu.asepharyana.my.id/api/v1/auth/google/callback
|
||||||
ENVEOF
|
ENVEOF
|
||||||
} > .env
|
} > .env
|
||||||
|
|
||||||
|
|||||||
@@ -186,7 +186,8 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
prompt: 'select_account',
|
prompt: 'select_account',
|
||||||
});
|
});
|
||||||
|
|
||||||
set.redirect = `https://accounts.google.com/o/oauth2/v2/auth?${params.toString()}`;
|
set.status = 302;
|
||||||
|
set.headers['Location'] = `https://accounts.google.com/o/oauth2/v2/auth?${params.toString()}`;
|
||||||
})
|
})
|
||||||
.get('/google/callback', async ({ query, set, request }) => {
|
.get('/google/callback', async ({ query, set, request }) => {
|
||||||
if (!env.googleOAuthEnabled) {
|
if (!env.googleOAuthEnabled) {
|
||||||
@@ -199,7 +200,8 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
|
|
||||||
// User denied or Google returned an error
|
// User denied or Google returned an error
|
||||||
if (error || !code) {
|
if (error || !code) {
|
||||||
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent(error ?? 'missing_code')}`;
|
set.status = 302;
|
||||||
|
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent(error ?? 'missing_code')}`;
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -210,13 +212,15 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
idPayload = decodeGoogleIdToken(tokens.id_token);
|
idPayload = decodeGoogleIdToken(tokens.id_token);
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
const msg = err instanceof Error ? err.message : 'Google auth failed';
|
const msg = err instanceof Error ? err.message : 'Google auth failed';
|
||||||
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent(msg)}`;
|
set.status = 302;
|
||||||
|
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent(msg)}`;
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Validate email
|
// Validate email
|
||||||
if (!idPayload.email_verified || !idPayload.email) {
|
if (!idPayload.email_verified || !idPayload.email) {
|
||||||
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent('Email not verified by Google')}`;
|
set.status = 302;
|
||||||
|
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent('Email not verified by Google')}`;
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -256,8 +260,10 @@ export const authRoutes = new Elysia({ prefix: '/api/v1/auth' })
|
|||||||
authCounter.labels('login', 'true').inc();
|
authCounter.labels('login', 'true').inc();
|
||||||
|
|
||||||
// Redirect to web app with token in URL for localStorage fallback
|
// Redirect to web app with token in URL for localStorage fallback
|
||||||
set.redirect = `${env.webAppUrl}/login?token=${encodeURIComponent(token)}`;
|
set.status = 302;
|
||||||
|
set.headers['Location'] = `${env.webAppUrl}/login?token=${encodeURIComponent(token)}`;
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
set.redirect = `${env.webAppUrl}/login?error=${encodeURIComponent('Database unavailable')}`;
|
set.status = 302;
|
||||||
|
set.headers['Location'] = `${env.webAppUrl}/login?error=${encodeURIComponent('Database unavailable')}`;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -75,8 +75,17 @@ export function AuthForm({ mode, isSubmitting, error, googleOAuthEnabled, onSubm
|
|||||||
</Button>
|
</Button>
|
||||||
</form>
|
</form>
|
||||||
{googleOAuthEnabled && (
|
{googleOAuthEnabled && (
|
||||||
<Button className="mt-3 w-full" variant="outline" asChild>
|
<Button className="mt-3 w-full flex items-center justify-center gap-2.5" variant="outline" asChild>
|
||||||
<a href="/api/v1/auth/google">Masuk dengan Google</a>
|
<a href="/api/v1/auth/google">
|
||||||
|
<svg viewBox="0 0 24 24" className="h-5 w-5" aria-hidden="true">
|
||||||
|
<path fill="#4285F4" d="M22.56 12.25c0-.78-.07-1.53-.2-2.25H12v4.26h5.92a5.06 5.06 0 0 1-2.2 3.32v2.77h3.57c2.08-1.92 3.28-4.74 3.28-8.1z" />
|
||||||
|
<path fill="#34A853" d="M12 23c2.97 0 5.46-.98 7.28-2.66l-3.57-2.77c-.98.66-2.23 1.06-3.71 1.06-2.86 0-5.29-1.93-6.16-4.53H2.18v2.84C3.99 20.53 7.7 23 12 23z" />
|
||||||
|
<path fill="#FBBC05" d="M5.84 14.09c-.22-.66-.35-1.36-.35-2.09s.13-1.43.35-2.09V7.07H2.18C1.43 8.55 1 10.22 1 12s.43 3.45 1.18 4.93l2.85-2.22.81-.62z" />
|
||||||
|
<path fill="#EA4335" d="M12 5.38c1.62 0 3.06.56 4.21 1.64l3.15-3.15C17.45 2.09 14.97 1 12 1 7.7 1 3.99 3.47 2.18 7.07l3.66 2.84c.87-2.6 3.3-4.53 6.16-4.53z" />
|
||||||
|
<path fill="none" d="M1 1h22v22H1z" />
|
||||||
|
</svg>
|
||||||
|
Masuk dengan Google
|
||||||
|
</a>
|
||||||
</Button>
|
</Button>
|
||||||
)}
|
)}
|
||||||
</CardContent>
|
</CardContent>
|
||||||
|
|||||||
@@ -1,23 +1,28 @@
|
|||||||
import { useState, useEffect, useRef } from "react";
|
import { useState, useEffect, useRef } from "react";
|
||||||
import { Link, useNavigate, useSearchParams } from "react-router-dom";
|
import { Link, useNavigate } from "react-router-dom";
|
||||||
import { useMutation, useQuery, useQueryClient } from "@tanstack/react-query";
|
import { useMutation, useQuery, useQueryClient } from "@tanstack/react-query";
|
||||||
import { AuthForm } from "@/components/auth-form";
|
import { AuthForm } from "@/components/auth-form";
|
||||||
import { apiClient, setAuthToken } from "@/lib/api-client";
|
import { apiClient, setAuthToken } from "@/lib/api-client";
|
||||||
import { useAuthStore } from "@/store/auth-store";
|
import { useAuthStore } from "@/store/auth-store";
|
||||||
|
|
||||||
|
function getUrlParam(name: string): string | null {
|
||||||
|
return new URLSearchParams(window.location.search).get(name);
|
||||||
|
}
|
||||||
|
|
||||||
export function LoginPage() {
|
export function LoginPage() {
|
||||||
const navigate = useNavigate();
|
const navigate = useNavigate();
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
const setUser = useAuthStore((state) => state.setUser);
|
const setUser = useAuthStore((state) => state.setUser);
|
||||||
const [error, setError] = useState<string | null>(null);
|
const [error, setError] = useState<string | null>(null);
|
||||||
const [searchParams] = useSearchParams();
|
|
||||||
const oauthTokenConsumed = useRef(false);
|
const oauthTokenConsumed = useRef(false);
|
||||||
|
const [oauthProcessing, setOauthProcessing] = useState(false);
|
||||||
|
|
||||||
// Handle OAuth callback: the API redirects to /login?token=<session_token>
|
// Handle OAuth callback: the API redirects to /login?token=<session_token>
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
const token = searchParams.get("token");
|
const token = getUrlParam("token");
|
||||||
if (!token || oauthTokenConsumed.current) return;
|
if (!token || oauthTokenConsumed.current) return;
|
||||||
oauthTokenConsumed.current = true;
|
oauthTokenConsumed.current = true;
|
||||||
|
setOauthProcessing(true);
|
||||||
|
|
||||||
// Store token for future API calls and fetch user
|
// Store token for future API calls and fetch user
|
||||||
setAuthToken(token);
|
setAuthToken(token);
|
||||||
@@ -31,12 +36,13 @@ export function LoginPage() {
|
|||||||
})
|
})
|
||||||
.catch((err) => {
|
.catch((err) => {
|
||||||
setAuthToken(null);
|
setAuthToken(null);
|
||||||
|
setOauthProcessing(false);
|
||||||
setError(err instanceof Error ? err.message : "Google login gagal");
|
setError(err instanceof Error ? err.message : "Google login gagal");
|
||||||
});
|
});
|
||||||
}, [searchParams, setUser, queryClient, navigate]);
|
}, [setUser, queryClient, navigate]);
|
||||||
|
|
||||||
// Show OAuth error from query param
|
// Show OAuth error from query param
|
||||||
const oauthError = searchParams.get("error");
|
const oauthError = getUrlParam("error");
|
||||||
const meQuery = useQuery({
|
const meQuery = useQuery({
|
||||||
queryKey: ["auth", "me"],
|
queryKey: ["auth", "me"],
|
||||||
queryFn: () => apiClient.getMe(),
|
queryFn: () => apiClient.getMe(),
|
||||||
@@ -53,6 +59,18 @@ export function LoginPage() {
|
|||||||
setError(err instanceof Error ? err.message : "Login gagal"),
|
setError(err instanceof Error ? err.message : "Login gagal"),
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Show loading spinner while OAuth token is being processed
|
||||||
|
if (oauthProcessing) {
|
||||||
|
return (
|
||||||
|
<main className="flex min-h-screen items-center justify-center px-6 py-12">
|
||||||
|
<div className="flex flex-col items-center gap-3">
|
||||||
|
<div className="h-10 w-10 border-4 border-green-500 border-t-transparent rounded-full animate-spin" />
|
||||||
|
<p className="text-gray-500 text-sm">Menyelesaikan login dengan Google...</p>
|
||||||
|
</div>
|
||||||
|
</main>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<main className="flex min-h-screen items-center justify-center px-6 py-12">
|
<main className="flex min-h-screen items-center justify-center px-6 py-12">
|
||||||
<div className="w-full max-w-sm md:max-w-md space-y-4">
|
<div className="w-full max-w-sm md:max-w-md space-y-4">
|
||||||
|
|||||||
+16
-1
@@ -9,7 +9,22 @@ export default defineConfig(({ mode }) => {
|
|||||||
const apiProxyTarget = env.VITE_API_PROXY_TARGET || 'http://localhost:3000';
|
const apiProxyTarget = env.VITE_API_PROXY_TARGET || 'http://localhost:3000';
|
||||||
|
|
||||||
return {
|
return {
|
||||||
plugins: [react(), tsconfigPaths(), metricsPlugin()],
|
plugins: [
|
||||||
|
react(),
|
||||||
|
tsconfigPaths(),
|
||||||
|
metricsPlugin(),
|
||||||
|
{
|
||||||
|
name: 'cloudflare-rocket-loader-fix',
|
||||||
|
transformIndexHtml(html) {
|
||||||
|
// Prevent Cloudflare Rocket Loader from mangling <script type="module">
|
||||||
|
// which breaks the entire JS bundle (blank page)
|
||||||
|
return html.replace(
|
||||||
|
/<script type="module"/g,
|
||||||
|
'<script data-cfasync="false" type="module"',
|
||||||
|
);
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
server: {
|
server: {
|
||||||
proxy: {
|
proxy: {
|
||||||
'/api': apiProxyTarget,
|
'/api': apiProxyTarget,
|
||||||
|
|||||||
Reference in New Issue
Block a user