Initial commit: Kalendartool (Next.js, Prisma, Docker)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
55
app/auth/hub/route.ts
Normal file
55
app/auth/hub/route.ts
Normal file
@@ -0,0 +1,55 @@
|
||||
/**
|
||||
* GET /auth/hub?token=... – SSO-Einstiegspunkt der MultiToolApp-Plattform.
|
||||
*
|
||||
* Ablauf (platform-plan.md §5.2):
|
||||
* 1. Hub-Token validieren (RS256 via JWKS vom Hub, aud = HUB_TOOL_SLUG)
|
||||
* 2. JIT-Provisioning (Account an hubId koppeln oder anlegen)
|
||||
* 3. Eigene Session setzen (bewährtes calendar_session-Cookie)
|
||||
* 4. Redirect auf das Kalender-Dashboard
|
||||
*
|
||||
* Fehler → Redirect auf /login mit ?hubError=... (keine Details im Query,
|
||||
* nur grober Code; Details stehen im Server-Log).
|
||||
*/
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { verifyHubToken } from "@/lib/auth/hub";
|
||||
import { provisionHubUser } from "@/lib/auth/hub-provisioning";
|
||||
import { createSessionToken, setSessionCookie } from "@/lib/auth/session";
|
||||
|
||||
/** basePath der App (Proxy-Modus) – Redirect-Ziele müssen darunter liegen. */
|
||||
function getBasePath(): string {
|
||||
return (process.env.HUB_BASE_PATH ?? "").replace(/\/$/, "");
|
||||
}
|
||||
|
||||
export async function GET(request: NextRequest) {
|
||||
const basePath = getBasePath();
|
||||
const loginUrl = new URL(`${basePath}/login`, request.url);
|
||||
|
||||
try {
|
||||
const token = request.nextUrl.searchParams.get("token");
|
||||
if (!token) {
|
||||
loginUrl.searchParams.set("hubError", "missing_token");
|
||||
return NextResponse.redirect(loginUrl);
|
||||
}
|
||||
|
||||
// 1. Token validieren (Signatur/TTL/aud/iss)
|
||||
const identity = await verifyHubToken(token);
|
||||
|
||||
// 2. JIT-Provisioning
|
||||
const user = await provisionHubUser(identity);
|
||||
|
||||
// 3. Eigene Session setzen
|
||||
const sessionToken = await createSessionToken({
|
||||
id: user.id,
|
||||
email: user.email,
|
||||
role: user.role,
|
||||
});
|
||||
await setSessionCookie(sessionToken);
|
||||
|
||||
// 4. Weiter ins Tool (basePath-kompatibel)
|
||||
return NextResponse.redirect(new URL(`${basePath}/`, request.url));
|
||||
} catch (error) {
|
||||
console.error("Hub-SSO fehlgeschlagen:", error);
|
||||
loginUrl.searchParams.set("hubError", "invalid_token");
|
||||
return NextResponse.redirect(loginUrl);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user