OIDC-Integration: Keycloak-Login (Authorization Code Flow + PKCE), app-seitige Rollen bleiben unangetastet
This commit is contained in:
@@ -113,8 +113,9 @@ app.use(cookieParser());
|
||||
|
||||
// P4: CSRF protection for state-changing requests (Double-Submit-Cookie)
|
||||
// Skip CSRF check for login/register (no session yet, no CSRF token available)
|
||||
// and OIDC flow endpoints (GET-Redirects; der Flow selbst ist per State-Cookie geschützt)
|
||||
app.use('/api', (req, res, next) => {
|
||||
if (req.path.startsWith('/auth/login') || req.path.startsWith('/auth/register') || req.path.startsWith('/v1/auth/login') || req.path.startsWith('/v1/auth/register')) {
|
||||
if (req.path.startsWith('/auth/login') || req.path.startsWith('/auth/register') || req.path.startsWith('/v1/auth/login') || req.path.startsWith('/v1/auth/register') || req.path.startsWith('/auth/oidc/') || req.path.startsWith('/v1/auth/oidc/')) {
|
||||
return next();
|
||||
}
|
||||
csrfMiddleware(req, res, next);
|
||||
|
||||
Reference in New Issue
Block a user