mirror of
https://github.com/multica-ai/multica.git
synced 2026-07-22 17:49:48 +02:00
* fix(auth): fall back to token-mode WS for users with legacy localStorage token Users who logged in before the cookie-auth migration still have multica_token in localStorage but no multica_auth cookie. Forcing cookieAuth=true for every session caused their WebSocket upgrade to 401 with only workspace_id in the URL. Detect the legacy token at boot and run that session in token mode (Bearer HTTP + URL-param WS). Pure cookie-mode is used only when no legacy token is present, so new users get the intended path and legacy users migrate naturally on their next logout/login cycle (logout already clears multica_token). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs(auth): note sunset plan for legacy-token WS fallback Make the XSS-exposure tradeoff explicit and give future maintainers a concrete signal (<1% of sessions) for when to delete the compat branch. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
39 lines
1.3 KiB
TypeScript
39 lines
1.3 KiB
TypeScript
"use client";
|
|
|
|
import { CoreProvider } from "@multica/core/platform";
|
|
import { WebNavigationProvider } from "@/platform/navigation";
|
|
import {
|
|
setLoggedInCookie,
|
|
clearLoggedInCookie,
|
|
} from "@/features/auth/auth-cookie";
|
|
|
|
// Legacy token in localStorage → keep this session in token mode so users who
|
|
// logged in before the cookie-auth migration stay authed. They migrate to
|
|
// cookie mode on their next logout/login cycle (logout clears multica_token).
|
|
// Sunset: once telemetry shows <1% of sessions still carry multica_token,
|
|
// delete this branch and hard-code `cookieAuth` — the localStorage token is
|
|
// XSS-exposed and is the exact thing the cookie migration exists to remove.
|
|
function hasLegacyToken(): boolean {
|
|
if (typeof window === "undefined") return false;
|
|
try {
|
|
return Boolean(window.localStorage.getItem("multica_token"));
|
|
} catch {
|
|
return false;
|
|
}
|
|
}
|
|
|
|
export function WebProviders({ children }: { children: React.ReactNode }) {
|
|
const cookieAuth = !hasLegacyToken();
|
|
return (
|
|
<CoreProvider
|
|
apiBaseUrl={process.env.NEXT_PUBLIC_API_URL}
|
|
wsUrl={process.env.NEXT_PUBLIC_WS_URL}
|
|
cookieAuth={cookieAuth}
|
|
onLogin={setLoggedInCookie}
|
|
onLogout={clearLoggedInCookie}
|
|
>
|
|
<WebNavigationProvider>{children}</WebNavigationProvider>
|
|
</CoreProvider>
|
|
);
|
|
}
|