mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-04 19:07:56 +00:00
fix(oidc): session token vs gui token issues
This commit is contained in:
@@ -152,10 +152,11 @@ const TabSecurity = {
|
||||
const password_confirm_promise = new TeePromise();
|
||||
const try_password = async () => {
|
||||
const value = $win.find('.password-entry').val();
|
||||
// Do not send Authorization: user-protected endpoints use session cookie (hasHttpPowers)
|
||||
const resp = await fetch(`${window.api_origin}/user-protected/disable-2fa`, {
|
||||
method: 'POST',
|
||||
credentials: 'include',
|
||||
headers: {
|
||||
Authorization: `Bearer ${puter.authToken}`,
|
||||
'Content-Type': 'application/json',
|
||||
},
|
||||
body: JSON.stringify({
|
||||
|
||||
@@ -86,10 +86,11 @@ export default {
|
||||
const password_confirm_promise = new TeePromise();
|
||||
const try_password = async () => {
|
||||
const value = password_entry.get('value');
|
||||
// No Authorization header: user-protected endpoints use session cookie (hasHttpPowers)
|
||||
const resp = await fetch(`${window.api_origin}/user-protected/disable-2fa`, {
|
||||
method: 'POST',
|
||||
credentials: 'include',
|
||||
headers: {
|
||||
Authorization: `Bearer ${puter.authToken}`,
|
||||
'Content-Type': 'application/json',
|
||||
},
|
||||
body: JSON.stringify({
|
||||
|
||||
@@ -114,13 +114,12 @@ async function UIWindowChangePassword (options) {
|
||||
|
||||
$(el_window).find('.form-error-msg').hide();
|
||||
|
||||
// Do not send Authorization: user-protected endpoints use session cookie (hasHttpPowers)
|
||||
$.ajax({
|
||||
url: `${window.api_origin }/user-protected/change-password`,
|
||||
type: 'POST',
|
||||
async: true,
|
||||
headers: {
|
||||
'Authorization': `Bearer ${window.auth_token}`,
|
||||
},
|
||||
xhrFields: { withCredentials: true },
|
||||
contentType: 'application/json',
|
||||
data: JSON.stringify({
|
||||
password: current_password,
|
||||
|
||||
@@ -182,12 +182,12 @@ async function UIWindowChangeUsername (options) {
|
||||
const new_username = $(el_window).find('.new-username').val();
|
||||
const body = { new_username };
|
||||
if ( password !== undefined && password !== '' ) body.password = password;
|
||||
// Do not send Authorization: user-protected endpoints use session cookie (hasHttpPowers)
|
||||
return fetch(apiUrl, {
|
||||
method: 'POST',
|
||||
credentials: 'include',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
...(window.auth_token ? { 'Authorization': `Bearer ${window.auth_token}` } : {}),
|
||||
},
|
||||
body: JSON.stringify(body),
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user