Compare commits

...

1 Commits

Author SHA1 Message Date
calli f49cc61da4 up deps and improve login 2026-04-14 22:26:17 +03:00
8 changed files with 1148 additions and 1059 deletions
+1104 -1033
View File
File diff suppressed because it is too large Load Diff
+2 -2
View File
@@ -255,7 +255,7 @@ export const AccountCard = ({ characters, isCollapsed: propIsCollapsed }: { char
const newIds = ids.filter(id => !valid.includes(id)); const newIds = ids.filter(id => !valid.includes(id));
return [...valid, ...newIds]; return [...valid, ...newIds];
} }
} catch {} } catch (_) { /* ignore corrupt localStorage */ }
return characters.map(c => c.character.characterId); return characters.map(c => c.character.characterId);
}); });
@@ -278,7 +278,7 @@ export const AccountCard = ({ characters, isCollapsed: propIsCollapsed }: { char
try { try {
const saved = localStorage.getItem(`collapsedCharacters-${accountName}`); const saved = localStorage.getItem(`collapsedCharacters-${accountName}`);
if (saved) return new Set<number>(JSON.parse(saved)); if (saved) return new Set<number>(JSON.parse(saved));
} catch {} } catch (_) { /* ignore corrupt localStorage */ }
return new Set<number>(); return new Set<number>();
}); });
+4 -11
View File
@@ -19,7 +19,6 @@ export const LoginDialog = ({
DEFAULT_SCOPES_TO_SELECT DEFAULT_SCOPES_TO_SELECT
); );
const [ssoUrl, setSsoUrl] = useState<string | undefined>(undefined); const [ssoUrl, setSsoUrl] = useState<string | undefined>(undefined);
const [loginUrl, setLoginUrl] = useState<string | undefined>(undefined);
const { EVE_SSO_CLIENT_ID, EVE_SSO_CALLBACK_URL } = const { EVE_SSO_CLIENT_ID, EVE_SSO_CALLBACK_URL } =
useContext(SessionContext); useContext(SessionContext);
@@ -30,15 +29,6 @@ export const LoginDialog = ({
}); });
}, []); }, []);
useEffect(() => {
if (!ssoUrl || selectedScopes.length === 0) return;
loginParameters(
selectedScopes,
EVE_SSO_CLIENT_ID,
EVE_SSO_CALLBACK_URL
).then((res) => setLoginUrl(ssoUrl + "?" + res));
}, [selectedScopes, ssoUrl, EVE_SSO_CLIENT_ID, EVE_SSO_CALLBACK_URL]);
return ( return (
<Dialog open={open} onClose={closeDialog}> <Dialog open={open} onClose={closeDialog}>
<DialogTitle>Select scopes to login with</DialogTitle> <DialogTitle>Select scopes to login with</DialogTitle>
@@ -59,8 +49,11 @@ export const LoginDialog = ({
<DialogActions> <DialogActions>
<Button <Button
variant="contained" variant="contained"
disabled={!ssoUrl || selectedScopes.length === 0}
onClick={() => { onClick={() => {
window.open(loginUrl, "_self"); if (!ssoUrl) return;
const params = loginParameters(selectedScopes, EVE_SSO_CLIENT_ID, EVE_SSO_CALLBACK_URL);
window.open(ssoUrl + "?" + params, "_self");
}} }}
> >
Login Login
+12 -2
View File
@@ -3,7 +3,7 @@ import "@fontsource/roboto/300.css";
import "@fontsource/roboto/400.css"; import "@fontsource/roboto/400.css";
import "@fontsource/roboto/500.css"; import "@fontsource/roboto/500.css";
import "@fontsource/roboto/700.css"; import "@fontsource/roboto/700.css";
import { memo, useCallback, useEffect, useState, Suspense } from "react"; import { memo, useCallback, useEffect, useRef, useState, Suspense } from "react";
import { AccessToken, CharacterUpdate, Env, PlanetWithInfo } from "../types"; import { AccessToken, CharacterUpdate, Env, PlanetWithInfo } from "../types";
import { MainGrid } from "./components/MainGrid"; import { MainGrid } from "./components/MainGrid";
import { refreshToken } from "@/esi-sso"; import { refreshToken } from "@/esi-sso";
@@ -37,6 +37,7 @@ const processInBatches = async <T, R>(
const Home = () => { const Home = () => {
const searchParams = useSearchParams(); const searchParams = useSearchParams();
const callbackHandled = useRef(false);
const [characters, setCharacters] = useState<AccessToken[]>([]); const [characters, setCharacters] = useState<AccessToken[]>([]);
const [sessionReady, setSessionReady] = useState(false); const [sessionReady, setSessionReady] = useState(false);
const [environment, setEnvironment] = useState<Env | undefined>(undefined); const [environment, setEnvironment] = useState<Env | undefined>(undefined);
@@ -93,7 +94,16 @@ const Home = () => {
characters: AccessToken[], characters: AccessToken[],
): Promise<AccessToken[]> => { ): Promise<AccessToken[]> => {
const code = searchParams?.get("code"); const code = searchParams?.get("code");
if (code) { const returnedState = searchParams?.get("state");
if (code && !callbackHandled.current) {
callbackHandled.current = true;
const expectedState = localStorage.getItem("oauth_state");
localStorage.removeItem("oauth_state");
if (!expectedState || returnedState !== expectedState) {
console.error("OAuth state mismatch — possible CSRF attack");
window.history.replaceState(null, "", "/");
return Promise.resolve(characters);
}
window.history.replaceState(null, "", "/"); window.history.replaceState(null, "", "/");
const res = await fetch(`api/token?code=${code}`); const res = await fetch(`api/token?code=${code}`);
const newCharacter: AccessToken = await res.json(); const newCharacter: AccessToken = await res.json();
+4 -2
View File
@@ -37,17 +37,19 @@ export const revokeToken = async (
}); });
}; };
export const loginParameters = async ( export const loginParameters = (
selectedScopes: string[], selectedScopes: string[],
EVE_SSO_CLIENT_ID: string, EVE_SSO_CLIENT_ID: string,
EVE_SSO_CALLBACK_URL: string, EVE_SSO_CALLBACK_URL: string,
) => { ) => {
const state = crypto.randomUUID();
localStorage.setItem("oauth_state", state);
return new URLSearchParams({ return new URLSearchParams({
response_type: "code", response_type: "code",
redirect_uri: EVE_SSO_CALLBACK_URL, redirect_uri: EVE_SSO_CALLBACK_URL,
client_id: EVE_SSO_CLIENT_ID, client_id: EVE_SSO_CLIENT_ID,
scope: selectedScopes.join(" "), scope: selectedScopes.join(" "),
state: "asfe", state,
}).toString(); }).toString();
}; };
+18 -5
View File
@@ -9,11 +9,25 @@ const handler = async (req: NextApiRequest, res: NextApiResponse) => {
}); });
try { try {
const praisalRequest: { quantity: number; type_id: number }[] = JSON.parse( const parsed = JSON.parse(req.body);
req.body
if (!Array.isArray(parsed)) {
return res.status(400).json({ error: 'Invalid input' });
}
const praisalRequest: { quantity: number; type_id: number }[] = parsed.filter(
(item): item is { quantity: number; type_id: number } =>
item !== null &&
typeof item === 'object' &&
typeof item.quantity === 'number' &&
Number.isFinite(item.quantity) &&
item.quantity >= 0 &&
typeof item.type_id === 'number' &&
Number.isInteger(item.type_id) &&
item.type_id > 0
); );
logger.info({ logger.info({
event: 'praisal_request_parsed', event: 'praisal_request_parsed',
items: praisalRequest.length items: praisalRequest.length
}); });
@@ -27,10 +41,9 @@ const handler = async (req: NextApiRequest, res: NextApiResponse) => {
return res.json(praisal); return res.json(praisal);
} catch (e) { } catch (e) {
logger.error({ logger.error({
event: 'praisal_request_failed', event: 'praisal_request_failed',
error: e, error: e,
body: req.body
}); });
return res.status(500).json({ error: 'Failed to get praisal' }); return res.status(500).json({ error: 'Failed to get praisal' });
} }
+2 -4
View File
@@ -20,9 +20,8 @@ const handler = async (req: NextApiRequest, res: NextApiResponse) => {
return res.status(404).end(); return res.status(404).end();
} }
logger.info({ logger.info({
event: 'token_request_start', event: 'token_request_start',
code: code
}); });
const params = new URLSearchParams({ const params = new URLSearchParams({
@@ -88,11 +87,10 @@ const handler = async (req: NextApiRequest, res: NextApiResponse) => {
}; };
return res.json(token); return res.json(token);
} catch (e) { } catch (e) {
logger.error({ logger.error({
event: 'token_request_failed', event: 'token_request_failed',
reason: 'api_error', reason: 'api_error',
error: e, error: e,
code: code
}); });
return res.status(500).end(); return res.status(500).end();
} }
+2
View File
@@ -31,6 +31,7 @@ const CACHE_DURATION_MS = 60_000; // 1 minute
const CACHE_STORAGE_KEY = "planet_cache"; const CACHE_STORAGE_KEY = "planet_cache";
const loadCacheFromStorage = (): Map<string, CachedPlanetData> => { const loadCacheFromStorage = (): Map<string, CachedPlanetData> => {
if (typeof window === "undefined") return new Map();
try { try {
const stored = localStorage.getItem(CACHE_STORAGE_KEY); const stored = localStorage.getItem(CACHE_STORAGE_KEY);
if (stored) { if (stored) {
@@ -44,6 +45,7 @@ const loadCacheFromStorage = (): Map<string, CachedPlanetData> => {
}; };
const saveCacheToStorage = (cache: Map<string, CachedPlanetData>) => { const saveCacheToStorage = (cache: Map<string, CachedPlanetData>) => {
if (typeof window === "undefined") return;
try { try {
const obj = Object.fromEntries(cache); const obj = Object.fromEntries(cache);
localStorage.setItem(CACHE_STORAGE_KEY, JSON.stringify(obj)); localStorage.setItem(CACHE_STORAGE_KEY, JSON.stringify(obj));