Harden cookie authentication

This commit is contained in:
lucast committed 2026-09-29 15:57:07 +02:00
1 parent a0a62c1c06
commit 31e6c0c5d2
5 files changed
+116 -17

No files matched your search

+7 -2
View File
@@ -1,10 +1,15 @@
import { readBody, setCookie, setResponseStatus } from "h3"
import argon2 from "argon2"
import { User } from "../../models/user"
import { REFRESH_COOKIE } from "../../utils/auth"
import {
assertCookieRequestOrigin,
defineAuthenticatedEventHandler,
REFRESH_COOKIE,
} from "../../utils/auth"
import { getAuthValidationMessage } from "../../utils/auth-validation"
export default defineEventHandler(async (event) => {
export default defineAuthenticatedEventHandler(async (event) => {
assertCookieRequestOrigin(event)
const body = await readBody(event)
const validationMessage = getAuthValidationMessage(body, [
{ name: "name" },