Auto-inlog opent in nieuw tabblad via GET route
Vervangt server action door /api/auto-login GET route zodat <a target="_blank"> werkt. Server action verwijderd. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,28 @@
|
|||||||
|
import { NextRequest, NextResponse } from "next/server";
|
||||||
|
import { createHmac } from "crypto";
|
||||||
|
import { getSession } from "../../../lib/auth";
|
||||||
|
import { getPlatformDb } from "../../../lib/platform-db";
|
||||||
|
|
||||||
|
export async function GET(request: NextRequest) {
|
||||||
|
const session = await getSession();
|
||||||
|
if (!session) return NextResponse.redirect(new URL("/login", request.url));
|
||||||
|
|
||||||
|
const accountId = Number(request.nextUrl.searchParams.get("account_id"));
|
||||||
|
const slug = request.nextUrl.searchParams.get("slug");
|
||||||
|
if (!accountId || !slug) return NextResponse.redirect(new URL("/tenants", request.url));
|
||||||
|
|
||||||
|
const db = getPlatformDb();
|
||||||
|
const user = db
|
||||||
|
.prepare("SELECT id FROM users WHERE account_id = ? AND role = 'admin' LIMIT 1")
|
||||||
|
.get(accountId) as { id: number } | undefined;
|
||||||
|
|
||||||
|
if (!user) return NextResponse.redirect(new URL("/tenants?error=no-admin", request.url));
|
||||||
|
|
||||||
|
const secret = process.env.AUTO_LOGIN_SECRET!;
|
||||||
|
const expires = Date.now() + 60_000;
|
||||||
|
const payload = `${user.id}:${accountId}:${expires}`;
|
||||||
|
const sig = createHmac("sha256", secret).update(payload).digest("hex");
|
||||||
|
const token = encodeURIComponent(`${payload}:${sig}`);
|
||||||
|
|
||||||
|
return NextResponse.redirect(`https://${slug}.rikxplatform.nl/auto-login?token=${token}`);
|
||||||
|
}
|
||||||
+8
-11
@@ -3,7 +3,6 @@ import { getSession } from "../../lib/auth";
|
|||||||
import { listAccounts } from "../../lib/platform-db";
|
import { listAccounts } from "../../lib/platform-db";
|
||||||
import { createTenant, deleteTenant } from "./actions";
|
import { createTenant, deleteTenant } from "./actions";
|
||||||
import { logout } from "./logout";
|
import { logout } from "./logout";
|
||||||
import { autoLogin } from "./auto-login";
|
|
||||||
|
|
||||||
export default async function TenantsPage({
|
export default async function TenantsPage({
|
||||||
searchParams,
|
searchParams,
|
||||||
@@ -80,16 +79,14 @@ export default async function TenantsPage({
|
|||||||
{new Date(a.created_at).toLocaleDateString("nl-NL")}
|
{new Date(a.created_at).toLocaleDateString("nl-NL")}
|
||||||
</td>
|
</td>
|
||||||
<td className="px-4 py-3 text-right">
|
<td className="px-4 py-3 text-right">
|
||||||
<form action={autoLogin}>
|
<a
|
||||||
<input type="hidden" name="account_id" value={a.id} />
|
href={`/api/auto-login?account_id=${a.id}&slug=${a.slug}`}
|
||||||
<input type="hidden" name="slug" value={a.slug} />
|
target="_blank"
|
||||||
<button
|
rel="noopener noreferrer"
|
||||||
type="submit"
|
className="text-xs text-blue-600 hover:text-blue-800 dark:text-blue-400 dark:hover:text-blue-300 transition-colors"
|
||||||
className="text-xs text-blue-600 hover:text-blue-800 dark:text-blue-400 dark:hover:text-blue-300 transition-colors"
|
>
|
||||||
>
|
Inloggen ↗
|
||||||
Inloggen
|
</a>
|
||||||
</button>
|
|
||||||
</form>
|
|
||||||
</td>
|
</td>
|
||||||
<td className="px-4 py-3 text-right">
|
<td className="px-4 py-3 text-right">
|
||||||
<form action={deleteTenant}>
|
<form action={deleteTenant}>
|
||||||
|
|||||||
Reference in New Issue
Block a user