refactor: don't store oauth token in cookie

This commit is contained in:
Stavros
2025-01-26 11:05:11 +02:00
parent 389248cfe1
commit 682a918812
2 changed files with 4 additions and 20 deletions

View File

@@ -291,7 +291,7 @@ func (api *API) SetupRoutes() {
return
}
token, tokenErr := provider.ExchangeToken(code)
_, tokenErr := provider.ExchangeToken(code)
if handleApiError(c, "Failed to exchange token", tokenErr) {
return
@@ -315,7 +315,7 @@ func (api *API) SetupRoutes() {
}
session := sessions.Default(c)
session.Set("tinyauth_sid", fmt.Sprintf("%s:%s", providerName.Provider, token))
session.Set("tinyauth_sid", fmt.Sprintf("%s:%s", providerName.Provider, email))
session.Save()
redirectURI, redirectURIErr := c.Cookie("tinyauth_redirect_uri")