mirror of
https://github.com/steveiliop56/tinyauth.git
synced 2025-11-07 01:25:43 +00:00
* wip * feat: make forms functional * feat: finalize pages * chore: remove unused translations * feat: app context * feat: user context * feat: finalize username login * fix: use correct tab order in login form * feat: add oauth logic * chore: update readme and assets * chore: rename docs back to assets * feat: favicons * feat: custom background image config option * chore: add acknowledgements for background image * feat: sanitize redirect URL * feat: sanitize redirect URL on check * chore: fix dependabot config * refactor: bot suggestions * fix: correctly redirect to app and check for untrusted redirects * fix: run oauth auto redirect only when there is a redirect URI * refactor: change select color * fix: fix dockerfiles * fix: fix hook rendering * chore: remove translations cdn * chore: formatting * feat: validate api response against zod schema * fix: use axios error instead of generic error in login page
133 lines
3.6 KiB
TypeScript
133 lines
3.6 KiB
TypeScript
import { Button } from "@/components/ui/button";
|
|
import {
|
|
Card,
|
|
CardDescription,
|
|
CardFooter,
|
|
CardHeader,
|
|
CardTitle,
|
|
} from "@/components/ui/card";
|
|
import { useAppContext } from "@/context/app-context";
|
|
import { useUserContext } from "@/context/user-context";
|
|
import { isValidUrl } from "@/lib/utils";
|
|
import { Trans, useTranslation } from "react-i18next";
|
|
import { Navigate, useLocation, useNavigate } from "react-router";
|
|
import DOMPurify from "dompurify";
|
|
|
|
export const ContinuePage = () => {
|
|
const { isLoggedIn } = useUserContext();
|
|
|
|
if (!isLoggedIn) {
|
|
return <Navigate to="/login" />;
|
|
}
|
|
|
|
const { domain, disableContinue } = useAppContext();
|
|
const { search } = useLocation();
|
|
|
|
const searchParams = new URLSearchParams(search);
|
|
const redirectURI = searchParams.get("redirect_uri");
|
|
|
|
if (!redirectURI) {
|
|
return <Navigate to="/logout" />;
|
|
}
|
|
|
|
if (!isValidUrl(DOMPurify.sanitize(redirectURI))) {
|
|
return <Navigate to="/logout" />;
|
|
}
|
|
|
|
if (disableContinue) {
|
|
window.location.href = DOMPurify.sanitize(redirectURI);
|
|
}
|
|
|
|
const { t } = useTranslation();
|
|
const navigate = useNavigate();
|
|
|
|
const url = new URL(redirectURI);
|
|
|
|
if (!(url.hostname == domain) && !url.hostname.endsWith(`.${domain}`)) {
|
|
return (
|
|
<Card className="min-w-xs sm:min-w-sm">
|
|
<CardHeader>
|
|
<CardTitle className="text-3xl">
|
|
{t("untrustedRedirectTitle")}
|
|
</CardTitle>
|
|
<CardDescription>
|
|
<Trans
|
|
i18nKey="untrustedRedirectSubtitle"
|
|
t={t}
|
|
components={{
|
|
code: <code />,
|
|
}}
|
|
values={{ domain }}
|
|
/>
|
|
</CardDescription>
|
|
</CardHeader>
|
|
<CardFooter className="flex flex-col items-stretch gap-2">
|
|
<Button
|
|
onClick={() =>
|
|
(window.location.href = DOMPurify.sanitize(redirectURI))
|
|
}
|
|
variant="destructive"
|
|
>
|
|
{t("continueTitle")}
|
|
</Button>
|
|
<Button onClick={() => navigate("/logout")} variant="outline">
|
|
{t("cancelTitle")}
|
|
</Button>
|
|
</CardFooter>
|
|
</Card>
|
|
);
|
|
}
|
|
|
|
if (url.protocol === "http:" && window.location.protocol === "https:") {
|
|
return (
|
|
<Card className="min-w-xs sm:min-w-sm">
|
|
<CardHeader>
|
|
<CardTitle className="text-3xl">
|
|
{t("continueInsecureRedirectTitle")}
|
|
</CardTitle>
|
|
<CardDescription>
|
|
<Trans
|
|
i18nKey="continueInsecureRedirectSubtitle"
|
|
t={t}
|
|
components={{
|
|
code: <code />,
|
|
}}
|
|
/>
|
|
</CardDescription>
|
|
</CardHeader>
|
|
<CardFooter className="flex flex-col items-stretch gap-2">
|
|
<Button
|
|
onClick={() =>
|
|
(window.location.href = DOMPurify.sanitize(redirectURI))
|
|
}
|
|
variant="warning"
|
|
>
|
|
{t("continueTitle")}
|
|
</Button>
|
|
<Button onClick={() => navigate("/logout")} variant="outline">
|
|
{t("cancelTitle")}
|
|
</Button>
|
|
</CardFooter>
|
|
</Card>
|
|
);
|
|
}
|
|
|
|
return (
|
|
<Card className="min-w-xs sm:min-w-sm">
|
|
<CardHeader>
|
|
<CardTitle className="text-3xl">{t("continueTitle")}</CardTitle>
|
|
<CardDescription>{t("continueSubtitle")}</CardDescription>
|
|
</CardHeader>
|
|
<CardFooter className="flex flex-col items-stretch">
|
|
<Button
|
|
onClick={() =>
|
|
(window.location.href = DOMPurify.sanitize(redirectURI))
|
|
}
|
|
>
|
|
{t("continueTitle")}
|
|
</Button>
|
|
</CardFooter>
|
|
</Card>
|
|
);
|
|
};
|