chore: Move token from params to headers (#11281)

* chore: Move token from params to body

* chore: Add type

* wip

* chore: clean up

* clean ip
This commit is contained in:
Oli Juhl
2025-02-26 17:41:16 +01:00
committed by GitHub
parent 4ec5219a72
commit 54a6ef91ac
7 changed files with 96 additions and 75 deletions
@@ -15,15 +15,15 @@ import { emitEventStep, useRemoteQueryStep } from "../../common"
* [Generate Reset Password Token for Admin](https://docs.medusajs.com/api/admin#auth_postactor_typeauth_providerresetpassword)
* and [Generate Reset Password Token for Customer](https://docs.medusajs.com/api/store#auth_postactor_typeauth_providerresetpassword)
* API Routes.
*
*
* The workflow emits the `auth.password_reset` event, which you can listen to in
* a [subscriber](https://docs.medusajs.com/learn/fundamentals/events-and-subscribers). Follow
* [this guide](https://docs.medusajs.com/resources/commerce-modules/auth/reset-password) to learn
* how to handle this event.
*
*
* You can use this workflow within your customizations or your own custom workflows, allowing you to
* generate reset password tokens within your custom flows.
*
*
* @example
* const { result } = await generateResetPasswordTokenWorkflow(container)
* .run({
@@ -34,9 +34,9 @@ import { emitEventStep, useRemoteQueryStep } from "../../common"
* secret: "jwt_123" // jwt secret
* }
* })
*
*
* @summary
*
*
* Generate a reset password token for a user or customer.
*/
export const generateResetPasswordTokenWorkflow = createWorkflow(
@@ -90,11 +90,6 @@ export const generateResetPasswordTokenWorkflow = createWorkflow(
eventName: AuthWorkflowEvents.PASSWORD_RESET,
data: {
entity_id: input.entityId,
/**
* Use `actor_type` instead. Will be removed in a future version.
* @deprecated
*/
actorType: input.actorType,
actor_type: input.actorType,
token,
},
@@ -170,7 +170,7 @@ const getAuthContextFromSession = (
return null
}
const getAuthContextFromJwtToken = (
export const getAuthContextFromJwtToken = (
authHeader: string | undefined,
jwtSecret: string,
authTypes: AuthType[],
+14 -16
View File
@@ -20,7 +20,7 @@ export class Auth {
* @param payload - The data to pass in the request's body for authentication. When using the `emailpass` provider,
* you pass the email and password.
* @returns The JWT token used for registration later.
*
*
* @tags auth
*
* @example
@@ -68,7 +68,7 @@ export class Auth {
* @param payload - The data to pass in the request's body for authentication. When using the `emailpass` provider,
* you pass the email and password.
* @returns The authentication JWT token
*
*
* @tags auth
*
* @example
@@ -116,7 +116,7 @@ export class Auth {
* @param query - The query parameters from the Oauth callback, which should be passed to the API route. This includes query parameters like
* `code` and `state`.
* @returns The authentication JWT token
*
*
* @tags auth
*
* @example
@@ -125,7 +125,7 @@ export class Auth {
* "google",
* {
* code: "123",
* state: "456"
* state: "456"
* }
* ).then((token) => {
* console.log(token)
@@ -158,7 +158,7 @@ export class Auth {
* with {@link callback}. It sends a request to the [Refresh Authentication Token API route](https://docs.medusajs.com/api/admin#auth_postadminauthtokenrefresh).
*
* @returns The refreshed JWT authentication token.
*
*
* @tags auth
*
* @example
@@ -184,7 +184,7 @@ export class Auth {
/**
* This method deletes the authentication session of the currently logged-in user to log them out.
* It sends a request to the [Delete Authentication Session API route](https://docs.medusajs.com/api/admin#auth_deletesession).
*
*
* @tags auth
*
* @example
@@ -214,7 +214,7 @@ export class Auth {
* @param actor - The actor type. For example, `user` for admin user, or `customer` for customer.
* @param provider - The authentication provider to use. For example, `emailpass`.
* @param body - The data required to identify the user.
*
*
* @tags auth
*
* @example
@@ -261,7 +261,7 @@ export class Auth {
* @param provider - The authentication provider to use. For example, `emailpass`.
* @param body - The data necessary to update the user's authentication data. When resetting the user's password,
* send the `password` property.
*
*
* @tags auth
*
* @example
@@ -280,16 +280,14 @@ export class Auth {
updateProvider = async (
actor: string,
provider: string,
body: Record<string, unknown>,
body: HttpTypes.AdminUpdateProvider,
token: string
) => {
await this.client.fetch(
`/auth/${actor}/${provider}/update?token=${token}`,
{
method: "POST",
body,
}
)
await this.client.fetch(`/auth/${actor}/${provider}/update`, {
method: "POST",
body,
headers: { Authorization: `Bearer ${token}` },
})
}
/**
@@ -5,3 +5,7 @@ export interface AdminSignUpWithEmailPassword {
export interface AdminSignInWithEmailPassword
extends AdminSignUpWithEmailPassword {}
export interface AdminUpdateProvider {
[key: string]: unknown // Allow for any additional fields, this will vary depending on the provider
}