feat(auth): rate-limit /login+/setup, per-user session cap, periodic /me poll

This commit is contained in:
saopig1 committed 2026-05-27 16:16:07 +08:00
1 parent 1a11489f2e
commit a39fc25104
6 files changed
+161 -1

No files matched your search

+22
View File
@@ -10,6 +10,26 @@ const currentUser = ref<User | null>(null);
const needsSetup = ref<boolean | null>(null); // null = unknown / not fetched yet
const ready = ref(false);
let pollTimer: ReturnType<typeof setInterval> | null = null;
const POLL_INTERVAL_MS = 60_000;
function ensurePollStarted() {
if (pollTimer !== null) return;
pollTimer = setInterval(() => {
if (currentUser.value !== null) {
// Best-effort refresh; ignore errors (network blips etc.)
refreshMe().catch(() => {});
}
}, POLL_INTERVAL_MS);
}
function stopPoll() {
if (pollTimer !== null) {
clearInterval(pollTimer);
pollTimer = null;
}
}
async function refreshNeedsSetup(): Promise<void> {
const res = await fetch("/api/session/needs-setup", { credentials: "same-origin" });
if (res.ok) {
@@ -35,6 +55,7 @@ async function refresh(): Promise<void> {
await refreshMe();
}
ready.value = true;
ensurePollStarted();
}
async function login(username: string, password: string): Promise<void> {
@@ -67,6 +88,7 @@ async function setup(username: string, password: string): Promise<void> {
}
async function logout(): Promise<void> {
stopPoll();
await fetch("/api/session/logout", { method: "POST", credentials: "same-origin" });
currentUser.value = null;
}