website/routes/_middleware.ts

60 lines
1.4 KiB
TypeScript
Raw Normal View History

import { FreshContext } from '$fresh/server.ts'
import { SessionStore } from ':src/session/mod.ts'
2024-06-13 14:42:39 +02:00
import { getCookies, setCookie } from '@std/http/cookie'
export async function handler(request: Request, ctx: FreshContext) {
// Update fresh context state with session
ctx.state = { ...ctx.state, session: SessionStore.getFromRequest(request) }
// Allow service worker to serve root scope
const response = await ctx.next()
const url = new URL(request.url)
if (url.pathname.endsWith('island-startserviceworker.js')) {
response.headers.set('Service-Worker-Allowed', '/')
}
2024-06-13 12:20:47 +02:00
// Start session
if (SessionStore.getFromRequest(request) === undefined) {
// Clear outdated cookies
for (const cookie in getCookies(request.headers)) {
2024-06-13 14:42:39 +02:00
setCookie(response.headers, {
name: cookie,
value: '',
2024-06-13 17:20:15 +02:00
path: '/',
2024-06-13 14:42:39 +02:00
expires: 0,
})
}
// Create new session
2024-06-13 12:20:47 +02:00
const session = SessionStore.createSession()
ctx.state = { ...ctx.state, session }
2024-06-13 12:20:47 +02:00
// Set session cookie
setCookie(response.headers, {
name: '_SESSION',
value: session.uuid,
httpOnly: true,
sameSite: 'Strict',
secure: true,
2024-06-13 14:38:27 +02:00
path: '/',
2024-06-13 12:20:47 +02:00
expires: SessionStore.maxAge,
})
// Set csrf
const csrf = crypto.randomUUID()
session.set('_csrf', csrf)
setCookie(response.headers, {
name: '_CSRF',
value: csrf,
httpOnly: false,
sameSite: 'Strict',
secure: true,
2024-06-13 14:38:27 +02:00
path: '/',
2024-06-13 12:20:47 +02:00
expires: SessionStore.maxAge,
})
}
return response
}