[frontend/core] Update stored userdata on user select (ISH-705)

This commit is contained in:
Lilian 2025-02-09 14:32:22 +01:00
parent 13a25c78ff
commit 1b84d3b87e
No known key found for this signature in database
2 changed files with 48 additions and 12 deletions

View file

@ -1,5 +1,6 @@
using Blazored.LocalStorage;
using Iceshrimp.Frontend.Core.Schemas;
using Iceshrimp.Shared.Schemas.Web;
using Microsoft.AspNetCore.Components;
using Microsoft.JSInterop;
@ -7,11 +8,14 @@ namespace Iceshrimp.Frontend.Core.Services;
internal class SessionService
{
public SessionService(ApiService apiService, ISyncLocalStorageService localStorage, IJSRuntime js)
public SessionService(
ApiService apiService, ISyncLocalStorageService localStorage, IJSRuntime js, ILogger<SessionService> logger
)
{
ApiService = apiService;
LocalStorage = localStorage;
Js = js;
Logger = logger;
Users = LocalStorage.GetItem<Dictionary<string, StoredUser>>("Users") ?? [];
var lastUser = LocalStorage.GetItem<string?>("last_user");
if (lastUser != null)
@ -20,11 +24,12 @@ internal class SessionService
}
}
[Inject] public ISyncLocalStorageService LocalStorage { get; }
[Inject] public ApiService ApiService { get; }
[Inject] public IJSRuntime Js { get; }
public Dictionary<string, StoredUser> Users { get; }
public StoredUser? Current { get; private set; }
private ISyncLocalStorageService LocalStorage { get; }
private ApiService ApiService { get; }
private IJSRuntime Js { get; }
private ILogger<SessionService> Logger { get; }
public Dictionary<string, StoredUser> Users { get; }
public StoredUser? Current { get; private set; }
private void WriteUsers()
{
@ -36,15 +41,45 @@ internal class SessionService
try
{
Users.Add(user.Id, user);
Logger.LogInformation($"User {user.Id} added.");
}
catch (ArgumentException) // Update user if it already exists.
{
Users[user.Id] = user;
Logger.LogInformation($"User {user.Id} updated.");
}
WriteUsers();
}
public async Task UpdateCurrentUserAsync()
{
if (Current == null) return;
var res = await ApiService.Auth.GetAuthStatusAsync();
if (res.Status is AuthStatusEnum.Authenticated)
{
var user = new StoredUser
{ // Token nor user will ever be null on an authenticated response
Id = res.User!.Id,
Username = res.User.Username,
DisplayName = res.User.DisplayName,
AvatarUrl = res.User.AvatarUrl,
BannerUrl = res.User.BannerUrl,
InstanceName = res.User.InstanceName,
InstanceIconUrl = res.User.InstanceIconUrl,
Token = res.Token!,
Host = res.User.Host,
IsAdmin = res.IsAdmin ?? false,
IsModerator = res.IsModerator ?? false,
Emojis = res.User.Emojis,
MovedTo = res.User.MovedTo
};
AddUser(user);
Current = user;
Logger.LogInformation($"Updated current user {user.Id}");
}
}
public void DeleteUser(string id)
{
if (id == Current?.Id) throw new ArgumentException("Cannot remove current user.");
@ -63,13 +98,13 @@ internal class SessionService
Current = null;
LocalStorage.RemoveItem("last_user");
((IJSInProcessRuntime)Js).InvokeVoid("eval",
"document.cookie = \"admin_session=; path=/ ; Fri, 31 Dec 1000 23:59:59 GMT SameSite=Lax\"");
"document.cookie = \"admin_session=; path=/ ; Fri, 31 Dec 1000 23:59:59 GMT SameSite=Lax\"");
}
public void SetSession(string id)
{
((IJSInProcessRuntime)Js).InvokeVoid("eval",
"document.cookie = \"admin_session=; path=/; expires=Fri, 31 Dec 1000 23:59:59 GMT SameSite=Lax\"");
"document.cookie = \"admin_session=; path=/; expires=Fri, 31 Dec 1000 23:59:59 GMT SameSite=Lax\"");
var user = GetUserById(id);
if (user == null) throw new Exception("Did not find User in Local Storage");
ApiService.SetBearerToken(user.Token);
@ -77,11 +112,11 @@ internal class SessionService
LocalStorage.SetItem("last_user", user.Id);
var sessionsString = Users.Aggregate("", (current, el) => current + $"{el.Value.Token},").TrimEnd(',');
((IJSInProcessRuntime)Js).InvokeVoid("eval",
$"document.cookie = \"sessions={sessionsString}; path=/; expires=Fri, 31 Dec 9999 23:59:59 GMT; SameSite=Lax\"");
$"document.cookie = \"sessions={sessionsString}; path=/; expires=Fri, 31 Dec 9999 23:59:59 GMT; SameSite=Lax\"");
if (user.IsAdmin)
{
((IJSInProcessRuntime)Js).InvokeVoid("eval",
$"document.cookie = \"admin_session={user.Token}; path=/; expires=Fri, 31 Dec 9999 23:59:59 GMT; SameSite=Lax\"");
$"document.cookie = \"admin_session={user.Token}; path=/; expires=Fri, 31 Dec 9999 23:59:59 GMT; SameSite=Lax\"");
}
// Security implications of this need a second pass? user.Id should never be user controllable, but still.
}

View file

@ -209,9 +209,10 @@
}
}
private void LoginUser(StoredUser user)
private async Task LoginUser(StoredUser user)
{
SessionService.SetSession(user.Id);
await SessionService.UpdateCurrentUserAsync();
Navigation.NavigateTo(Uri.TryCreate(Redirect, UriKind.Relative, out _) ? Redirect : "/", true);
}