BUG fix. Refresh route should properly refresh the token and be calla… (#69)

* BUG fix. Refresh route should properly refresh the token and be callable when cookie token is no longer valid.

* Use old session id from old token for refresh. Refresh offset set to ten minutes.
This commit is contained in:
Hendrik
2025-09-08 11:36:11 +02:00
committed by GitHub
parent 22dc3e71d6
commit 94e20ca9aa
4 changed files with 58 additions and 12 deletions
+1 -1
View File
@@ -21,13 +21,13 @@ const PUBLIC_PATHS = [
"/api/log",
"/api/admin/init",
"/api/admin/exists",
"/api/auth/refresh", // Must be public since the access token might already be invalid when this gets called
];
const GLOBAL_ADMIN_PATHS = ["/api/admin", "/api/tenants"];
const ADMIN_PATHS = ["/api/tenant-admin"];
const PROTECTED_AUTH_PATHS = [
"/api/auth/logout",
"/api/auth/refresh",
"/api/auth/session",
"/api/auth/sessions",
"/api/auth/passkeys",