mirror of
https://github.com/open-reception/appointment-booking-software.git
synced 2026-09-29 12:14:50 +02:00
BUG fix. Refresh route should properly refresh the token and be calla… (#69)
* BUG fix. Refresh route should properly refresh the token and be callable when cookie token is no longer valid. * Use old session id from old token for refresh. Refresh offset set to ten minutes.
This commit is contained in:
@@ -21,13 +21,13 @@ const PUBLIC_PATHS = [
|
||||
"/api/log",
|
||||
"/api/admin/init",
|
||||
"/api/admin/exists",
|
||||
"/api/auth/refresh", // Must be public since the access token might already be invalid when this gets called
|
||||
];
|
||||
const GLOBAL_ADMIN_PATHS = ["/api/admin", "/api/tenants"];
|
||||
const ADMIN_PATHS = ["/api/tenant-admin"];
|
||||
|
||||
const PROTECTED_AUTH_PATHS = [
|
||||
"/api/auth/logout",
|
||||
"/api/auth/refresh",
|
||||
"/api/auth/session",
|
||||
"/api/auth/sessions",
|
||||
"/api/auth/passkeys",
|
||||
|
||||
Reference in New Issue
Block a user