fix(ui): store SSO exchange token via storeLoginToken to keep Secure flag

exchangeLoginCode wrote the session cookie by hand with path=/ and no Secure flag, replacing the server-set Secure cookie from /v3/login/exchange on https deployments. Use storeLoginToken like loginCall does: UI-path cookie with Secure on https plus sessionStorage fallback, leaving the server cookie untouched.
This commit is contained in:
Nabil Ameena 2026-09-24 00:18:42 +05:30
parent 1c289e5ecd
commit f9060193fc
2 changed files with 36 additions and 1 deletions

View file

@ -118,6 +118,40 @@ describe("loginCall - storeLoginToken integration", () => {
});
});
describe("exchangeLoginCode - storeLoginToken integration", () => {
const originalFetch = global.fetch;
beforeEach(() => {
vi.clearAllMocks();
});
afterEach(() => {
global.fetch = originalFetch;
});
it("calls storeLoginToken when exchange response includes token", async () => {
global.fetch = vi.fn().mockResolvedValue({
ok: true,
json: async () => ({ token: "sso-jwt" }),
}) as unknown as typeof global.fetch;
const { storeLoginToken } = await import("@/utils/cookieUtils");
const token = await Networking.exchangeLoginCode("some-login-code");
expect(token).toBe("sso-jwt");
expect(storeLoginToken).toHaveBeenCalledWith("sso-jwt");
});
it("does not call storeLoginToken when exchange response has no token", async () => {
global.fetch = vi.fn().mockResolvedValue({
ok: true,
json: async () => ({}),
}) as unknown as typeof global.fetch;
const { storeLoginToken } = await import("@/utils/cookieUtils");
const token = await Networking.exchangeLoginCode("some-login-code");
expect(token).toBeUndefined();
expect(storeLoginToken).not.toHaveBeenCalled();
});
});
describe("modelInfoCall", () => {
let currentFetch: typeof global.fetch;

View file

@ -7240,7 +7240,8 @@ export const exchangeLoginCode = async (code: string, workerBaseUrl?: string | n
const data = await response.json();
if (data.token) {
document.cookie = `token=${data.token}; path=/; SameSite=Lax`;
// UI-path copy only; don't overwrite the server-set cookie at "/" (Secure on https) with a non-Secure one
storeLoginToken(data.token);
}
return data.token;
};