mirror of
https://github.com/go-shiori/shiori.git
synced 2026-04-25 22:45:55 +03:00
[PR #743] [MERGED] feat: use new JWT auth in all frontend API calls #766
Labels
No labels
component:backend
component:builds
component:builds
component:extension
component:frontend
component:readability
database
database:mysql
database:postgres
database:sqlite
feature:ebooks
github_actions
good first issue
hacktoberfest
note:duplicate?
note:fixed?
note:out-of-scope?
os:windows
priority:high
priority:low
pull-request
resolution:as-intended
resolution:cant-reproduce
resolution:duplicate
resolution:fixed
resolution:wontfix
tag:TBD
tag:big-task
tag:help-wanted
tag:huge-data
tag:meta
tag:more-info
tag:next
tag:no-stale
tag:requires-migrations
tag:research
tag:security 🛡️
tag:stale
tag:waiting-for-assignee
type:bug
type:documentation
type:enhancement
type:meta
type:ux
user:cli
user:web
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/shiori#766
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/go-shiori/shiori/pull/743
Author: @fmartingr
Created: 9/30/2023
Status: ✅ Merged
Merged: 9/30/2023
Merged by: @fmartingr
Base:
master← Head:frontend-jwt-auth📝 Commits (3)
ba71dbcproperly store jwt token2d9f153use a secret in the local dev server248bbcesend jwt token in all api calls📊 Changes
4 files changed (+110 additions, -97 deletions)
View changed files
📝
Makefile(+1 -1)📝
internal/view/assets/js/page/home.js(+99 -94)📝
internal/view/assets/js/page/setting.js(+9 -1)📝
internal/view/login.html(+1 -1)📄 Description
Authorizationheader.There's still something to solve when we require the user to load an URL that is not an API route (bookmark archive, readable, ebook), since those won't be API calls per se, but load content directly in the browser. Right now they work because we still maintain the cookie with the session around, but we need to figure out the best way to migrate that to the new routes. Probably a cookie is the best solution, but we need to think what to put in it.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.