Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "fullsend",
"version": "1.8.2",
"version": "1.8.3",
"description": "Fullsend allows allowed users to send bulk text messages to groups of recipients",
"main": "server.js",
"scripts": {
Expand Down
13 changes: 8 additions & 5 deletions server.js
Original file line number Diff line number Diff line change
Expand Up @@ -168,8 +168,11 @@ authRouter.get("/api/user/:user", async ({ params: { user: user } }, res) => {
});

authRouter.get("/api/session/info", async (req, res) => {
if (req.body.sessionInfo) {
const sessionInfo = req.body.sessionInfo;
// Prefer server-side session data (populated by express-session via the
// connect.sid cookie). GET requests generally don't have a body, so rely
// on `req.session` rather than `req.body`.
const sessionInfo = req.session && (req.session.claims || (req.session.tokenSet && req.session.tokenSet.claims && req.session.tokenSet.claims()));
if (sessionInfo) {
// Expose the configured admin role name to the client so browser-side checks
// don't need to rely on Node-only process.env variables.
sessionInfo.adminRole = process.env.KEYCLOAK_ADMIN_ROLE || 'admin';
Expand All @@ -185,9 +188,9 @@ authRouter.get("/api/session/info", async (req, res) => {
} catch (e) {
console.error('local user lookup failed', e && e.message);
}
// If we have a localUser stored in session (created during callback), prefer that
const sessionLocalUser = req.session && req.session.localUser ? req.session.localUser : localUser;
res.send({ success: true, data: { sessionInfo, localUser: sessionLocalUser } });
// If we have a localUser stored in session (created during callback), prefer that
const sessionLocalUser = req.session && req.session.localUser ? req.session.localUser : localUser;
res.send({ success: true, data: { sessionInfo, localUser: sessionLocalUser } });
} else {
res.status(404).send({ success: false, error: "No session info" });
}
Expand Down