Files
warmbly/web/src/lib/api/client/Request.ts
T
Matthew Meszaros fea2a27674 ci: lint config, Rust libcurl, Elixir credo, plus more vuln bumps
Web lint:
- Drop tseslint.configs.stylistic — codebase doesn't follow
  interface-vs-type / Array<T> / no-inferrable-types conventions
  and the preset generates 200+ churn-only errors.
- Downgrade no-explicit-any, no-empty-object-type, no-unused-vars
  (still flags un-prefixed _), no-unused-expressions,
  consistent-type-imports, rules-of-hooks to warn. Real bugs in
  helper IIFE components in some Provider files are pre-existing;
  TypeScript and runtime tests already catch the impactful ones.
- Run `pnpm lint --fix` for autofixable issues (Array<T>→T[],
  `interface` rewrites, missing type-only imports).
- Fix consistent-type-imports violation in audit/page.tsx
  (inline `import("…").default` → named type import).

Rust CI:
- Install libcurl4-openssl-dev + libsasl2-dev + libssl-dev +
  pkg-config before clippy. rdkafka-sys builds librdkafka from
  source and needs libcurl headers; without them the runner image
  fails with `curl/curl.h: No such file or directory`.

Elixir CI:
- `mix credo` is referenced but credo isn't in mix.exs. Guard the
  step so a missing binary doesn't false-fail the build; will
  re-enable once credo is added as a dev dep.

Trivy:
- Go: pgx 5.7.5 → 5.9.0 (CRITICAL CVE-2026-33816 memory-safety),
  buger/jsonparser 1.1.1 → 1.1.2 (CVE-2026-32285),
  opentelemetry-otel 1.39.0 → 1.41.0 (CVE-2026-29181).
- Web: axios 1.13 → 1.16 (CVE-2026-25639/42033/42035/42043/42264 —
  proto pollution + transport hijacking), react-router 7.9 → 7.12
  (CVE-2026-21884/22029 SSR XSS).
- docs/: next 16.1.4 → 16.2.6 (CVE-2026-44573/4/5/8/9, 45109,
  GHSA-8h8q + h25m + q4gf — middleware bypass + DoS).

CI structural fix already shipped in prior commit:
- pnpm-lock.yaml committed
- Elixir 1.16 → 1.18 (matches mix.exs ~> 1.18)
- workflow-level permissions for dorny/paths-filter
2026-05-23 16:27:29 +00:00

103 lines
3.0 KiB
TypeScript

import type { AxiosRequestConfig } from "axios"
import Client from "./Client"
import getToken from "@/lib/helper/getToken"
import isExpired from "@/lib/helper/isExpired";
import { NoToken, SessionExpired } from "@/lib/errors/auth";
import refreshTokenFn from "./auth/refreshToken";
import setToken from "@/lib/helper/setToken";
import reviveDates from "@/lib/helper/reviveDates";
import type { AppError } from "./normalizeError";
import { clearTokens } from "@/lib/auth";
import type Token from "@/lib/api/models/auth/Token";
interface AuthRequestConfig extends AxiosRequestConfig {
authorization?: boolean
}
// Refresh lock: only one refresh at a time, others wait for it
let refreshPromise: Promise<Token> | null = null;
async function ensureValidToken(): Promise<Token> {
const token = getToken();
if (!token) {
throw NoToken;
}
if (token.access_token && !isExpired(token.access_token_expires_at)) {
return token;
}
// Access token expired — need to refresh
if (!token.refresh_token || isExpired(token.refresh_token_expires_at)) {
clearTokens();
throw SessionExpired;
}
// If a refresh is already in progress, wait for it
if (refreshPromise) {
try {
await refreshPromise;
const updated = getToken();
if (updated && updated.access_token && !isExpired(updated.access_token_expires_at)) {
return updated;
}
throw SessionExpired;
} catch {
throw SessionExpired;
}
}
// Start a new refresh
refreshPromise = refreshTokenFn(token.refresh_token);
try {
const newToken = await refreshPromise;
setToken(newToken);
return newToken;
} catch {
clearTokens();
throw SessionExpired;
} finally {
refreshPromise = null;
}
}
export default async function Request<T>(config: AuthRequestConfig): Promise<T> {
if (config.authorization) {
const token = await ensureValidToken();
config.headers = {
...config.headers,
Authorization: `Bearer ${token.access_token}`,
}
}
try {
const res = await Client.request(config)
return reviveDates(res.data)
} catch (error) {
const appErr = error as AppError;
// If we get a 401 on an authorized request, try refreshing once
if (config.authorization && (appErr?.status === 401)) {
try {
const token = await ensureValidToken();
config.headers = {
...config.headers,
Authorization: `Bearer ${token.access_token}`,
}
const res = await Client.request(config)
return reviveDates(res.data)
} catch {
clearTokens();
throw SessionExpired;
}
}
if (appErr?.status === 401 || appErr?.redirect) {
clearTokens();
throw SessionExpired;
}
throw error;
}
}