2026-06-17 17:06:30 -06:00
|
|
|
/**
|
|
|
|
|
* Session store — the authenticated user and derived flags.
|
|
|
|
|
*
|
2026-06-17 22:07:18 -06:00
|
|
|
* Replaces the user-related fields of the original `app` state object
|
2026-06-17 17:06:30 -06:00
|
|
|
* (isExternalUser, userHomeFolderId/Name). `isExternalUser` drives default
|
|
|
|
|
* routing: externals (magic-link / OIDC-only / OCM recipients) have no home
|
|
|
|
|
* folder and land on the shared-with-me view.
|
|
|
|
|
*/
|
|
|
|
|
import { fetchMe, tryRefresh } from '$lib/api/endpoints/auth';
|
2026-06-20 01:28:52 +02:00
|
|
|
import { drives } from '$lib/stores/drives.svelte';
|
2026-06-17 17:06:30 -06:00
|
|
|
import type { User } from '$lib/api/types';
|
|
|
|
|
|
|
|
|
|
class SessionStore {
|
|
|
|
|
user = $state<User | null>(null);
|
|
|
|
|
loaded = $state(false);
|
|
|
|
|
homeFolderId = $state<string | null>(null);
|
|
|
|
|
homeFolderName = $state<string | null>(null);
|
|
|
|
|
|
|
|
|
|
isExternalUser = $derived(this.user?.is_external ?? false);
|
|
|
|
|
isAuthenticated = $derived(this.user !== null);
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Resolve the session once. Probes /api/auth/me; on 401 it makes a single
|
|
|
|
|
* refresh attempt and re-probes. Never redirects — the layout guard decides
|
|
|
|
|
* what to do with an unauthenticated result. Idempotent: subsequent calls
|
|
|
|
|
* return the cached result (so client-side navigation doesn't re-probe).
|
|
|
|
|
*/
|
|
|
|
|
async load(): Promise<User | null> {
|
|
|
|
|
if (this.loaded) return this.user;
|
|
|
|
|
try {
|
|
|
|
|
let me = await fetchMe();
|
|
|
|
|
if (!me && (await tryRefresh())) {
|
|
|
|
|
me = await fetchMe();
|
|
|
|
|
}
|
|
|
|
|
this.user = me;
|
|
|
|
|
} catch {
|
|
|
|
|
this.user = null;
|
|
|
|
|
}
|
|
|
|
|
this.loaded = true;
|
|
|
|
|
return this.user;
|
|
|
|
|
}
|
|
|
|
|
|
2026-06-20 16:33:08 +02:00
|
|
|
/**
|
|
|
|
|
* Re-fetch the authenticated user from the server, bypassing the one-shot
|
|
|
|
|
* `load()` cache. Call after operations that change server-side user state —
|
|
|
|
|
* chiefly storage usage after uploads / deletes — so the UI reflects the new
|
|
|
|
|
* `storage_used_bytes` instead of the value cached at login. A transient
|
|
|
|
|
* failure leaves the current user untouched (never logs the UI out).
|
|
|
|
|
*/
|
|
|
|
|
async refresh(): Promise<void> {
|
|
|
|
|
try {
|
|
|
|
|
const me = await fetchMe();
|
|
|
|
|
if (me) this.user = me;
|
|
|
|
|
} catch {
|
|
|
|
|
/* keep the existing user on a transient /api/auth/me failure */
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-06-17 17:06:30 -06:00
|
|
|
/**
|
2026-06-20 01:28:52 +02:00
|
|
|
* Resolve the caller's default personal drive's root folder — the landing
|
|
|
|
|
* point for `/files` and the `/` redirect. Externals (grant-only) have no
|
|
|
|
|
* personal drive, so this is skipped for them.
|
|
|
|
|
*
|
|
|
|
|
* Identifies the default via `default_for_user`, not folder name: users
|
|
|
|
|
* can rename "Personal" without breaking this lookup.
|
2026-06-17 17:06:30 -06:00
|
|
|
*/
|
|
|
|
|
async loadHomeFolder(): Promise<string | null> {
|
|
|
|
|
if (this.homeFolderId) return this.homeFolderId;
|
|
|
|
|
if (this.isExternalUser) return null;
|
2026-06-20 01:28:52 +02:00
|
|
|
await drives.load();
|
|
|
|
|
const def = drives.findDefault();
|
|
|
|
|
if (def) {
|
|
|
|
|
this.homeFolderId = def.root_folder_id;
|
|
|
|
|
this.homeFolderName = def.name;
|
2026-06-17 17:06:30 -06:00
|
|
|
}
|
|
|
|
|
return this.homeFolderId;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
reset(): void {
|
|
|
|
|
this.user = null;
|
|
|
|
|
this.homeFolderId = null;
|
|
|
|
|
this.homeFolderName = null;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
export const session = new SessionStore();
|