feat(dpop): provide nonce on immediate login

provide the DPoP nonce via cookie on login, this reduce the amount of API call
and prevent having any first call returning in 401
This commit is contained in:
Edouard Vanbelle
2026-08-09 14:40:10 +02:00
parent 2eb1e8a1d5
commit 950c8c0f38
9 changed files with 155 additions and 1 deletions
+9
View File
@@ -6,6 +6,7 @@
import { setSessionExpiredHandler } from '$lib/api/client';
import { initI18n } from '$lib/i18n/index.svelte';
import { session } from '$lib/stores/session.svelte';
import { seedNonceFromCookie } from '$lib/auth/dpop-proof';
export async function init(): Promise<void> {
setSessionExpiredHandler(() => {
@@ -15,5 +16,13 @@ export async function init(): Promise<void> {
}
});
// Consume the one-shot `oxicloud_dpop_nonce` cookie the backend
// stamps on every login-success response — critical for redirect-
// flow logins (OIDC callback, magic-link finish) where the browser
// lands here BEFORE any client-side login handler has run. Without
// this, the layout's `session.load()` fetchMe would be the first
// bound request and eat a `use_dpop_nonce` 401 → retry cycle.
seedNonceFromCookie();
await initI18n();
}