mirror of
https://github.com/hex248/sprint.git
synced 2026-02-08 18:33:01 +00:00
updated auth routes to use sessions and "httpOnly" cookies
This commit is contained in:
@@ -8,5 +8,10 @@ export default async function me(req: AuthedRequest) {
|
||||
return new Response("user not found", { status: 404 });
|
||||
}
|
||||
|
||||
return Response.json(user as UserRecord);
|
||||
const { passwordHash: _, ...safeUser } = user;
|
||||
|
||||
return Response.json({
|
||||
user: safeUser as Omit<UserRecord, "passwordHash">,
|
||||
csrfToken: req.csrfToken,
|
||||
});
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user