TikTok V5 + Security
This commit is contained in:
@@ -1,6 +1,10 @@
|
||||
import { NextRequest, NextResponse } from 'next/server';
|
||||
import { db } from '@/lib/db';
|
||||
import { TIKTOK_ACCOUNT_KEY, TIKTOK_OAUTH_STATE_COOKIE_NAME } from '@/lib/tiktok';
|
||||
import {
|
||||
assertExpectedTiktokAccount,
|
||||
TIKTOK_ACCOUNT_KEY,
|
||||
TIKTOK_OAUTH_STATE_COOKIE_NAME,
|
||||
} from '@/lib/tiktok';
|
||||
|
||||
const textResponse = (body: string, status: number) => {
|
||||
const response = new NextResponse(body, {
|
||||
@@ -56,6 +60,9 @@ export async function GET(request: NextRequest) {
|
||||
throw new Error(tokens.error_description || tokens.error || 'TikTok token exchange failed');
|
||||
}
|
||||
|
||||
// Reject the wrong browser account before it can replace the valid QRMaster connection.
|
||||
assertExpectedTiktokAccount(tokens.open_id);
|
||||
|
||||
const now = Date.now();
|
||||
const accessTokenExpiresAt = new Date(now + Number(tokens.expires_in || 0) * 1000);
|
||||
const refreshTokenExpiresAt = tokens.refresh_expires_in
|
||||
@@ -87,6 +94,8 @@ export async function GET(request: NextRequest) {
|
||||
} catch (err) {
|
||||
console.error('TikTok callback error:', err);
|
||||
const message = err instanceof Error ? err.message : 'Unknown error';
|
||||
return textResponse(`Failed to connect TikTok account: ${message}`, 502);
|
||||
const status =
|
||||
err instanceof Error && 'status' in err ? (err as { status?: number }).status : 502;
|
||||
return textResponse(`Failed to connect TikTok account: ${message}`, status || 502);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user