Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .changeset/pre.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"mode": "pre",
"tag": "beta",
"initialVersions": {
"@labdigital/federated-token-apollo": "2.1.0",
"@labdigital/federated-token": "2.1.0",
"@labdigital/federated-token-express-adapter": "2.1.0",
"@labdigital/federated-token-fastify-adapter": "2.1.0",
"@labdigital/federated-token-react": "2.1.0",
"@labdigital/federated-token-yoga": "2.1.0"
},
"changesets": []
}
7 changes: 7 additions & 0 deletions .changeset/slick-rabbits-count.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
"@labdigital/federated-token-express-adapter": minor
"@labdigital/federated-token-fastify-adapter": minor
"@labdigital/federated-token": minor
---

Add support for cookie path and refresh token path function
40 changes: 35 additions & 5 deletions packages/core/src/tokensource/cookies-base.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ import {
* support multiple Set-Cookie headers, so we just 'join' them with a comma.
*/
class TestAdapter implements CookieAdapter<Request, Response> {
constructor(private options: BaseCookieSourceOptions) {}
constructor(private options: BaseCookieSourceOptions<Request>) {}

getCookie(request: Request, name: string): string | undefined {
const header = request.headers.get("cookie");
Expand Down Expand Up @@ -55,7 +55,7 @@ class TestAdapter implements CookieAdapter<Request, Response> {
class TestCookieTokenSource extends BaseCookieTokenSource<Request, Response> {
protected adapter: CookieAdapter<Request, Response>;

constructor(options: BaseCookieSourceOptions) {
constructor(options: BaseCookieSourceOptions<Request>) {
super(options);
this.adapter = new TestAdapter(options);
}
Expand Down Expand Up @@ -282,7 +282,10 @@ describe("CookieTokenSource", () => {
cookieTokenSource.deleteAccessToken(request, response);

const cookies = getCookies(response);
expect(cookies).toEqual([{ userToken: "" }, { guestToken: "" }]);
expect(cookies).toEqual([
{ userToken: "", Path: "/" },
{ guestToken: "", Path: "/" },
]);
});

// Test for deleting refresh tokens
Expand All @@ -305,8 +308,8 @@ describe("CookieTokenSource", () => {
const cookies = getCookies(response);
expect(cookies).toEqual([
{ refreshToken: "", Path: "/refresh" },
{ guestRefreshTokenExists: "" },
{ userRefreshTokenExists: "" },
{ guestRefreshTokenExists: "", Path: "/" },
{ userRefreshTokenExists: "", Path: "/" },
]);
});

Expand All @@ -330,4 +333,31 @@ describe("CookieTokenSource", () => {
const cookies = getCookies(response);
expect(cookies).toEqual([{ refreshToken: "", Path: "/refresh" }]);
});

it("should get the refresh path from the refresh path function", () => {
const request: Request = new Request("http://localhost");

const cookieTokenSource = new TestCookieTokenSource({
secure: true,
sameSite: "strict",
refreshTokenPath: () => "/refresh",
});

const result = cookieTokenSource["_getRefreshTokenPath"](request);
expect(result).toBe("/refresh");
});

it("should get the cookiePath from the cookiePath function", () => {
const request: Request = new Request("http://localhost");

const cookieTokenSource = new TestCookieTokenSource({
secure: true,
sameSite: "strict",
refreshTokenPath: "/refresh",
cookiePathFn: () => "/cookie",
});

const result = cookieTokenSource["options"].cookiePathFn?.(request);
expect(result).toBe("/cookie");
});
});
22 changes: 15 additions & 7 deletions packages/core/src/tokensource/cookies-base.ts
Original file line number Diff line number Diff line change
Expand Up @@ -63,14 +63,15 @@ type CookieSettings = {
expiresIn: number | "session";
};

export type BaseCookieSourceOptions = {
export type BaseCookieSourceOptions<TRequest> = {
secure: boolean;
sameSite: "strict" | "lax" | "none" | boolean;
refreshTokenPath: string;
refreshTokenPath: string | ((request: TRequest) => string | undefined);
cookieNames?: Partial<CookieNames>;
guestToken?: CookieSettings;
userToken?: CookieSettings;
refreshToken?: CookieSettings;
cookiePathFn?: (request: TRequest) => string | undefined;
};

export abstract class BaseCookieTokenSource<TRequest, TResponse>
Expand All @@ -79,7 +80,7 @@ export abstract class BaseCookieTokenSource<TRequest, TResponse>
protected cookieNames: CookieNames;
protected abstract adapter: CookieAdapter<TRequest, TResponse>;

constructor(protected options: BaseCookieSourceOptions) {
constructor(protected options: BaseCookieSourceOptions<TRequest>) {
this.cookieNames = {
...DEFAULT_COOKIE_NAMES,
...(options.cookieNames ?? {}),
Expand All @@ -96,7 +97,7 @@ export abstract class BaseCookieTokenSource<TRequest, TResponse>

deleteRefreshToken(request: TRequest, response: TResponse): void {
this.adapter.clearCookie(request, response, this.cookieNames.refreshToken, {
path: this.options.refreshTokenPath,
path: this._getRefreshTokenPath(request),
domain: this.adapter.getPrivateDomain(request),
});

Expand Down Expand Up @@ -128,6 +129,7 @@ export abstract class BaseCookieTokenSource<TRequest, TResponse>
if (this.adapter.getCookie(request, name)) {
this.adapter.clearCookie(request, response, name, {
domain: this.adapter.getPublicDomain(request),
path: this.options.cookiePathFn?.(request) ?? "/",
});
}
}
Expand All @@ -140,6 +142,7 @@ export abstract class BaseCookieTokenSource<TRequest, TResponse>
if (this.adapter.getCookie(request, name)) {
this.adapter.clearCookie(request, response, name, {
domain: this.adapter.getPublicDomain(request),
path: this.options.cookiePathFn?.(request) ?? "/",
});
}
}
Expand Down Expand Up @@ -180,7 +183,7 @@ export abstract class BaseCookieTokenSource<TRequest, TResponse>
opts.expiresIn === "session"
? undefined
: new Date(Date.now() + opts.expiresIn * 1000),
path: "/",
path: this.options.cookiePathFn?.(request) ?? "/",
};

if (isAuthenticated) {
Expand Down Expand Up @@ -244,7 +247,7 @@ export abstract class BaseCookieTokenSource<TRequest, TResponse>
opts.expiresIn === "session"
? undefined
: new Date(Date.now() + opts.expiresIn * 1000),
path: "/",
path: this.options.cookiePathFn?.(request) ?? "/",
};

if (isAuthenticated) {
Expand Down Expand Up @@ -299,7 +302,7 @@ export abstract class BaseCookieTokenSource<TRequest, TResponse>
{
...cookieOptions,
httpOnly: true,
path: this.options.refreshTokenPath,
path: this._getRefreshTokenPath(request),
},
);

Expand Down Expand Up @@ -331,4 +334,9 @@ export abstract class BaseCookieTokenSource<TRequest, TResponse>
);
}
}

private _getRefreshTokenPath(req: TRequest): string | undefined {
const path = this.options.refreshTokenPath;
return typeof path === "function" ? path(req) : path;
}
}
4 changes: 3 additions & 1 deletion packages/express-adapter/src/cookies.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,11 @@ import {
} from "@labdigital/federated-token/tokensource";
import type { CookieOptions, Request, Response } from "express";

type ExpressCookieSourceOptions = BaseCookieSourceOptions & {
type ExpressCookieSourceOptions = BaseCookieSourceOptions<Request> & {
refreshTokenPath: string | ((request: Request) => string | undefined);
publicDomainFn?: (request: Request) => string | undefined;
privateDomainFn?: (request: Request) => string | undefined;
cookiePathFn?: (request: Request) => string | undefined;
Copy link

Copilot AI Sep 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The function signatures correctly use the Express Request type, which is consistent with other properties in this interface. This is the expected pattern for the Express adapter.

Copilot uses AI. Check for mistakes.

};

class ExpressCookieAdapter implements CookieAdapter<Request, Response> {
Expand Down
4 changes: 3 additions & 1 deletion packages/fastify-adapter/src/cookies.ts
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,11 @@ import {
} from "@labdigital/federated-token/tokensource";
import type { FastifyReply, FastifyRequest } from "fastify";

type FastifyCookieSourceOptions = BaseCookieSourceOptions & {
type FastifyCookieSourceOptions = BaseCookieSourceOptions<FastifyRequest> & {
refreshTokenPath: string | ((request: FastifyRequest) => string | undefined);
publicDomainFn?: (request: FastifyRequest) => string | undefined;
privateDomainFn?: (request: FastifyRequest) => string | undefined;
cookiePathFn?: (request: FastifyRequest) => string | undefined;
};

class FastifyCookieAdapter
Expand Down