7ce42324da
The frontend half of the calendar auth cutover (step 4 of docs/calendar-auth-migration.md in the API repo). This app now shares one identity with the tickets, feedback and admin apps. Every call carries the session cookie via withCredentials rather than appending sessionId/sessionKey to the URL, so there is no credential left in api.service.ts at all - that was DEFERRED_SECURITY.md item 1. The login and registration forms are gone. Accounts exist only by invitation from the admin app, so both were one redirect; sign-out ends the session for all four apps and returns here, so doing it by accident costs one click. 401 and 403 are deliberately not collapsed. Only 401 goes to the login page: redirecting on 403 produces a loop where signing in succeeds and lands straight back on the refusal, and doing it for an unreachable API produces the same loop with no way out. Both of those now render a message instead. src/app/models/session.ts and the unrouted LoginComponent are dead but left in place; removing files is a separate decision. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
32 lines
841 B
TypeScript
32 lines
841 B
TypeScript
import {Injectable} from '@angular/core';
|
|
|
|
@Injectable({
|
|
providedIn: 'root'
|
|
})
|
|
export class UtilsService {
|
|
|
|
constructor() {
|
|
}
|
|
|
|
/**
|
|
* The signed-in user's name, cached so a freshly added draft row can show an
|
|
* author before it has been saved. Purely cosmetic: the server records the
|
|
* author from the session, never from anything the client sends.
|
|
*
|
|
* The session itself is an httpOnly cookie and is deliberately not here -
|
|
* this app used to keep a sessionId/sessionKey pair in localStorage and
|
|
* append it to every URL, which is what the auth cutover removed.
|
|
*/
|
|
static saveNameToLocalStorage(name: string): void {
|
|
localStorage.setItem('name', name);
|
|
}
|
|
|
|
static getNameFromLocalStorage(): string {
|
|
return localStorage.getItem('name') ?? '';
|
|
}
|
|
|
|
static clearName(): void {
|
|
localStorage.removeItem('name');
|
|
}
|
|
}
|