Repository navigation
Initial Auth Flow & UI Updates #14
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
17 commits
Select commit
Hold shift + click to select a range
0e3e721
new home page mock
orimcoding c05d55c
dashboard shell
orimcoding 3770d33
dashboard layout
orimcoding 355de79
refined home page mock
orimcoding e2413c8
updated global styling
orimcoding 2a1a34d
dependencies additions
orimcoding 6ced524
route validation
orimcoding c13606d
updating current sign-up / sign-in routes
orimcoding 8fb59e4
logout route creation
orimcoding 2bf17ed
login/sign-up page scaffold
orimcoding e2d02aa
shared auth shell
orimcoding c082181
reusable auth form
orimcoding 9ac2740
reference updates
orimcoding 6fb1644
login / signup initial frontend
orimcoding 6ded032
middleware refactoring
orimcoding 944e77b
session aware UI & logout flow
orimcoding 77d249a
Merge remote-tracking branch 'origin/main' into feat/login-v0
orimcoding File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| import { createServerSupabaseClient } from "@/lib/supabase/server"; | ||
| import { NextResponse } from "next/server"; | ||
|
|
||
| export async function POST() { | ||
| try { | ||
| const supabase = await createServerSupabaseClient(); | ||
| const { error } = await supabase.auth.signOut(); | ||
|
|
||
| if (error) { | ||
| return NextResponse.json({ error: error.message }, { status: 400 }); | ||
| } | ||
|
|
||
| return NextResponse.json({ success: true }); | ||
| } catch { | ||
| return NextResponse.json( | ||
| { error: "Internal server error" }, | ||
| { status: 500 } | ||
| ); | ||
| } | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,71 @@ | ||
| "use client"; | ||
|
|
||
| import Link from "next/link"; | ||
| import { useRouter } from "next/navigation"; | ||
| import { useState } from "react"; | ||
| import { AuthForm } from "@/components/auth/auth-form"; | ||
| import { AuthShell } from "@/components/auth/auth-shell"; | ||
|
|
||
| export default function LoginPage() { | ||
| const router = useRouter(); | ||
| const [isSubmitting, setIsSubmitting] = useState(false); | ||
| const [error, setError] = useState<string | null>(null); | ||
|
|
||
| async function handleSubmit(event: React.FormEvent<HTMLFormElement>) { | ||
| event.preventDefault(); | ||
| setError(null); | ||
| setIsSubmitting(true); | ||
|
|
||
| const formData = new FormData(event.currentTarget); | ||
| const email = formData.get("email"); | ||
| const password = formData.get("password"); | ||
|
|
||
| try { | ||
| const response = await fetch("/api/auth/login", { | ||
| method: "POST", | ||
| headers: { | ||
| "Content-Type": "application/json", | ||
| }, | ||
| body: JSON.stringify({ email, password }), | ||
| }); | ||
|
|
||
| const result = (await response.json()) as { error?: string }; | ||
|
|
||
| if (!response.ok) { | ||
| setError(result.error ?? "Unable to sign in"); | ||
| return; | ||
| } | ||
|
|
||
| router.push("/dashboard"); | ||
| router.refresh(); | ||
| } catch { | ||
| setError("Something went wrong. Please try again."); | ||
| } finally { | ||
| setIsSubmitting(false); | ||
| } | ||
| } | ||
|
|
||
| return ( | ||
| <AuthShell | ||
| title="Welcome back." | ||
| subtitle="Sign in to open your football workspace, follow live matchdays, and pick up where you left off." | ||
| footer={ | ||
| <> | ||
| New to Swale?{" "} | ||
| <Link href="/signup" className="font-medium text-blue-700 hover:text-blue-800"> | ||
| Create an account | ||
| </Link> | ||
| </> | ||
| } | ||
| > | ||
| <AuthForm | ||
| mode="login" | ||
| submitLabel={isSubmitting ? "Signing in..." : "Sign in"} | ||
| helperText="Use your email and password to access your live dashboard, saved context, and player tracking workspace." | ||
| isSubmitting={isSubmitting} | ||
| error={error} | ||
| onSubmit={handleSubmit} | ||
| /> | ||
| </AuthShell> | ||
| ); | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🧩 Analysis chain
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 158
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 42
🏁 Script executed:
# Read the login route file to see what's currently there cat -n src/app/api/auth/login/route.tsRepository: orimcoding/swale
Length of output: 1424
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 44
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 44
🏁 Script executed:
# Check if there's middleware in the api/auth directory ls -la src/app/api/auth/Repository: orimcoding/swale
Length of output: 333
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 88
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 78
🏁 Script executed:
# Read the middleware file to check for rate limiting cat -n src/middleware.tsRepository: orimcoding/swale
Length of output: 2320
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 42
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 42
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 430
🏁 Script executed:
# Read the timeout utility to understand how it's implemented cat -n src/lib/utils.tsRepository: orimcoding/swale
Length of output: 12936
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 42
🏁 Script executed:
# Check package.json to see what dependencies are available cat package.jsonRepository: orimcoding/swale
Length of output: 1140
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 42
🏁 Script executed:
# Check if there are any other auth route files to see if they have rate limiting cat -n src/app/api/auth/signup/route.tsRepository: orimcoding/swale
Length of output: 1434
🏁 Script executed:
Repository: orimcoding/swale
Length of output: 42
Add rate limiting and timeout guards to the login endpoint.
This credential route currently has no rate limiter and no bounded-time guard around the external auth call, which leaves brute-force and request-exhaustion paths open.
As per coding guidelines, "Check for rate limiting and timeout handling." While
fetchWithTimeoututility exists in the codebase, it is not applied to thesupabase.auth.signInWithPassword()call. Additionally, no rate limiting mechanism (e.g., using Upstash Redis) is implemented on this endpoint.🤖 Prompt for AI Agents
Source: Coding guidelines