Revert: Remove token from response (HttpOnly cookie is sufficient)
Login page checks cookie on load via useEffect, no need for localStorage token. More secure this way. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
parent
73cfd2a761
commit
ffaa92cd13
2 changed files with 0 additions and 4 deletions
|
|
@ -34,8 +34,6 @@ export default function AdminLoginPage() {
|
|||
const data = await res.json();
|
||||
|
||||
if (res.ok && data.success) {
|
||||
localStorage.setItem("admin_token", data.token);
|
||||
localStorage.setItem("admin_user", JSON.stringify({ username: data.username, role: data.role }));
|
||||
router.push("/admin");
|
||||
} else {
|
||||
setError(data.error || "Invalid credentials");
|
||||
|
|
|
|||
|
|
@ -60,7 +60,6 @@ export async function POST(request: Request) {
|
|||
|
||||
const response = NextResponse.json({
|
||||
success: true,
|
||||
token: sessionToken,
|
||||
admin: { username, role: "super_admin" },
|
||||
});
|
||||
response.cookies.set("tia_admin_session", sessionToken, {
|
||||
|
|
@ -102,7 +101,6 @@ export async function POST(request: Request) {
|
|||
|
||||
const response = NextResponse.json({
|
||||
success: true,
|
||||
token: sessionToken,
|
||||
username: admin.username,
|
||||
role: admin.role,
|
||||
});
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue