import { NextResponse } from 'next/server'; import { cookies } from 'next/headers'; import { createCustomerSessionToken, CUSTOMER_SESSION_COOKIE, getCustomerSessionCookieOptions, } from '@/infrastructure/auth/customer-session'; import { fetchGoogleUserFromCode, isGoogleOAuthConfigured, verifyOAuthState, } from '@/infrastructure/auth/google-oauth'; import { getOAuthReturnCookieName, sanitizeOAuthReturnPath, } from '@/infrastructure/auth/oauth-return'; export const dynamic = 'force-dynamic'; const OAUTH_STATE_COOKIE = 'shahi_google_oauth_state'; function redirectToLogin(error: string, returnTo?: string) { const loginUrl = new URL('/login', getOrigin()); loginUrl.searchParams.set('tab', 'customer'); loginUrl.searchParams.set('error', error); if (returnTo && returnTo !== '/account') { loginUrl.searchParams.set('returnTo', returnTo); } return NextResponse.redirect(loginUrl); } function getOrigin(): string { return process.env.NEXT_PUBLIC_SITE_URL ?? 'http://localhost:3000'; } export async function GET(request: Request) { if (!isGoogleOAuthConfigured()) { return redirectToLogin('google_not_configured'); } const url = new URL(request.url); const code = url.searchParams.get('code'); const state = url.searchParams.get('state'); const oauthError = url.searchParams.get('error'); const cookieStore = await cookies(); const returnTo = sanitizeOAuthReturnPath(cookieStore.get(getOAuthReturnCookieName())?.value); cookieStore.delete(getOAuthReturnCookieName()); if (oauthError) { return redirectToLogin('google_denied', returnTo); } const storedState = cookieStore.get(OAUTH_STATE_COOKIE)?.value; cookieStore.delete(OAUTH_STATE_COOKIE); if (!verifyOAuthState(state) || state !== storedState) { return redirectToLogin('invalid_state', returnTo); } if (!code) { return redirectToLogin('missing_code', returnTo); } const user = await fetchGoogleUserFromCode(code); if (!user) { return redirectToLogin('google_failed', returnTo); } cookieStore.set( CUSTOMER_SESSION_COOKIE, createCustomerSessionToken(user), getCustomerSessionCookieOptions(), ); const response = NextResponse.redirect(new URL(returnTo, getOrigin())); response.headers.set('Cache-Control', 'no-store'); return response; }