fix(oauth): declare searchParams in register-session POST handler
Missing declaration caused a ReferenceError -> 500 HTML response instead of JSON when clients called POST .../register-session.
This commit is contained in:
parent
86131b9ca4
commit
948dd8f89b
1 changed files with 1 additions and 0 deletions
|
|
@ -254,6 +254,7 @@ export async function POST(request, { params }) {
|
||||||
if (action === "register-session") {
|
if (action === "register-session") {
|
||||||
// Register proxy session out of URL query (state) + body (codeVerifier).
|
// Register proxy session out of URL query (state) + body (codeVerifier).
|
||||||
// Zed's codeVerifier encodes the RSA private key — must stay out of URL/logs.
|
// Zed's codeVerifier encodes the RSA private key — must stay out of URL/logs.
|
||||||
|
const searchParams = new URL(request.url).searchParams;
|
||||||
const state = searchParams.get("state") || body?.state;
|
const state = searchParams.get("state") || body?.state;
|
||||||
if (!state) return NextResponse.json({ error: "Missing state" }, { status: 400 });
|
if (!state) return NextResponse.json({ error: "Missing state" }, { status: 400 });
|
||||||
let ok = false;
|
let ok = false;
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue