mirror of
https://github.com/dreamhunter2333/cloudflare_temp_email.git
synced 2026-09-05 07:27:27 +08:00
Stale localStorage credentials (`jwt` / `auth` / `adminAuth` / `userJwt` / `access_token`) can be the empty string, the literal string `"undefined"`, or carry a stray newline / control character left over from an older build. axios + undici reject these eagerly with `Invalid character in header content ["Authorization"]`, so every API call crashes client-side before reaching the worker. This adds two tiny helpers in `frontend/src/utils/headers.js`: - `safeHeaderValue(v)` returns the trimmed value when it is a non-empty string with no control chars (per RFC 7230) and no `"undefined"` / `"null"` sentinel; otherwise `undefined`. - `safeBearerHeader(jwt)` wraps a safe JWT with `Bearer `, otherwise `undefined`. `apiFetch` builds the headers object incrementally and only sets each auth header when its value is safe. Missing/unsafe credentials now drop out cleanly and the worker returns a normal 401, which the existing `response.status === 401` flow already handles by surfacing the auth prompt — the same UX users see on a fresh session. Tests: `frontend/src/utils/__tests__/headers.test.js` adds 9 vitest cases covering safe input, sentinel strings, control chars (\\n / \\r / \\t / NUL / 0x1F / DEL), trimming, and `Bearer` construction. Build (`pnpm build`) and tests (`pnpm test`) both pass. Co-authored-by: voidborne-d <voidborne.d@agentmail.to> Co-authored-by: Dream Hunter <dreamhunter2333@gmail.com>
This commit is contained in:
co-authored by
voidborne-d
Dream Hunter
parent
7e7f824f88
commit
5f955ccca6
@@ -19,6 +19,7 @@
|
||||
|
||||
- fix: |Frontend| 收窄地址管理相关弹窗宽度,并让地址表格在弹窗内部横向滚动,避免多地址场景撑宽弹窗
|
||||
- fix: |Frontend| 修复 `/open_api/settings` 未返回 `domains` 数组时前端设置初始化直接调用 `map()` 报 `undefined` 错误的问题,统一按空数组兜底处理
|
||||
- fix: |Frontend| 修复前端在 `jwt` / `auth` / `adminAuth` 等 localStorage 凭据为空字符串、字面量 `"undefined"` 或包含换行/控制符时,请求构造的 `Authorization` 等头部抛出 `Invalid character in header content` 导致前端所有接口报错的问题(issue #1000)。新增 `safeHeaderValue` / `safeBearerHeader` 工具,对全部认证头做 RFC 7230 校验,不安全的值直接跳过该头部,让 worker 走标准 401 而不是请求级崩溃
|
||||
|
||||
### Improvements
|
||||
|
||||
|
||||
Reference in New Issue
Block a user