Remove unused /api/client/sso route (replaced by server-side ticket generation)

This commit is contained in:
openhands committed 2026-07-09 19:11:10 +02:00
1 parent 7fe3220359
commit 0ac3e4353a
1 file changed
-33
-33
View File
@@ -1,33 +0,0 @@
import { headers } from "next/headers";
import { auth } from "@/lib/auth";
import { prisma } from "@/lib/prisma";
import { clientIp, rateLimit } from "@/lib/rate-limit";
import { siteSettings } from "@/lib/services/site-settings";
import { issueSsoTicket } from "@/lib/auth/sso-ticket";
export const dynamic = "force-dynamic";
export async function GET() {
const session = await auth();
if (!session?.user?.id) {
return new Response(JSON.stringify({ error: "Unauthorized" }), { status: 401 });
}
const userId = Number(session.user.id);
// Throttle SSO ticket generation (5 per 30s per user) — prevent ticket spam.
if (!(await rateLimit(`sso:${userId}`, 5, 30_000)).ok) {
return new Response(JSON.stringify({ error: "Rate limited" }), { status: 429 });
}
const [hotelName, clientUrl] = await Promise.all([
siteSettings.get("hotel_name", "Atom"),
siteSettings.get("nitro_client_url", ""),
]);
const ip = await clientIp();
const ticket = await issueSsoTicket(prisma, userId, hotelName ?? "Atom", ip);
return Response.json({ ticket, hotelName: hotelName ?? "Atom", clientUrl });
}