Skip to content

Commit 2338991

Browse files
nicokempelarbish
andauthored
fix(cookies): guard writes when response headers already sent (#525)
Co-authored-by: Baptiste Leproux <[email protected]>
1 parent 52f2a18 commit 2338991

File tree

3 files changed

+33
-17
lines changed

3 files changed

+33
-17
lines changed

src/runtime/plugins/supabase.server.ts

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
import { createServerClient, parseCookieHeader } from '@supabase/ssr'
2-
import { getHeader, setCookie } from 'h3'
2+
import { getHeader } from 'h3'
33
import type { SupabaseClient } from '@supabase/supabase-js'
44
import { fetchWithRetry } from '../utils/fetch-retry'
5+
import { setCookies } from '../utils/cookies'
56
import { serverSupabaseUser, serverSupabaseSession } from '../server/services'
67
import { useSupabaseSession } from '../composables/useSupabaseSession'
78
import { useSupabaseUser } from '../composables/useSupabaseUser'
@@ -21,13 +22,7 @@ export default defineNuxtPlugin({
2122
...clientOptions,
2223
cookies: {
2324
getAll: () => parseCookieHeader(getHeader(event, 'Cookie') ?? ''),
24-
setAll: (
25-
cookies: {
26-
name: string
27-
value: string
28-
options: CookieOptions
29-
}[],
30-
) => cookies.forEach(({ name, value, options }) => setCookie(event, name, value, options)),
25+
setAll: (cookies: { name: string, value: string, options: CookieOptions }[]) => setCookies(event, cookies),
3126
},
3227
cookieOptions: {
3328
...cookieOptions,

src/runtime/server/services/serverSupabaseClient.ts

Lines changed: 5 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,9 @@
11
import type { SupabaseClient } from '@supabase/supabase-js'
2-
import { createServerClient, parseCookieHeader, type CookieOptions } from '@supabase/ssr'
3-
import { getHeader, setCookie, type H3Event } from 'h3'
2+
import { createServerClient, parseCookieHeader } from '@supabase/ssr'
3+
import { getHeader, type H3Event } from 'h3'
44
import { fetchWithRetry } from '../../utils/fetch-retry'
5+
import { setCookies } from '../../utils/cookies'
6+
import type { CookieOptions } from '#app'
57
import { useRuntimeConfig } from '#imports'
68
// @ts-expect-error - `#supabase/database` is a runtime alias
79
import type { Database } from '#supabase/database'
@@ -17,13 +19,7 @@ export const serverSupabaseClient: <T = Database>(event: H3Event) => Promise<Sup
1719
auth,
1820
cookies: {
1921
getAll: () => parseCookieHeader(getHeader(event, 'Cookie') ?? ''),
20-
setAll: (
21-
cookies: {
22-
name: string
23-
value: string
24-
options: CookieOptions
25-
}[],
26-
) => cookies.forEach(({ name, value, options }) => setCookie(event, name, value, options)),
22+
setAll: (cookies: { name: string, value: string, options: CookieOptions }[]) => setCookies(event, cookies),
2723
},
2824
cookieOptions: {
2925
...cookieOptions,

src/runtime/utils/cookies.ts

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
import { setCookie, type H3Event } from 'h3'
2+
import type { CookieOptions } from '#app'
3+
4+
export function setCookies(
5+
event: H3Event,
6+
cookies: {
7+
name: string
8+
value: string
9+
options: CookieOptions
10+
}[],
11+
) {
12+
const response = event.node.res
13+
const headersWritable = () => !response.headersSent && !response.writableEnded
14+
15+
if (!headersWritable()) {
16+
return
17+
}
18+
19+
for (const { name, value, options } of cookies) {
20+
if (!headersWritable()) {
21+
break
22+
}
23+
setCookie(event, name, value, options)
24+
}
25+
}

0 commit comments

Comments
 (0)