Skip to content

Refresh User API ​

Overview ​

The refresh-user.post.ts endpoint fetches fresh user data from the backend API using the HTTP-only auth token cookie. This allows the client to get updated user data without having direct access to the token.

Endpoint ​

Path: POST /api/auth/refresh-user

File: server/api/auth/refresh-user.post.ts

Request Body ​

No request body required. The endpoint uses the HTTP-only auth_token cookie.

Response ​

typescript
{
  success: boolean
  user: User              // Full user object with accessibleInstances
}

User Object Structure ​

typescript
{
  id: number
  email: string
  name: string
  workspace_id: string
  instance_id: number
  dealer_user_id?: number
  is_slider?: boolean
  is_backend_user?: boolean
  brand_name?: string
  url?: string
  accessibleInstances: Array<{
    instance_id: number
    workspace_id: string
    brand_name: string
    url: string
    // ... other instance fields
  }>
  // ... other user fields
}

Features ​

Token-Based Fetching ​

  • Reads auth_token from HTTP-only cookie
  • Uses token to fetch user data from backend API
  • Token never exposed to client

After fetching user data, the endpoint:

  1. Creates minimal user data for cookie
  2. Finds current workspace instance
  3. Updates auth_user cookie with minimal data
  4. Returns full user data in response (client stores accessibleInstances in localStorage)

The cookie stores minimal user data (first instance only):

typescript
{
  id, email, name,
  workspace_id, instance_id,
  dealer_user_id, is_slider, is_backend_user,
  brand_name, url,
  accessibleInstances: [firstInstance]  // Minimal fields only
}

Error Handling ​

Missing Token ​

typescript
throw createError({
  statusCode: 401,
  statusMessage: 'No authentication token found'
})

Invalid Token ​

If token is invalid (401 response from backend):

  1. Clears auth_token cookie
  2. Clears auth_user cookie
  3. Throws 401 error

Backend Errors ​

typescript
throw createError({
  statusCode: error.statusCode || 500,
  statusMessage: error.statusMessage || 'Failed to refresh user data'
})

Usage ​

typescript
const { $api } = useNuxtApp()

// Refresh user data
try {
  const response = await $api('/api/auth/refresh-user', {
    method: 'POST'
  })
  
  if (response.success) {
    const user = response.user
    
    // Store full accessibleInstances in localStorage
    if (user.accessibleInstances) {
      localStorage.setItem('accessibleInstances', JSON.stringify(user.accessibleInstances))
    }
    
    // Update auth store
    authStore.setUser(user)
  }
} catch (error) {
  if (error.statusCode === 401) {
    // Token invalid, redirect to login
    await navigateTo('/login')
  }
}

Use Cases ​

Periodic User Refresh ​

typescript
// Refresh user data every 5 minutes
setInterval(async () => {
  try {
    await $api('/api/auth/refresh-user', { method: 'POST' })
  } catch (error) {
    console.error('Failed to refresh user:', error)
  }
}, 5 * 60 * 1000)

After Workspace Switch ​

typescript
// After switching workspace, refresh user data
const switchWorkspace = async (workspaceId: string) => {
  // Switch workspace logic...
  
  // Refresh user to get updated accessibleInstances
  await $api('/api/auth/refresh-user', { method: 'POST' })
}

Security Considerations ​

  1. HTTP-Only Cookie: Token read from HTTP-only cookie
  2. Server-Side Fetch: User data fetched on server, not exposed to client
  3. Token Validation: Token validated before fetching user data
  4. Auto-Logout: Invalid tokens trigger cookie clearing
  5. Minimal Cookie Data: Only essential data stored in cookie

Backend API ​

The endpoint calls the backend API:

GET {API_BASE_URL}/user
Headers: {
  Authorization: Bearer {token}
}