Appearance
Refresh User API ​
Overview ​
The refresh-user.post.ts endpoint fetches fresh user data from the backend API using the HTTP-only auth token cookie. This allows the client to get updated user data without having direct access to the token.
Endpoint ​
Path: POST /api/auth/refresh-user
File: server/api/auth/refresh-user.post.ts
Request Body ​
No request body required. The endpoint uses the HTTP-only auth_token cookie.
Response ​
typescript
{
success: boolean
user: User // Full user object with accessibleInstances
}User Object Structure ​
typescript
{
id: number
email: string
name: string
workspace_id: string
instance_id: number
dealer_user_id?: number
is_slider?: boolean
is_backend_user?: boolean
brand_name?: string
url?: string
accessibleInstances: Array<{
instance_id: number
workspace_id: string
brand_name: string
url: string
// ... other instance fields
}>
// ... other user fields
}Features ​
Token-Based Fetching ​
- Reads
auth_tokenfrom HTTP-only cookie - Uses token to fetch user data from backend API
- Token never exposed to client
Cookie Update ​
After fetching user data, the endpoint:
- Creates minimal user data for cookie
- Finds current workspace instance
- Updates
auth_usercookie with minimal data - Returns full user data in response (client stores
accessibleInstancesin localStorage)
Minimal User Cookie ​
The cookie stores minimal user data (first instance only):
typescript
{
id, email, name,
workspace_id, instance_id,
dealer_user_id, is_slider, is_backend_user,
brand_name, url,
accessibleInstances: [firstInstance] // Minimal fields only
}Error Handling ​
Missing Token ​
typescript
throw createError({
statusCode: 401,
statusMessage: 'No authentication token found'
})Invalid Token ​
If token is invalid (401 response from backend):
- Clears
auth_tokencookie - Clears
auth_usercookie - Throws 401 error
Backend Errors ​
typescript
throw createError({
statusCode: error.statusCode || 500,
statusMessage: error.statusMessage || 'Failed to refresh user data'
})Usage ​
typescript
const { $api } = useNuxtApp()
// Refresh user data
try {
const response = await $api('/api/auth/refresh-user', {
method: 'POST'
})
if (response.success) {
const user = response.user
// Store full accessibleInstances in localStorage
if (user.accessibleInstances) {
localStorage.setItem('accessibleInstances', JSON.stringify(user.accessibleInstances))
}
// Update auth store
authStore.setUser(user)
}
} catch (error) {
if (error.statusCode === 401) {
// Token invalid, redirect to login
await navigateTo('/login')
}
}Use Cases ​
Periodic User Refresh ​
typescript
// Refresh user data every 5 minutes
setInterval(async () => {
try {
await $api('/api/auth/refresh-user', { method: 'POST' })
} catch (error) {
console.error('Failed to refresh user:', error)
}
}, 5 * 60 * 1000)After Workspace Switch ​
typescript
// After switching workspace, refresh user data
const switchWorkspace = async (workspaceId: string) => {
// Switch workspace logic...
// Refresh user to get updated accessibleInstances
await $api('/api/auth/refresh-user', { method: 'POST' })
}Security Considerations ​
- HTTP-Only Cookie: Token read from HTTP-only cookie
- Server-Side Fetch: User data fetched on server, not exposed to client
- Token Validation: Token validated before fetching user data
- Auto-Logout: Invalid tokens trigger cookie clearing
- Minimal Cookie Data: Only essential data stored in cookie
Backend API ​
The endpoint calls the backend API:
GET {API_BASE_URL}/user
Headers: {
Authorization: Bearer {token}
}Related Documentation ​
- Set Session - Store authentication token
- Get Session - Get session status
- Authentication - Authentication system