♻️(frontend) switch to Authorization Code flow

Instead of interacting with Keycloak, the frontend navigate to the
/authenticate endpoint, which starts the Authorization code flow.

When the flow is done, the backend redirect back to the SPA,
passing a session cookie and a csrf cookie.

Done:
- Query GET user/me to determine if user is authenticated yet
- Remove Keycloak js dependency, as all the OIDC logic is handled by the backend
- Store user's data instead of the JWT token
This commit is contained in:
Lebaud Antoine
2024-02-14 23:47:43 +01:00
committed by aleb_the_flash
parent 38c4d33791
commit 4cacfd3a45
13 changed files with 87 additions and 97 deletions

View File

@@ -39,7 +39,6 @@
"fetch-mock": "9.11.0",
"jest": "29.7.0",
"jest-environment-jsdom": "29.7.0",
"keycloak-js": "23.0.6",
"node-fetch": "2.7.0",
"prettier": "3.2.5",
"stylelint": "16.2.1",