fix: check for JWT validity when attempting to decode it
All checks were successful
Update changelog / changelog (push) Successful in 26s

This commit is contained in:
2026-01-27 12:52:21 +01:00
parent 5771a182fe
commit 6114416b8b

View File

@@ -94,7 +94,10 @@ export async function createLinkHandler(
) {
// Using locals to retrieve decoded user JWT.
const decodedUser: jwt.JwtDecoded | undefined = res.locals.user?.decoded;
// jwt.JwtDecoded when JWT is supplied
// undefined if not
// null if is invalid (expired)
const decodedUser: jwt.JwtDecoded | undefined | null = res.locals.user?.decoded;
const linkService = new LinkService();
const subdomainsAllowed: boolean = env.getBool('useSubdomains', true)!;
const rewriteStrings: env.RewriteStrings = env.getRewriteStrings();
@@ -114,7 +117,7 @@ export async function createLinkHandler(
}
let user: User | null = null;
if (decodedUser !== undefined) {
if (decodedUser !== undefined && decodedUser !== null) {
// If user is logged in, retrieve the account.
const userService = new UserService();
user = await userService.findById(decodedUser.sub);