Repository navigation
Conversation
…o-calculation Implement scoring metrics and golden alignment tooling
…uirements Align angles export precision and enhance rule validation
…e_test.dart-xsm3gt Fix python baseline CLI arguments for golden test
…e_test.dart-zl7cq0 Fix Windows compatibility for golden test
…e_test.dart Fix python baseline CLI arguments for golden test
docs: rewrite agents guide in chinese
…are_test.dart Fix golden comparison test to use PoseSeries
…n-cli Fix hybrid processing guard and metric parsing
…n-cli Normalize evidence entries before export
…x-type-casting-issues-in-cli-jmoi3s
…ions-in-cli Add CI assertions, cue enrichment, and overlay export
…/implement-built-in-assertions-in-cli-emr2lj
docs: add Chinese project collaboration guide
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const tokens = await authService.login(input); | ||
|
|
||
| // Sign JWT tokens | ||
| const accessToken = request.server.jwt.sign( | ||
| { sub: tokens.accessToken, type: 'access' }, | ||
| { expiresIn: '15m' } |
There was a problem hiding this comment.
Sign JWT with user id instead of serialized payload
The controller signs access tokens using request.server.jwt.sign({ sub: tokens.accessToken, … }), but AuthService.generateAccessToken already returns a JSON string containing { sub: userId, email, type: 'access' }. As a result the emitted JWT has its sub claim set to that JSON blob rather than the user’s id. The new auth.middleware later treats decoded.sub as a user id and attaches it to request.userId, which will now be the serialized payload and will not match any database id, breaking any authenticated route that relies on request.userId. The controller should sign with the actual userId (and optionally include email) or let generateAccessToken return the final JWT string instead.
Useful? React with 👍 / 👎.
No description provided.