diff --git a/api/middleware/secure.js b/api/middleware/secure.js index e5e4834..18de538 100644 --- a/api/middleware/secure.js +++ b/api/middleware/secure.js @@ -7,12 +7,12 @@ const secure = jwt({ cache: true, rateLimit: true, jwksRequestsPerMinute: 5, - jwksUri: `https://${process.env.SNOWPACK_PUBLIC_AUTH0_DOMAIN}/.well-known/jwks.json`, + jwksUri: `https://${process.env.auth0Domain}/.well-known/jwks.json`, }), // Validate the audience and the issuer - audience: `https://${process.env.SNOWPACK_PUBLIC_API_DOMAIN}/`, //replace with your API's audience, available at Dashboard > APIs - issuer: `https://${process.env.SNOWPACK_PUBLIC_AUTH0_DOMAIN}/`, + audience: process.env.auth0Audience, //replace with your API's audience, available at Dashboard > APIs + issuer: `https://${process.env.auth0Domain}/`, algorithms: ["RS256"], }); diff --git a/api/serverless.yml b/api/serverless.yml index 72c1181..0d8e2eb 100644 --- a/api/serverless.yml +++ b/api/serverless.yml @@ -16,3 +16,5 @@ inputs: dbIndex1: ${output:database.indexes.gsi1.name} # A secret token to sign the JWT tokens with. tokenSecret: ${env:tokenSecret} # Change to secret via environment variable: ${env:tokenSecret} + auth0Audience: "https://${env:SNOWPACK_PUBLIC_API_DOMAIN}/" + auth0Domain: ${env:SNOWPACK_PUBLIC_AUTH0_DOMAIN} diff --git a/site/src/components/ProfileFromApi.jsx b/site/src/components/ProfileFromApi.jsx index ffc0392..c0a665a 100644 --- a/site/src/components/ProfileFromApi.jsx +++ b/site/src/components/ProfileFromApi.jsx @@ -1,5 +1,6 @@ import React, { useEffect, useState } from "react"; import { useAuth0 } from "@auth0/auth0-react"; +import config from "../config"; const ProfileFromApi = () => { const { user, isAuthenticated, getAccessTokenSilently } = useAuth0(); @@ -9,12 +10,11 @@ const ProfileFromApi = () => { const getMessage = async () => { try { const accessToken = await getAccessTokenSilently({ - audience: "https://1t8da6s66e.execute-api.us-east-1.amazonaws.com/", + audience: config.auth0.audience, scope: "read:stuff", }); - const authorizedUrl = - "https://1t8da6s66e.execute-api.us-east-1.amazonaws.com/authorized"; + const authorizedUrl = `${config.domains.api}/test-authorized/`; const authorizedResponse = await fetch(authorizedUrl, { headers: {