From f396864feb6831b1dc0cfdd8dcf9a05e42879f8e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Fri, 23 Dec 2022 11:25:55 +0100 Subject: [PATCH 01/24] Fix newsletter form subscription --- src/components/molecules/EmailForm.svelte | 7 +++++-- src/utils/forms/subscribe.ts | 6 +++--- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/src/components/molecules/EmailForm.svelte b/src/components/molecules/EmailForm.svelte index 181cae0..6ce88cc 100644 --- a/src/components/molecules/EmailForm.svelte +++ b/src/components/molecules/EmailForm.svelte @@ -4,6 +4,7 @@ diff --git a/src/routes/api/newsletter/+server.ts b/src/routes/api/newsletter/+server.ts index 5ac5600..4f7070b 100644 --- a/src/routes/api/newsletter/+server.ts +++ b/src/routes/api/newsletter/+server.ts @@ -3,9 +3,8 @@ import type { RequestHandler } from './$types' import { error } from '@sveltejs/kit' export const POST = (async ({ request, fetch }) => { - const data = await request.json() + const data: { email: string } = await request.json() const { email } = data - console.log('server:', data, email) // No email if (!email) { @@ -16,25 +15,28 @@ export const POST = (async ({ request, fetch }) => { throw error(400, { message: 'INVALID_EMAIL' }) } - // Newsletter API request - const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { - method: 'POST', - headers: { 'content-type': 'application/json' }, - body: JSON.stringify({ - api_key: NEWSLETTER_API_TOKEN, - email_address: email, - }) - }) - const res = await req.json() - console.log('server:', res) - - // Other error - if (res && res.status !== 'PENDING') { - throw error(400, { message: res.error.code }) - } - return new Response(JSON.stringify({ - success: true, - message: res.status, + email, })) + + // // Newsletter API request + // const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { + // method: 'POST', + // headers: { 'Content-Type': 'application/json' }, + // body: JSON.stringify({ + // api_key: NEWSLETTER_API_TOKEN, + // email_address: email, + // }) + // }) + // const res = await req.json() + + // // Other error + // if (res && res.status !== 'PENDING') { + // throw error(400, { message: res.error.code }) + // } + + // return new Response(JSON.stringify({ + // success: true, + // message: res.status, + // })) }) satisfies RequestHandler \ No newline at end of file From a2afd38fda8a0814af81763949cca78b535b6f19 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 15:25:54 +0100 Subject: [PATCH 14/24] Try returning json via SK --- src/components/molecules/EmailForm.svelte | 18 +++++----- src/routes/api/newsletter/+server.ts | 43 +++++++++++------------ 2 files changed, 30 insertions(+), 31 deletions(-) diff --git a/src/components/molecules/EmailForm.svelte b/src/components/molecules/EmailForm.svelte index 397da17..e3da1b9 100644 --- a/src/components/molecules/EmailForm.svelte +++ b/src/components/molecules/EmailForm.svelte @@ -45,16 +45,16 @@ }) const result: FormStatus = await req.json() formStatus = result - console.log(result) + console.log('SK api response:', result) - // // If successful - // if (formStatus.success) { - // sendEvent('newsletterSubscribe') - // } else { - // // Hide message for errors - // clearTimeout(formMessageTimeout) - // formMessageTimeout = requestAnimationFrame(() => setTimeout(() => formStatus = null, 4000)) - // } + // If successful + if (formStatus.success) { + sendEvent('newsletterSubscribe') + } else { + // Hide message for errors + clearTimeout(formMessageTimeout) + formMessageTimeout = requestAnimationFrame(() => setTimeout(() => formStatus = null, 4000)) + } } } diff --git a/src/routes/api/newsletter/+server.ts b/src/routes/api/newsletter/+server.ts index 4f7070b..ff01efa 100644 --- a/src/routes/api/newsletter/+server.ts +++ b/src/routes/api/newsletter/+server.ts @@ -1,6 +1,6 @@ import { NEWSLETTER_API_TOKEN, NEWSLETTER_LIST_ID } from '$env/static/private' import type { RequestHandler } from './$types' -import { error } from '@sveltejs/kit' +import { error, json } from '@sveltejs/kit' export const POST = (async ({ request, fetch }) => { const data: { email: string } = await request.json() @@ -15,28 +15,27 @@ export const POST = (async ({ request, fetch }) => { throw error(400, { message: 'INVALID_EMAIL' }) } - return new Response(JSON.stringify({ - email, - })) + // return json(email) - // // Newsletter API request - // const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { - // method: 'POST', - // headers: { 'Content-Type': 'application/json' }, - // body: JSON.stringify({ - // api_key: NEWSLETTER_API_TOKEN, - // email_address: email, - // }) - // }) - // const res = await req.json() + // Newsletter API request + const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { + method: 'POST', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({ + api_key: NEWSLETTER_API_TOKEN, + email_address: email, + }) + }) + const res = await req.json() + console.log('server API response:', res) - // // Other error - // if (res && res.status !== 'PENDING') { - // throw error(400, { message: res.error.code }) - // } + // Other error + if (res && res.status !== 'PENDING') { + throw error(400, { message: res.error.code }) + } - // return new Response(JSON.stringify({ - // success: true, - // message: res.status, - // })) + return json({ + success: true, + message: res.status, + }) }) satisfies RequestHandler \ No newline at end of file From 3e1b3be2ba6b5dc4696bb49be6c7dfe92cd50bc4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 15:34:51 +0100 Subject: [PATCH 15/24] Disable csrf? --- svelte.config.js | 3 +++ 1 file changed, 3 insertions(+) diff --git a/svelte.config.js b/svelte.config.js index 0c9a3f4..03e6d17 100644 --- a/svelte.config.js +++ b/svelte.config.js @@ -17,6 +17,9 @@ const config = { }), kit: { + csrf: { + checkOrigin: false + }, adapter: adapter({ edge: true }), From 4f97e8bc8e768a09f5e1fca7c4e780154ddb5bd4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 15:42:03 +0100 Subject: [PATCH 16/24] Just return a json response --- src/routes/api/newsletter/+server.ts | 38 ++++++++++++++-------------- 1 file changed, 19 insertions(+), 19 deletions(-) diff --git a/src/routes/api/newsletter/+server.ts b/src/routes/api/newsletter/+server.ts index ff01efa..1fea22f 100644 --- a/src/routes/api/newsletter/+server.ts +++ b/src/routes/api/newsletter/+server.ts @@ -15,27 +15,27 @@ export const POST = (async ({ request, fetch }) => { throw error(400, { message: 'INVALID_EMAIL' }) } - // return json(email) + return json(email) // Newsletter API request - const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { - method: 'POST', - headers: { 'Content-Type': 'application/json' }, - body: JSON.stringify({ - api_key: NEWSLETTER_API_TOKEN, - email_address: email, - }) - }) - const res = await req.json() - console.log('server API response:', res) + // const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { + // method: 'POST', + // headers: { 'Content-Type': 'application/json' }, + // body: JSON.stringify({ + // api_key: NEWSLETTER_API_TOKEN, + // email_address: email, + // }) + // }) + // const res = await req.json() + // console.log('server API response:', res) - // Other error - if (res && res.status !== 'PENDING') { - throw error(400, { message: res.error.code }) - } + // // Other error + // if (res && res.status !== 'PENDING') { + // throw error(400, { message: res.error.code }) + // } - return json({ - success: true, - message: res.status, - }) + // return json({ + // success: true, + // message: res.status, + // }) }) satisfies RequestHandler \ No newline at end of file From fd652da00aa948fbff228b5fddca076b711b1733 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 15:53:58 +0100 Subject: [PATCH 17/24] Always return json response and not error? --- src/routes/api/newsletter/+server.ts | 44 ++++++++++++++-------------- 1 file changed, 22 insertions(+), 22 deletions(-) diff --git a/src/routes/api/newsletter/+server.ts b/src/routes/api/newsletter/+server.ts index 1fea22f..b96b34a 100644 --- a/src/routes/api/newsletter/+server.ts +++ b/src/routes/api/newsletter/+server.ts @@ -1,6 +1,6 @@ import { NEWSLETTER_API_TOKEN, NEWSLETTER_LIST_ID } from '$env/static/private' import type { RequestHandler } from './$types' -import { error, json } from '@sveltejs/kit' +import { json } from '@sveltejs/kit' export const POST = (async ({ request, fetch }) => { const data: { email: string } = await request.json() @@ -8,34 +8,34 @@ export const POST = (async ({ request, fetch }) => { // No email if (!email) { - throw error(400, { message: 'NO_EMAIL' }) + return json({ message: 'NO_EMAIL' }) } // Invalid email if (!email.match(/^[a-zA-Z0-9.!#$%&’*+/=?^_`{|}~-]+@[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)*$/)) { - throw error(400, { message: 'INVALID_EMAIL' }) + return json({ message: 'INVALID_EMAIL' }) } - return json(email) + // return json(email) // Newsletter API request - // const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { - // method: 'POST', - // headers: { 'Content-Type': 'application/json' }, - // body: JSON.stringify({ - // api_key: NEWSLETTER_API_TOKEN, - // email_address: email, - // }) - // }) - // const res = await req.json() - // console.log('server API response:', res) + const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { + method: 'POST', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({ + api_key: NEWSLETTER_API_TOKEN, + email_address: email, + }) + }) + const res = await req.json() + console.log('server API response:', res) - // // Other error - // if (res && res.status !== 'PENDING') { - // throw error(400, { message: res.error.code }) - // } + // Other error + if (res && res.status !== 'PENDING') { + return json({ message: res.error.code }) + } - // return json({ - // success: true, - // message: res.status, - // }) + return json({ + success: true, + message: res.status, + }) }) satisfies RequestHandler \ No newline at end of file From 0e4b8edd43ec5f107d21f13fe4e1620623ecf413 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 15:58:05 +0100 Subject: [PATCH 18/24] Is it CORS? --- vercel.json | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/vercel.json b/vercel.json index 9f9f663..b0e447d 100644 --- a/vercel.json +++ b/vercel.json @@ -1,5 +1,14 @@ { "headers": [ + { + "source": "/api/(.*)", + "headers": [ + { "key": "Access-Control-Allow-Credentials", "value": "true" }, + { "key": "Access-Control-Allow-Origin", "value": "*" }, + { "key": "Access-Control-Allow-Methods", "value": "GET,OPTIONS,PATCH,DELETE,POST,PUT" }, + { "key": "Access-Control-Allow-Headers", "value": "X-CSRF-Token, X-Requested-With, Accept, Accept-Version, Content-Length, Content-MD5, Content-Type, Date, X-Api-Version" } + ] + }, { "source": "/(.*)", "headers": [ From d23eac3bc42306d858675e67bb569f61f12cd8b9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 16:01:05 +0100 Subject: [PATCH 19/24] CORS everywhere? --- vercel.json | 15 +++++---------- 1 file changed, 5 insertions(+), 10 deletions(-) diff --git a/vercel.json b/vercel.json index b0e447d..b45a653 100644 --- a/vercel.json +++ b/vercel.json @@ -1,14 +1,5 @@ { "headers": [ - { - "source": "/api/(.*)", - "headers": [ - { "key": "Access-Control-Allow-Credentials", "value": "true" }, - { "key": "Access-Control-Allow-Origin", "value": "*" }, - { "key": "Access-Control-Allow-Methods", "value": "GET,OPTIONS,PATCH,DELETE,POST,PUT" }, - { "key": "Access-Control-Allow-Headers", "value": "X-CSRF-Token, X-Requested-With, Accept, Accept-Version, Content-Length, Content-MD5, Content-Type, Date, X-Api-Version" } - ] - }, { "source": "/(.*)", "headers": [ @@ -17,7 +8,11 @@ { "key": "X-XSS-Protection", "value": "1; mode=block" }, { "key": "Strict-Transport-Security", "value": "max-age=31536000; includeSubDomains; preload" }, { "key": "Referrer-Policy", "value": "no-referrer-when-downgrade" }, - { "key": "Feature-Policy", "value": "geolocation 'self'" } + { "key": "Feature-Policy", "value": "geolocation 'self'" }, + { "key": "Access-Control-Allow-Credentials", "value": "true" }, + { "key": "Access-Control-Allow-Origin", "value": "*" }, + { "key": "Access-Control-Allow-Methods", "value": "GET,OPTIONS,PATCH,DELETE,POST,PUT" }, + { "key": "Access-Control-Allow-Headers", "value": "X-CSRF-Token, X-Requested-With, Accept, Accept-Version, Content-Length, Content-MD5, Content-Type, Date, X-Api-Version" } ] }, { From ab965574e78802cc2cc26a4f03ec60331d76ac3d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 16:01:16 +0100 Subject: [PATCH 20/24] Try catch the request --- src/routes/api/newsletter/+server.ts | 27 +++++++++++++++++---------- 1 file changed, 17 insertions(+), 10 deletions(-) diff --git a/src/routes/api/newsletter/+server.ts b/src/routes/api/newsletter/+server.ts index b96b34a..c4913e7 100644 --- a/src/routes/api/newsletter/+server.ts +++ b/src/routes/api/newsletter/+server.ts @@ -26,16 +26,23 @@ export const POST = (async ({ request, fetch }) => { email_address: email, }) }) - const res = await req.json() - console.log('server API response:', res) - // Other error - if (res && res.status !== 'PENDING') { - return json({ message: res.error.code }) + try { + if (req.ok) { + const res = await req.json() + console.log('server API response:', res) + + // Other error + if (res && res.status !== 'PENDING') { + return json({ message: res.error.code }) + } + + return json({ + success: true, + message: res.status, + }) + } + } catch (err) { + console.error(err) } - - return json({ - success: true, - message: res.status, - }) }) satisfies RequestHandler \ No newline at end of file From 5af12a39d70443d13428c1d624a6372f51a361d9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 16:05:16 +0100 Subject: [PATCH 21/24] Return Response --- src/routes/api/newsletter/+server.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/routes/api/newsletter/+server.ts b/src/routes/api/newsletter/+server.ts index c4913e7..1ce6da5 100644 --- a/src/routes/api/newsletter/+server.ts +++ b/src/routes/api/newsletter/+server.ts @@ -37,9 +37,11 @@ export const POST = (async ({ request, fetch }) => { return json({ message: res.error.code }) } - return json({ + return new Response(JSON.stringify({ success: true, message: res.status, + }), { + status: 200 }) } } catch (err) { From f0018bead374da7bc49689de55d32977d0ffcab8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 16:08:09 +0100 Subject: [PATCH 22/24] Return Responses --- src/routes/api/newsletter/+server.ts | 38 ++++++++++------------------ 1 file changed, 14 insertions(+), 24 deletions(-) diff --git a/src/routes/api/newsletter/+server.ts b/src/routes/api/newsletter/+server.ts index 1ce6da5..1297d73 100644 --- a/src/routes/api/newsletter/+server.ts +++ b/src/routes/api/newsletter/+server.ts @@ -1,6 +1,5 @@ import { NEWSLETTER_API_TOKEN, NEWSLETTER_LIST_ID } from '$env/static/private' import type { RequestHandler } from './$types' -import { json } from '@sveltejs/kit' export const POST = (async ({ request, fetch }) => { const data: { email: string } = await request.json() @@ -8,15 +7,13 @@ export const POST = (async ({ request, fetch }) => { // No email if (!email) { - return json({ message: 'NO_EMAIL' }) + return new Response(JSON.stringify({ message: 'NO_EMAIL' }), { status: 400 }) } // Invalid email if (!email.match(/^[a-zA-Z0-9.!#$%&’*+/=?^_`{|}~-]+@[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)*$/)) { - return json({ message: 'INVALID_EMAIL' }) + return new Response(JSON.stringify({ message: 'INVALID_EMAIL' }), { status: 400 }) } - // return json(email) - // Newsletter API request const req = await fetch(`https://emailoctopus.com/api/1.6/lists/${NEWSLETTER_LIST_ID}/contacts`, { method: 'POST', @@ -26,25 +23,18 @@ export const POST = (async ({ request, fetch }) => { email_address: email, }) }) + const res = await req.json() + console.log('server API response:', res) - try { - if (req.ok) { - const res = await req.json() - console.log('server API response:', res) - - // Other error - if (res && res.status !== 'PENDING') { - return json({ message: res.error.code }) - } - - return new Response(JSON.stringify({ - success: true, - message: res.status, - }), { - status: 200 - }) - } - } catch (err) { - console.error(err) + // Other error + if (res && res.status !== 'PENDING') { + return new Response(JSON.stringify({ message: res.error.code }), { status: 400 }) } + + return new Response(JSON.stringify({ + success: true, + message: res.status, + }), { + status: 200 + }) }) satisfies RequestHandler \ No newline at end of file From 0a5261b0df5628b3e9ec6cc93bfa11920d8fd817 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 16:31:20 +0100 Subject: [PATCH 23/24] Is it the Edge? --- svelte.config.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/svelte.config.js b/svelte.config.js index 03e6d17..a577b53 100644 --- a/svelte.config.js +++ b/svelte.config.js @@ -21,7 +21,7 @@ const config = { checkOrigin: false }, adapter: adapter({ - edge: true + // edge: true }), alias: { $components: 'src/components', From c5803ae046036d3e8ec601bbad5295dbbcf76ada Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fe=CC=81lix=20Pe=CC=81ault?= Date: Sun, 25 Dec 2022 16:37:53 +0100 Subject: [PATCH 24/24] Put back CSRF --- svelte.config.js | 3 --- 1 file changed, 3 deletions(-) diff --git a/svelte.config.js b/svelte.config.js index a577b53..79e8b44 100644 --- a/svelte.config.js +++ b/svelte.config.js @@ -17,9 +17,6 @@ const config = { }), kit: { - csrf: { - checkOrigin: false - }, adapter: adapter({ // edge: true }),