summaryrefslogtreecommitdiff
path: root/hooks/use-next-auth-reauth.ts
blob: 6c17ddaed39a93fd7555ccf73a784faa629ea3d6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
// hooks/use-next-auth-reauth.ts
"use client"

import * as React from "react"
import { useSession } from "next-auth/react"

interface UseNextAuthReAuthOptions {
  // 재인증 유효 시간 (밀리초, 기본값: 5분)
  validDuration?: number
  // 재인증이 필요한지 여부
  requireReAuth?: boolean
}

export function useNextAuthReAuth(options: UseNextAuthReAuthOptions = {}) {
  const { validDuration = 5 * 60 * 1000, requireReAuth = true } = options
  const { data: session, status, update } = useSession()
  
  const [showReAuthModal, setShowReAuthModal] = React.useState(false)
  const [isLoading, setIsLoading] = React.useState(true)

  // 재인증이 필요한지 확인
  const isAuthenticated = React.useMemo(() => {
    if (!session || !requireReAuth) {
      return status === "authenticated"
    }

    // JWT 토큰에서 재인증 시간 확인
    const reAuthTime = session.user?.reAuthTime
    if (!reAuthTime) return false

    const now = Date.now()
    return (now - reAuthTime) < validDuration
  }, [session, requireReAuth, validDuration, status])

  React.useEffect(() => {
    if (status === "loading") return

    if (status === "unauthenticated") {
      setIsLoading(false)
      return
    }

    if (requireReAuth && !isAuthenticated) {
      setShowReAuthModal(true)
    }
    
    setIsLoading(false)
  }, [status, requireReAuth, isAuthenticated])

  const handleReAuthSuccess = React.useCallback(async () => {
    // 세션 업데이트 (재인증 시간 포함)
    await update({
      reAuthTime: Date.now()
    })
    setShowReAuthModal(false)
  }, [update])

  const forceReAuth = React.useCallback(async () => {
    // 재인증 강제 실행
    await update({
      reAuthTime: null
    })
    setShowReAuthModal(true)
  }, [update])

  return {
    isAuthenticated,
    showReAuthModal,
    isLoading,
    userEmail: session?.user?.email || "",
    handleReAuthSuccess,
    forceReAuth,
    sessionStatus: status,
    session,
  }
}