diff --git a/src/init/axios-init.ts b/src/init/axios-init.ts index d69f73a..53be517 100644 --- a/src/init/axios-init.ts +++ b/src/init/axios-init.ts @@ -39,6 +39,16 @@ axios.interceptors.request.use( config.headers['Authorization'] = `Bearer ${token}` } + // Varsayılan application/json, FormData ile giderse sunucu [FromForm] alanları bağlayamaz. + if (config.data instanceof FormData) { + const h = config.headers as any + if (typeof h?.delete === 'function') { + h.delete('Content-Type') + } + delete h?.['Content-Type'] + delete h?.['content-type'] + } + return config }, function (error) { diff --git a/src/module/auth/views/Login.vue b/src/module/auth/views/Login.vue index 4541a7e..9e6d65e 100644 --- a/src/module/auth/views/Login.vue +++ b/src/module/auth/views/Login.vue @@ -58,11 +58,12 @@ import router from '@/router' import GuestLayout from '@/layouts/GuestLayout.vue' + import { withEncodedPasswords } from '@/utils/passwordCrypto' const Login = async () => { if (authValidationStore.FormCheck()) { let login = await dataStore.dataPost('Auth/login', { - data: authStore.loginData + data: withEncodedPasswords(authStore.loginData, ['password']) }) Object.assign(authStore.loginData, authStore.safeLoginData) if (login !== 'errorfalse') { diff --git a/src/module/auth/views/Register.vue b/src/module/auth/views/Register.vue index 86c7272..1e8bf13 100644 --- a/src/module/auth/views/Register.vue +++ b/src/module/auth/views/Register.vue @@ -363,6 +363,8 @@ const uyeBilgileriStore = useUyeBilgileriStore() uyeBilgileriStore.ResetStore() + import { withEncodedPasswords } from '@/utils/passwordCrypto' + const kvkkCheck = ref([ { label: '', @@ -413,7 +415,7 @@ const handRegister = async () => { if (uyeBilgileriStore.FormCheck()) { const register: any = await dataStore.dataPost('Auth/register', { - data: uyeBilgileriStore.formData + data: withEncodedPasswords(uyeBilgileriStore.formData, ['password', 'confirmPassword']) }) if (register !== 'errorfalse') { diff --git a/src/module/kullanicilar/components/form/FormSifreDegistir.vue b/src/module/kullanicilar/components/form/FormSifreDegistir.vue index 10bc1e5..5ed8f9b 100644 --- a/src/module/kullanicilar/components/form/FormSifreDegistir.vue +++ b/src/module/kullanicilar/components/form/FormSifreDegistir.vue @@ -42,6 +42,7 @@ import { ref, reactive } from 'vue' import { useDataStore } from '@/stores/dataStore' const dataStore = useDataStore() + import { withEncodedPasswords } from '@/utils/passwordCrypto' import { useValidationStore } from '@/stores/validationStore' const validationStore = useValidationStore() import { useUsersStore } from '@/stores/usersStore' @@ -103,7 +104,7 @@ if (FormCheck()) { let res: any res = await dataStore.dataPost('Auth/updatepassword/', { - data: formData + data: withEncodedPasswords(formData, ['currentPassword', 'newPassword', 'confirmNewPassword']) }) if (res !== 'errorfalse') { diff --git a/src/module/uyeler/components/form/FormUyeBilgileri.vue b/src/module/uyeler/components/form/FormUyeBilgileri.vue index aa01d8c..1c4f2de 100644 --- a/src/module/uyeler/components/form/FormUyeBilgileri.vue +++ b/src/module/uyeler/components/form/FormUyeBilgileri.vue @@ -407,6 +407,7 @@ const route = useRoute() import { useDataStore } from '@/stores/dataStore' const dataStore = useDataStore() + import { withEncodedPasswords } from '@/utils/passwordCrypto' import { useUsersStore } from '@/stores/usersStore' const usersStore = useUsersStore() import { useGlobalStore } from '@/stores/globalStore' @@ -479,7 +480,7 @@ uyeBilgileriStore.formData.parentUserId = usersStore.userId register = await dataStore.dataPost('Auth/register', { - data: uyeBilgileriStore.formData + data: withEncodedPasswords(uyeBilgileriStore.formData, ['password', 'confirmPassword']) }) } else { register = await dataStore.dataPut( diff --git a/src/utils/passwordCrypto.ts b/src/utils/passwordCrypto.ts new file mode 100644 index 0000000..0302a74 --- /dev/null +++ b/src/utils/passwordCrypto.ts @@ -0,0 +1,41 @@ +// Parola transport kodlamasi. +// Parolalarin istek govdesinde DUZ METIN gorunmesini engellemek icin Base64 ile kodlanir. +// Backend "b64:" on ekini gorunce cozer. (Not: Bu HTTPS/TLS'in yerini tutmaz, ek bir gizleme katmanidir.) + +const PREFIX = 'b64:' + +/** + * Verilen parolayi UTF-8 guvenli sekilde Base64'e kodlar ve "b64:" on eki ekler. + * Bos/null/undefined degerler oldugu gibi (bos string) donulur. + */ +export function encodePassword(value: string | null | undefined): string { + if (value === null || value === undefined || value === '') return '' + + const bytes = new TextEncoder().encode(String(value)) + let binary = '' + bytes.forEach((b) => { + binary += String.fromCharCode(b) + }) + + return PREFIX + btoa(binary) +} + +/** + * Verilen nesnenin sig kopyasini olusturur ve belirtilen alanlari encode eder. + * Reactive store nesnelerini bozmamak icin daima yeni bir nesne doner. + */ +export function withEncodedPasswords>( + data: T, + fields: string[] +): T { + const clone: Record = { ...data } + + fields.forEach((field) => { + const current = clone[field] + if (current !== null && current !== undefined && current !== '') { + clone[field] = encodePassword(current) + } + }) + + return clone as T +}