Skip to content

fix(invoices): auth for print/PDF in new tabs - #69

Merged
prit-007 merged 1 commit into
mainfrom
fix/invoice-token-url
Oct 10, 2026
Merged

prit-007 merged 1 commit into
mainfrom
fix/invoice-token-url

Conversation

@prit-007

Copy link
Copy Markdown
Collaborator

New-tab print/PDF links couldn't send the Bearer header -> 401. Accept a ?token= query param (stripped before logging) and append it client-side. Verified 200/application/pdf. Lint clean.

window.open cannot carry an Authorization header, so the invoice print/PDF
endpoints returned 401. Now:
- server: attachTokenFromQuery middleware lifts a ?token= query param into the
  Bearer header (stripped before the request is processed/logged); mounted on
  the /invoices router before auth.
- frontend: AdminInvoices appends getAuthToken() to the print/pdf URLs;
  getAuthToken exported from services/api.
Verified: print -> 200, pdf -> 200 application/pdf with ?token=; access logs
are written to server/logs/info-*.log. Lint clean; no test impact.
@prit-007
prit-007 merged commit 600792d into main Oct 10, 2026
3 checks passed
@prit-007
prit-007 deleted the fix/invoice-token-url branch October 10, 2026 19:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant