How to redirect from GraphQL middleware resolver on authentication fail?

Viewed 148

Introduction: I am using GraphQL Mesh as a gateway between my app and an API. I use Apollo Client as the GraphQL client. When a user wants to visit the first screen after hitting the log-in button, I do a query to load data from a CMS. This query has to go through the gateway. In the gateway I do an auth check to see if the user has a valid JTW access token, if not, I want to redirect back to the sign-in page. If the user has a token, he is let through.

The gateway is-auth.ts resolver:

    const header = context.headers.authorization;

    if (typeof header === "undefined") {
      return new Error("Unauthorized: no access token found.");
    } else {
      const token = header.split(" ")[1];

      if (token) {
        try {
          const user = jwt.verify(token, process.env.JWT_SECRET as string);
        } catch (error) {
          return new Error("Unauthorized: " + error);
        }
      } else {
        return new Error("Unauthorized: no access token found.");
      }
    }
    return next(root, args, context, info);
  },

Problem: Right now, I am returning Errors in the authentication resolver of the gateway, hoping that I could pick them up in the error object that is sent to Apollo Client and then redirect off of that. Unfortunately, I don't get that option, since the Errors are thrown immediately, resulting in an error screen for the user (not what I want). I was hoping this would work in order to redirect to the sign-in from the client-side, but it does not work:

const { data, error } = await apolloClient(accessToken).query({
    query: gql`
      query {
        ...where my query is.
      }
    `,
  });

  if (error) {
    return {
      redirect: {
        permanent: false,
        destination: `/sign-in`,
      },
    };
  }

Does anyone perhaps have a solution to this problem?

This is the GraphQL Mesh documentation on the auth resolver, for anyone that wants to see it: https://www.graphql-mesh.com/docs/transforms/resolvers-composition. Unfortunately, it doesn't say anything about redirects.

Kind regards.

0 Answers
Related