From eda9c17116243df6c3aaebc2c1fac04f06487210 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 26 Aug 2025 15:39:59 +0000 Subject: [PATCH] Fix CORS error by removing [Authorize] from auth user endpoint Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> --- Server/Controllers/AuthController.cs | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/Server/Controllers/AuthController.cs b/Server/Controllers/AuthController.cs index 70ce71d..f03dcf5 100644 --- a/Server/Controllers/AuthController.cs +++ b/Server/Controllers/AuthController.cs @@ -56,13 +56,21 @@ namespace ShiftScheduler.Server.Controllers } [HttpGet("user")] - [Authorize] public IActionResult GetUser() { - var emailClaim = User.FindFirst(ClaimTypes.Email) ?? - User.FindFirst("email"); + if (User.Identity?.IsAuthenticated == true) + { + var emailClaim = User.FindFirst(ClaimTypes.Email) ?? + User.FindFirst("email"); + + // Verify the user is in the authorized emails list + if (emailClaim?.Value != null && _authorizedEmails.Contains(emailClaim.Value)) + { + return Ok(new { Email = emailClaim.Value, IsAuthenticated = true }); + } + } - return Ok(new { Email = emailClaim?.Value, IsAuthenticated = true }); + return Ok(new { Email = (string?)null, IsAuthenticated = false }); } } } \ No newline at end of file