Files
Sharrit/app/src/main/java/com/shaarit/domain/usecase/LoginUseCase.kt
T
bruno 8f90d5b3b8 fix: derive JWT iat from server clock
Shaarli rejects tokens whose iat falls outside its clock
tolerance, so device/server skew caused HTTP 401 logins
even with a correct API secret. Estimate server time from
the Date response header, retry a 401 once with a
recalibrated token, trim credentials on login, and explain
the API-secret vs password mismatch in French error
messages.

Bump version to 2.14.1 (code 42).
2026-10-07 16:33:24 -04:00

19 lines
819 B
Kotlin

package com.shaarit.domain.usecase
import com.shaarit.domain.model.Credentials
import com.shaarit.domain.repository.AuthRepository
import javax.inject.Inject
class LoginUseCase @Inject constructor(private val repository: AuthRepository) {
suspend operator fun invoke(url: String, secret: String): Result<Boolean> {
// Trim so a trailing space from copy/paste or autocomplete does not silently
// corrupt the URL or the HMAC key (which would surface as an obscure HTTP 401).
val cleanUrl = url.trim()
val cleanSecret = secret.trim()
if (cleanUrl.isBlank() || cleanSecret.isBlank()) {
return Result.failure(IllegalArgumentException("URL and Secret cannot be empty"))
}
return repository.login(Credentials(cleanUrl, cleanSecret), cleanUrl)
}
}