fix: log out and redirect to /login when the auth token expires - #352
Open
hassan1brahim wants to merge 1 commit into
Open
hassan1brahim wants to merge 1 commit into
hassan1brahim wants to merge 1 commit into
Conversation
The dashboard's Unauthorized check never fired: GetUser returned the error as an object, but the check required typeof error === 'string'. GetUser and GetAllUsers now return the HTTP statusCode, getSelf passes it through, and a shared redirectIfUnauthorized helper signs the user out and redirects to /login on a 401. Wired into the dashboard, organizer and director views. Closes #348
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #348
Problem
When the access token expires, every backend call returns
401 Unauthorized, but the dashboard only showed a raw "Unauthorized" alert and left the user stuck until they logged out by hand.There was already a redirect check in
dashboard/page.tsx, but it could never run:GetUserstored the whole response object inerror, while the check requiredtypeof data.error === 'string'. The organizer and director views had no 401 handling at all.Changes
app/lib/actions.ts:GetUserandGetAllUsersnow return the HTTPstatusCodeon failure (and401when there is no session).GetUser'serroris now the backend's message string instead of the raw object.app/lib/data.ts:getSelf()passesstatusCodethrough to its caller.app/lib/authGuard.ts(new):redirectIfUnauthorized(statusCode). On a401it calls the existinghandleSignOut()to clear the session, then redirects to/login, and returnstrueso the caller can stop. Any other status is a no-op.app/dashboard/page.tsx: replaced the dead string check with the helper.alert(data.error.message)→alert(data.error)sinceerroris a string now.views/organizerView.tsx,views/directorView.tsx: added the same check after their initial fetch.It keys on
statusCode === 401rather than matching message text, because the backend's error wording is inconsistent. On the backend, an expired JWT makesvalidateTokenreturn false and every authenticated handler answers401. A hacker reading someone else's data gets403, which is ignored, so it won't log anyone out by mistake.Scope
Only the page-load reads redirect. Actions taken later on the page (profile save, team actions) still show an alert on a 401; normalizing every call in
actions.tsis #240.Testing
tsc --noEmitpassesnpm run lintpasses with the same 7 pre-existing warnings asdev, none new