Skip to content

fix: log out and redirect to /login when the auth token expires - #352

Open
hassan1brahim wants to merge 1 commit into
devfrom
fix/348-logout-on-token-expiry
Open

hassan1brahim wants to merge 1 commit into
devfrom
fix/348-logout-on-token-expiry

Conversation

@hassan1brahim

Copy link
Copy Markdown
Collaborator

Closes #348

Problem

When the access token expires, every backend call returns 401 Unauthorized, but the dashboard only showed a raw "Unauthorized" alert and left the user stuck until they logged out by hand.

There was already a redirect check in dashboard/page.tsx, but it could never run: GetUser stored the whole response object in error, while the check required typeof data.error === 'string'. The organizer and director views had no 401 handling at all.

Changes

  • app/lib/actions.ts: GetUser and GetAllUsers now return the HTTP statusCode on failure (and 401 when there is no session). GetUser's error is now the backend's message string instead of the raw object.
  • app/lib/data.ts: getSelf() passes statusCode through to its caller.
  • app/lib/authGuard.ts (new): redirectIfUnauthorized(statusCode). On a 401 it calls the existing handleSignOut() to clear the session, then redirects to /login, and returns true so the caller can stop. Any other status is a no-op.
  • app/dashboard/page.tsx: replaced the dead string check with the helper. alert(data.error.message) → alert(data.error) since error is a string now.
  • views/organizerView.tsx, views/directorView.tsx: added the same check after their initial fetch.

It keys on statusCode === 401 rather than matching message text, because the backend's error wording is inconsistent. On the backend, an expired JWT makes validateToken return false and every authenticated handler answers 401. A hacker reading someone else's data gets 403, which is ignored, so it won't log anyone out by mistake.

Scope

Only the page-load reads redirect. Actions taken later on the page (profile save, team actions) still show an alert on a 401; normalizing every call in actions.ts is #240.

Testing

  • tsc --noEmit passes
  • npm run lint passes with the same 7 pre-existing warnings as dev, none new
  • Not yet tested in a browser with an expired token

The dashboard's Unauthorized check never fired: GetUser returned the
error as an object, but the check required typeof error === 'string'.
GetUser and GetAllUsers now return the HTTP statusCode, getSelf passes
it through, and a shared redirectIfUnauthorized helper signs the user
out and redirects to /login on a 401. Wired into the dashboard,
organizer and director views.

Closes #348
@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
frontendv2 Ready Ready Preview Sep 27, 2026 8:52pm UTC

Request Review

This branch was successfully deployed

1 active deployment
Preview — 13bef246 Deployed Sep 27, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant