From 40c4876a1900868b804dcd592343bf8afcdf136a Mon Sep 17 00:00:00 2001 From: Schalli Date: Tue, 30 Jun 2026 07:25:57 +0200 Subject: [PATCH] fix(web): move redirect() outside try/catch in changePasswordAction MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit redirect() throws NEXT_REDIRECT internally — inside catch it was swallowed and returned networkError. Extract cookie data in try/catch, then set cookie and redirect() after the block so the throw propagates correctly. Co-Authored-By: Claude Sonnet 4.6 --- apps/web/src/lib/auth-actions.ts | 32 ++++++++++++++++++-------------- 1 file changed, 18 insertions(+), 14 deletions(-) diff --git a/apps/web/src/lib/auth-actions.ts b/apps/web/src/lib/auth-actions.ts index 380d389..a9b9813 100644 --- a/apps/web/src/lib/auth-actions.ts +++ b/apps/web/src/lib/auth-actions.ts @@ -112,6 +112,9 @@ export async function changePasswordAction( return { success: false, error: 'networkError' }; } + let newSessionToken: string | undefined; + let newSessionMaxAge: number | undefined; + try { const response = await fetch(`${API_URL}/auth/change-password`, { method: 'POST', @@ -122,38 +125,39 @@ export async function changePasswordAction( body: JSON.stringify({ currentPassword, newPassword }), }); - console.log('[changePasswordAction] API response status:', response.status); - if (!response.ok) { const data = await response.json().catch(() => null); - console.error('[changePasswordAction] API error:', data); if (data?.message === 'Current password is incorrect') { return { success: false, error: 'wrongCurrentPassword' }; } return { success: false, error: 'networkError' }; } - // Forward new session cookie from API (mustChangePassword=false baked in) const setCookieHeader = response.headers.get('set-cookie'); if (setCookieHeader) { const sessionMatch = setCookieHeader.match(/session=([^;]+)/); + const maxAgeMatch = setCookieHeader.match(/Max-Age=(\d+)/i); if (sessionMatch) { - const maxAgeMatch = setCookieHeader.match(/Max-Age=(\d+)/i); - cookieStore.set('session', sessionMatch[1], { - httpOnly: true, - secure: process.env.NODE_ENV === 'production', - sameSite: 'lax', - path: '/', - ...(maxAgeMatch ? { maxAge: parseInt(maxAgeMatch[1]) } : {}), - }); + newSessionToken = sessionMatch[1]; + newSessionMaxAge = maxAgeMatch ? parseInt(maxAgeMatch[1]) : undefined; } } - - redirect('/'); } catch (err) { console.error('[changePasswordAction] fetch threw:', err); return { success: false, error: 'networkError' }; } + + if (newSessionToken) { + cookieStore.set('session', newSessionToken, { + httpOnly: true, + secure: process.env.NODE_ENV === 'production', + sameSite: 'lax', + path: '/', + ...(newSessionMaxAge ? { maxAge: newSessionMaxAge } : {}), + }); + } + + redirect('/'); } /**