fix(web): move redirect() outside try/catch in changePasswordAction
redirect() throws NEXT_REDIRECT internally — inside catch it was swallowed and returned networkError. Extract cookie data in try/catch, then set cookie and redirect() after the block so the throw propagates correctly. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -112,6 +112,9 @@ export async function changePasswordAction(
|
|||||||
return { success: false, error: 'networkError' };
|
return { success: false, error: 'networkError' };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let newSessionToken: string | undefined;
|
||||||
|
let newSessionMaxAge: number | undefined;
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const response = await fetch(`${API_URL}/auth/change-password`, {
|
const response = await fetch(`${API_URL}/auth/change-password`, {
|
||||||
method: 'POST',
|
method: 'POST',
|
||||||
@@ -122,38 +125,39 @@ export async function changePasswordAction(
|
|||||||
body: JSON.stringify({ currentPassword, newPassword }),
|
body: JSON.stringify({ currentPassword, newPassword }),
|
||||||
});
|
});
|
||||||
|
|
||||||
console.log('[changePasswordAction] API response status:', response.status);
|
|
||||||
|
|
||||||
if (!response.ok) {
|
if (!response.ok) {
|
||||||
const data = await response.json().catch(() => null);
|
const data = await response.json().catch(() => null);
|
||||||
console.error('[changePasswordAction] API error:', data);
|
|
||||||
if (data?.message === 'Current password is incorrect') {
|
if (data?.message === 'Current password is incorrect') {
|
||||||
return { success: false, error: 'wrongCurrentPassword' };
|
return { success: false, error: 'wrongCurrentPassword' };
|
||||||
}
|
}
|
||||||
return { success: false, error: 'networkError' };
|
return { success: false, error: 'networkError' };
|
||||||
}
|
}
|
||||||
|
|
||||||
// Forward new session cookie from API (mustChangePassword=false baked in)
|
|
||||||
const setCookieHeader = response.headers.get('set-cookie');
|
const setCookieHeader = response.headers.get('set-cookie');
|
||||||
if (setCookieHeader) {
|
if (setCookieHeader) {
|
||||||
const sessionMatch = setCookieHeader.match(/session=([^;]+)/);
|
const sessionMatch = setCookieHeader.match(/session=([^;]+)/);
|
||||||
|
const maxAgeMatch = setCookieHeader.match(/Max-Age=(\d+)/i);
|
||||||
if (sessionMatch) {
|
if (sessionMatch) {
|
||||||
const maxAgeMatch = setCookieHeader.match(/Max-Age=(\d+)/i);
|
newSessionToken = sessionMatch[1];
|
||||||
cookieStore.set('session', sessionMatch[1], {
|
newSessionMaxAge = maxAgeMatch ? parseInt(maxAgeMatch[1]) : undefined;
|
||||||
httpOnly: true,
|
|
||||||
secure: process.env.NODE_ENV === 'production',
|
|
||||||
sameSite: 'lax',
|
|
||||||
path: '/',
|
|
||||||
...(maxAgeMatch ? { maxAge: parseInt(maxAgeMatch[1]) } : {}),
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
redirect('/');
|
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
console.error('[changePasswordAction] fetch threw:', err);
|
console.error('[changePasswordAction] fetch threw:', err);
|
||||||
return { success: false, error: 'networkError' };
|
return { success: false, error: 'networkError' };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (newSessionToken) {
|
||||||
|
cookieStore.set('session', newSessionToken, {
|
||||||
|
httpOnly: true,
|
||||||
|
secure: process.env.NODE_ENV === 'production',
|
||||||
|
sameSite: 'lax',
|
||||||
|
path: '/',
|
||||||
|
...(newSessionMaxAge ? { maxAge: newSessionMaxAge } : {}),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
redirect('/');
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
Reference in New Issue
Block a user