From 46a6e277b86003d46aa6e2ea319293066dc8a416 Mon Sep 17 00:00:00 2001 From: Schalli Date: Sat, 20 Jun 2026 09:28:05 +0200 Subject: [PATCH] fix(03): login redirect + API internal URL for Docker networking - Use window.location.href for full page reload after login (ensures auth state) - Add API_INTERNAL_URL for server-side requests within Docker network - Remove unnecessary credentials:'include' from SSR fetch calls - Update planning state for Phase 03 progress Co-Authored-By: Claude Sonnet 4.6 --- .planning/STATE.md | 10 +++++----- .planning/config.json | 3 ++- apps/web/src/app/(auth)/login/page.tsx | 3 +-- apps/web/src/lib/auth-actions.ts | 5 +---- docker-compose.yml | 2 ++ 5 files changed, 11 insertions(+), 12 deletions(-) diff --git a/.planning/STATE.md b/.planning/STATE.md index 52e0010..2f62c88 100644 --- a/.planning/STATE.md +++ b/.planning/STATE.md @@ -3,14 +3,14 @@ gsd_state_version: 1.0 milestone: v1.0 milestone_name: milestone status: executing -stopped_at: Completed 02-02-PLAN.md -last_updated: "2026-06-19T10:27:41.286Z" +stopped_at: context exhaustion at 75% (2026-06-19) +last_updated: "2026-06-19T12:37:50.398Z" last_activity: 2026-06-19 -- Phase 03 execution started progress: total_phases: 6 completed_phases: 1 total_plans: 12 - completed_plans: 7 + completed_plans: 10 percent: 17 --- @@ -93,6 +93,6 @@ Items acknowledged and carried forward from previous milestone close: ## Session Continuity -Last session: 2026-06-18T11:41:48.372Z -Stopped at: Completed 02-02-PLAN.md +Last session: 2026-06-19T12:37:50.391Z +Stopped at: context exhaustion at 75% (2026-06-19) Resume file: None diff --git a/.planning/config.json b/.planning/config.json index a660775..e39ad2a 100644 --- a/.planning/config.json +++ b/.planning/config.json @@ -45,7 +45,8 @@ "post_planning_gaps": true, "security_enforcement": true, "security_asvs_level": 1, - "security_block_on": "high" + "security_block_on": "high", + "_auto_chain_active": false }, "ship": { "pr_body_sections": [ diff --git a/apps/web/src/app/(auth)/login/page.tsx b/apps/web/src/app/(auth)/login/page.tsx index d93a5a6..fab6786 100644 --- a/apps/web/src/app/(auth)/login/page.tsx +++ b/apps/web/src/app/(auth)/login/page.tsx @@ -27,8 +27,7 @@ export default function LoginPage() { startTransition(async () => { const result = await login(formData); if (result.success) { - router.push('/'); - router.refresh(); + window.location.href = '/'; } else { setError(result.error ?? 'invalidCredentials'); } diff --git a/apps/web/src/lib/auth-actions.ts b/apps/web/src/lib/auth-actions.ts index 99f221d..18e68e5 100644 --- a/apps/web/src/lib/auth-actions.ts +++ b/apps/web/src/lib/auth-actions.ts @@ -3,7 +3,7 @@ import { cookies } from 'next/headers'; import { redirect } from 'next/navigation'; -const API_URL = process.env.NEXT_PUBLIC_API_URL || 'http://localhost:3001'; +const API_URL = process.env.API_INTERNAL_URL || process.env.NEXT_PUBLIC_API_URL || 'http://localhost:3001'; export interface AuthUser { id: string; @@ -39,7 +39,6 @@ export async function login(formData: FormData): Promise { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ username, password }), - credentials: 'include', }); if (!response.ok) { @@ -51,7 +50,6 @@ export async function login(formData: FormData): Promise { // Forward the session cookie from the API response to the browser const setCookieHeader = response.headers.get('set-cookie'); if (setCookieHeader) { - // Parse the session cookie value from the API response const sessionMatch = setCookieHeader.match(/session=([^;]+)/); if (sessionMatch) { const cookieStore = await cookies(); @@ -59,7 +57,6 @@ export async function login(formData: FormData): Promise { httpOnly: true, secure: process.env.NODE_ENV === 'production', sameSite: 'lax', - // D-02: 30 days if rememberMe, otherwise session cookie (browser close) ...(rememberMe ? { maxAge: 30 * 24 * 60 * 60 } : {}), diff --git a/docker-compose.yml b/docker-compose.yml index acddebf..3c1a36f 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -8,6 +8,8 @@ services: environment: HOSTNAME: "0.0.0.0" NEXT_PUBLIC_API_URL: "http://localhost:3001" + API_INTERNAL_URL: "http://api:3001" + JWT_SECRET: ${JWT_SECRET:-tessera-dev-jwt-secret-change-in-production} networks: - frontend-net - backend-net