fix(03): login redirect + API internal URL for Docker networking

- Use window.location.href for full page reload after login (ensures auth state)
- Add API_INTERNAL_URL for server-side requests within Docker network
- Remove unnecessary credentials:'include' from SSR fetch calls
- Update planning state for Phase 03 progress

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-20 09:28:05 +02:00
parent f5a775c0df
commit 46a6e277b8
5 changed files with 11 additions and 12 deletions
+1 -4
View File
@@ -3,7 +3,7 @@
import { cookies } from 'next/headers';
import { redirect } from 'next/navigation';
const API_URL = process.env.NEXT_PUBLIC_API_URL || 'http://localhost:3001';
const API_URL = process.env.API_INTERNAL_URL || process.env.NEXT_PUBLIC_API_URL || 'http://localhost:3001';
export interface AuthUser {
id: string;
@@ -39,7 +39,6 @@ export async function login(formData: FormData): Promise<LoginResult> {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ username, password }),
credentials: 'include',
});
if (!response.ok) {
@@ -51,7 +50,6 @@ export async function login(formData: FormData): Promise<LoginResult> {
// Forward the session cookie from the API response to the browser
const setCookieHeader = response.headers.get('set-cookie');
if (setCookieHeader) {
// Parse the session cookie value from the API response
const sessionMatch = setCookieHeader.match(/session=([^;]+)/);
if (sessionMatch) {
const cookieStore = await cookies();
@@ -59,7 +57,6 @@ export async function login(formData: FormData): Promise<LoginResult> {
httpOnly: true,
secure: process.env.NODE_ENV === 'production',
sameSite: 'lax',
// D-02: 30 days if rememberMe, otherwise session cookie (browser close)
...(rememberMe
? { maxAge: 30 * 24 * 60 * 60 }
: {}),