diff --git a/apps/web/src/app/(portal)/change-password/page.tsx b/apps/web/src/app/(portal)/change-password/page.tsx index ccf63a9..28ba66f 100644 --- a/apps/web/src/app/(portal)/change-password/page.tsx +++ b/apps/web/src/app/(portal)/change-password/page.tsx @@ -3,17 +3,9 @@ import { useState, useTransition, useEffect } from 'react'; import { useTranslations } from 'next-intl'; import { useRouter } from 'next/navigation'; -import { fetchCurrentUser } from '@/lib/auth-actions'; +import { fetchCurrentUser, changePasswordAction } from '@/lib/auth-actions'; import { useAuthStore } from '@/lib/stores/auth-store'; -const API_URL = process.env.NEXT_PUBLIC_API_URL || 'http://localhost:3001'; - -/** - * Change password page (D-06 force-change + voluntary change). - * Inside (portal) route group -- has sidebar/header. - * Shows a notice when user was forced here by mustChangePassword flag. - * On success, redirects to dashboard. - */ export default function ChangePasswordPage() { const t = useTranslations('auth'); const router = useRouter(); @@ -23,7 +15,6 @@ export default function ChangePasswordPage() { const [passwordMismatch, setPasswordMismatch] = useState(false); const [isForced, setIsForced] = useState(false); - // Detect if this is a forced password change useEffect(() => { async function checkForceChange() { const currentUser = await fetchCurrentUser(); @@ -50,36 +41,19 @@ export default function ChangePasswordPage() { } startTransition(async () => { - try { - // Get the session cookie to send with the request - const response = await fetch(`${API_URL}/auth/change-password`, { - method: 'POST', - headers: { 'Content-Type': 'application/json' }, - body: JSON.stringify({ currentPassword, newPassword }), - credentials: 'include', - }); + const result = await changePasswordAction(currentPassword, newPassword); - if (!response.ok) { - const data = await response.json().catch(() => null); - if (data?.message === 'Current password is incorrect') { - setError('wrongCurrentPassword'); - } else { - setError('networkError'); - } - return; - } - - // Update auth store to clear mustChangePassword - if (user) { - setUser({ ...user }); - } - - // Redirect to dashboard - router.push('/'); - router.refresh(); - } catch { - setError('networkError'); + if (!result.success) { + setError(result.error); + return; } + + if (user) { + setUser({ ...user }); + } + + router.push('/'); + router.refresh(); }); } @@ -89,21 +63,18 @@ export default function ChangePasswordPage() { {t('changePassword.title')} - {/* Force-change notice (D-06) */} {isForced && (