fix(web): change password via server action instead of client-side fetch
Tessera CI/CD / Lint & Type Check (push) Successful in 40s
Tessera CI/CD / Tests (push) Successful in 36s
Tessera CI/CD / Build & Publish Images (push) Successful in 1m23s

Client-side fetch to NEXT_PUBLIC_API_URL was unreachable in production.
Replace with a server action that uses API_INTERNAL_URL (http://api:3001)
server-to-server — no browser connectivity required.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-29 15:54:29 +02:00
parent 6020021370
commit 46ba8868c7
2 changed files with 51 additions and 44 deletions
+39
View File
@@ -95,6 +95,45 @@ export async function logout(): Promise<void> {
redirect('/login');
}
export type ChangePasswordResult =
| { success: true }
| { success: false; error: 'wrongCurrentPassword' | 'networkError' };
export async function changePasswordAction(
currentPassword: string,
newPassword: string,
): Promise<ChangePasswordResult> {
const cookieStore = await cookies();
const session = cookieStore.get('session')?.value;
if (!session) {
return { success: false, error: 'networkError' };
}
try {
const response = await fetch(`${API_URL}/auth/change-password`, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
Cookie: `session=${session}`,
},
body: JSON.stringify({ currentPassword, newPassword }),
});
if (!response.ok) {
const data = await response.json().catch(() => null);
if (data?.message === 'Current password is incorrect') {
return { success: false, error: 'wrongCurrentPassword' };
}
return { success: false, error: 'networkError' };
}
return { success: true };
} catch {
return { success: false, error: 'networkError' };
}
}
/**
* Fetch the current authenticated user from the API.
* Uses the session cookie for authentication.