fix(web): change password via server action instead of client-side fetch
Client-side fetch to NEXT_PUBLIC_API_URL was unreachable in production. Replace with a server action that uses API_INTERNAL_URL (http://api:3001) server-to-server — no browser connectivity required. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -95,6 +95,45 @@ export async function logout(): Promise<void> {
|
||||
redirect('/login');
|
||||
}
|
||||
|
||||
export type ChangePasswordResult =
|
||||
| { success: true }
|
||||
| { success: false; error: 'wrongCurrentPassword' | 'networkError' };
|
||||
|
||||
export async function changePasswordAction(
|
||||
currentPassword: string,
|
||||
newPassword: string,
|
||||
): Promise<ChangePasswordResult> {
|
||||
const cookieStore = await cookies();
|
||||
const session = cookieStore.get('session')?.value;
|
||||
|
||||
if (!session) {
|
||||
return { success: false, error: 'networkError' };
|
||||
}
|
||||
|
||||
try {
|
||||
const response = await fetch(`${API_URL}/auth/change-password`, {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
Cookie: `session=${session}`,
|
||||
},
|
||||
body: JSON.stringify({ currentPassword, newPassword }),
|
||||
});
|
||||
|
||||
if (!response.ok) {
|
||||
const data = await response.json().catch(() => null);
|
||||
if (data?.message === 'Current password is incorrect') {
|
||||
return { success: false, error: 'wrongCurrentPassword' };
|
||||
}
|
||||
return { success: false, error: 'networkError' };
|
||||
}
|
||||
|
||||
return { success: true };
|
||||
} catch {
|
||||
return { success: false, error: 'networkError' };
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Fetch the current authenticated user from the API.
|
||||
* Uses the session cookie for authentication.
|
||||
|
||||
Reference in New Issue
Block a user