fix(web): change password via server action instead of client-side fetch
Client-side fetch to NEXT_PUBLIC_API_URL was unreachable in production. Replace with a server action that uses API_INTERNAL_URL (http://api:3001) server-to-server — no browser connectivity required. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -3,17 +3,9 @@
|
|||||||
import { useState, useTransition, useEffect } from 'react';
|
import { useState, useTransition, useEffect } from 'react';
|
||||||
import { useTranslations } from 'next-intl';
|
import { useTranslations } from 'next-intl';
|
||||||
import { useRouter } from 'next/navigation';
|
import { useRouter } from 'next/navigation';
|
||||||
import { fetchCurrentUser } from '@/lib/auth-actions';
|
import { fetchCurrentUser, changePasswordAction } from '@/lib/auth-actions';
|
||||||
import { useAuthStore } from '@/lib/stores/auth-store';
|
import { useAuthStore } from '@/lib/stores/auth-store';
|
||||||
|
|
||||||
const API_URL = process.env.NEXT_PUBLIC_API_URL || 'http://localhost:3001';
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Change password page (D-06 force-change + voluntary change).
|
|
||||||
* Inside (portal) route group -- has sidebar/header.
|
|
||||||
* Shows a notice when user was forced here by mustChangePassword flag.
|
|
||||||
* On success, redirects to dashboard.
|
|
||||||
*/
|
|
||||||
export default function ChangePasswordPage() {
|
export default function ChangePasswordPage() {
|
||||||
const t = useTranslations('auth');
|
const t = useTranslations('auth');
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
@@ -23,7 +15,6 @@ export default function ChangePasswordPage() {
|
|||||||
const [passwordMismatch, setPasswordMismatch] = useState(false);
|
const [passwordMismatch, setPasswordMismatch] = useState(false);
|
||||||
const [isForced, setIsForced] = useState(false);
|
const [isForced, setIsForced] = useState(false);
|
||||||
|
|
||||||
// Detect if this is a forced password change
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
async function checkForceChange() {
|
async function checkForceChange() {
|
||||||
const currentUser = await fetchCurrentUser();
|
const currentUser = await fetchCurrentUser();
|
||||||
@@ -50,36 +41,19 @@ export default function ChangePasswordPage() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
startTransition(async () => {
|
startTransition(async () => {
|
||||||
try {
|
const result = await changePasswordAction(currentPassword, newPassword);
|
||||||
// Get the session cookie to send with the request
|
|
||||||
const response = await fetch(`${API_URL}/auth/change-password`, {
|
|
||||||
method: 'POST',
|
|
||||||
headers: { 'Content-Type': 'application/json' },
|
|
||||||
body: JSON.stringify({ currentPassword, newPassword }),
|
|
||||||
credentials: 'include',
|
|
||||||
});
|
|
||||||
|
|
||||||
if (!response.ok) {
|
if (!result.success) {
|
||||||
const data = await response.json().catch(() => null);
|
setError(result.error);
|
||||||
if (data?.message === 'Current password is incorrect') {
|
return;
|
||||||
setError('wrongCurrentPassword');
|
|
||||||
} else {
|
|
||||||
setError('networkError');
|
|
||||||
}
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Update auth store to clear mustChangePassword
|
|
||||||
if (user) {
|
|
||||||
setUser({ ...user });
|
|
||||||
}
|
|
||||||
|
|
||||||
// Redirect to dashboard
|
|
||||||
router.push('/');
|
|
||||||
router.refresh();
|
|
||||||
} catch {
|
|
||||||
setError('networkError');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (user) {
|
||||||
|
setUser({ ...user });
|
||||||
|
}
|
||||||
|
|
||||||
|
router.push('/');
|
||||||
|
router.refresh();
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -89,21 +63,18 @@ export default function ChangePasswordPage() {
|
|||||||
{t('changePassword.title')}
|
{t('changePassword.title')}
|
||||||
</h1>
|
</h1>
|
||||||
|
|
||||||
{/* Force-change notice (D-06) */}
|
|
||||||
{isForced && (
|
{isForced && (
|
||||||
<div className="rounded-md bg-yellow-50 dark:bg-yellow-900/20 border border-yellow-200 dark:border-yellow-800 px-4 py-3 text-sm text-yellow-800 dark:text-yellow-200 mb-6">
|
<div className="rounded-md bg-yellow-50 dark:bg-yellow-900/20 border border-yellow-200 dark:border-yellow-800 px-4 py-3 text-sm text-yellow-800 dark:text-yellow-200 mb-6">
|
||||||
{t('changePassword.forceChangeNotice')}
|
{t('changePassword.forceChangeNotice')}
|
||||||
</div>
|
</div>
|
||||||
)}
|
)}
|
||||||
|
|
||||||
{/* Error message */}
|
|
||||||
{error && (
|
{error && (
|
||||||
<div className="rounded-md bg-destructive/10 border border-destructive/20 px-4 py-3 text-sm text-destructive mb-6">
|
<div className="rounded-md bg-destructive/10 border border-destructive/20 px-4 py-3 text-sm text-destructive mb-6">
|
||||||
{t(`changePassword.${error}`)}
|
{t(`changePassword.${error}`)}
|
||||||
</div>
|
</div>
|
||||||
)}
|
)}
|
||||||
|
|
||||||
{/* Password mismatch */}
|
|
||||||
{passwordMismatch && (
|
{passwordMismatch && (
|
||||||
<div className="rounded-md bg-destructive/10 border border-destructive/20 px-4 py-3 text-sm text-destructive mb-6">
|
<div className="rounded-md bg-destructive/10 border border-destructive/20 px-4 py-3 text-sm text-destructive mb-6">
|
||||||
{t('changePassword.passwordMismatch')}
|
{t('changePassword.passwordMismatch')}
|
||||||
@@ -111,7 +82,6 @@ export default function ChangePasswordPage() {
|
|||||||
)}
|
)}
|
||||||
|
|
||||||
<form onSubmit={handleSubmit} className="space-y-5">
|
<form onSubmit={handleSubmit} className="space-y-5">
|
||||||
{/* Current password */}
|
|
||||||
<div className="space-y-2">
|
<div className="space-y-2">
|
||||||
<label
|
<label
|
||||||
htmlFor="currentPassword"
|
htmlFor="currentPassword"
|
||||||
@@ -131,7 +101,6 @@ export default function ChangePasswordPage() {
|
|||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
{/* New password */}
|
|
||||||
<div className="space-y-2">
|
<div className="space-y-2">
|
||||||
<label
|
<label
|
||||||
htmlFor="newPassword"
|
htmlFor="newPassword"
|
||||||
@@ -151,7 +120,6 @@ export default function ChangePasswordPage() {
|
|||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
{/* Confirm new password */}
|
|
||||||
<div className="space-y-2">
|
<div className="space-y-2">
|
||||||
<label
|
<label
|
||||||
htmlFor="confirmPassword"
|
htmlFor="confirmPassword"
|
||||||
|
|||||||
@@ -95,6 +95,45 @@ export async function logout(): Promise<void> {
|
|||||||
redirect('/login');
|
redirect('/login');
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export type ChangePasswordResult =
|
||||||
|
| { success: true }
|
||||||
|
| { success: false; error: 'wrongCurrentPassword' | 'networkError' };
|
||||||
|
|
||||||
|
export async function changePasswordAction(
|
||||||
|
currentPassword: string,
|
||||||
|
newPassword: string,
|
||||||
|
): Promise<ChangePasswordResult> {
|
||||||
|
const cookieStore = await cookies();
|
||||||
|
const session = cookieStore.get('session')?.value;
|
||||||
|
|
||||||
|
if (!session) {
|
||||||
|
return { success: false, error: 'networkError' };
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const response = await fetch(`${API_URL}/auth/change-password`, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'Content-Type': 'application/json',
|
||||||
|
Cookie: `session=${session}`,
|
||||||
|
},
|
||||||
|
body: JSON.stringify({ currentPassword, newPassword }),
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!response.ok) {
|
||||||
|
const data = await response.json().catch(() => null);
|
||||||
|
if (data?.message === 'Current password is incorrect') {
|
||||||
|
return { success: false, error: 'wrongCurrentPassword' };
|
||||||
|
}
|
||||||
|
return { success: false, error: 'networkError' };
|
||||||
|
}
|
||||||
|
|
||||||
|
return { success: true };
|
||||||
|
} catch {
|
||||||
|
return { success: false, error: 'networkError' };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Fetch the current authenticated user from the API.
|
* Fetch the current authenticated user from the API.
|
||||||
* Uses the session cookie for authentication.
|
* Uses the session cookie for authentication.
|
||||||
|
|||||||
Reference in New Issue
Block a user