fix(web): change password via server action instead of client-side fetch
Tessera CI/CD / Lint & Type Check (push) Successful in 40s
Tessera CI/CD / Tests (push) Successful in 36s
Tessera CI/CD / Build & Publish Images (push) Successful in 1m23s

Client-side fetch to NEXT_PUBLIC_API_URL was unreachable in production.
Replace with a server action that uses API_INTERNAL_URL (http://api:3001)
server-to-server — no browser connectivity required.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-29 15:54:29 +02:00
parent 6020021370
commit 46ba8868c7
2 changed files with 51 additions and 44 deletions
@@ -3,17 +3,9 @@
import { useState, useTransition, useEffect } from 'react'; import { useState, useTransition, useEffect } from 'react';
import { useTranslations } from 'next-intl'; import { useTranslations } from 'next-intl';
import { useRouter } from 'next/navigation'; import { useRouter } from 'next/navigation';
import { fetchCurrentUser } from '@/lib/auth-actions'; import { fetchCurrentUser, changePasswordAction } from '@/lib/auth-actions';
import { useAuthStore } from '@/lib/stores/auth-store'; import { useAuthStore } from '@/lib/stores/auth-store';
const API_URL = process.env.NEXT_PUBLIC_API_URL || 'http://localhost:3001';
/**
* Change password page (D-06 force-change + voluntary change).
* Inside (portal) route group -- has sidebar/header.
* Shows a notice when user was forced here by mustChangePassword flag.
* On success, redirects to dashboard.
*/
export default function ChangePasswordPage() { export default function ChangePasswordPage() {
const t = useTranslations('auth'); const t = useTranslations('auth');
const router = useRouter(); const router = useRouter();
@@ -23,7 +15,6 @@ export default function ChangePasswordPage() {
const [passwordMismatch, setPasswordMismatch] = useState(false); const [passwordMismatch, setPasswordMismatch] = useState(false);
const [isForced, setIsForced] = useState(false); const [isForced, setIsForced] = useState(false);
// Detect if this is a forced password change
useEffect(() => { useEffect(() => {
async function checkForceChange() { async function checkForceChange() {
const currentUser = await fetchCurrentUser(); const currentUser = await fetchCurrentUser();
@@ -50,36 +41,19 @@ export default function ChangePasswordPage() {
} }
startTransition(async () => { startTransition(async () => {
try { const result = await changePasswordAction(currentPassword, newPassword);
// Get the session cookie to send with the request
const response = await fetch(`${API_URL}/auth/change-password`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ currentPassword, newPassword }),
credentials: 'include',
});
if (!response.ok) { if (!result.success) {
const data = await response.json().catch(() => null); setError(result.error);
if (data?.message === 'Current password is incorrect') { return;
setError('wrongCurrentPassword');
} else {
setError('networkError');
}
return;
}
// Update auth store to clear mustChangePassword
if (user) {
setUser({ ...user });
}
// Redirect to dashboard
router.push('/');
router.refresh();
} catch {
setError('networkError');
} }
if (user) {
setUser({ ...user });
}
router.push('/');
router.refresh();
}); });
} }
@@ -89,21 +63,18 @@ export default function ChangePasswordPage() {
{t('changePassword.title')} {t('changePassword.title')}
</h1> </h1>
{/* Force-change notice (D-06) */}
{isForced && ( {isForced && (
<div className="rounded-md bg-yellow-50 dark:bg-yellow-900/20 border border-yellow-200 dark:border-yellow-800 px-4 py-3 text-sm text-yellow-800 dark:text-yellow-200 mb-6"> <div className="rounded-md bg-yellow-50 dark:bg-yellow-900/20 border border-yellow-200 dark:border-yellow-800 px-4 py-3 text-sm text-yellow-800 dark:text-yellow-200 mb-6">
{t('changePassword.forceChangeNotice')} {t('changePassword.forceChangeNotice')}
</div> </div>
)} )}
{/* Error message */}
{error && ( {error && (
<div className="rounded-md bg-destructive/10 border border-destructive/20 px-4 py-3 text-sm text-destructive mb-6"> <div className="rounded-md bg-destructive/10 border border-destructive/20 px-4 py-3 text-sm text-destructive mb-6">
{t(`changePassword.${error}`)} {t(`changePassword.${error}`)}
</div> </div>
)} )}
{/* Password mismatch */}
{passwordMismatch && ( {passwordMismatch && (
<div className="rounded-md bg-destructive/10 border border-destructive/20 px-4 py-3 text-sm text-destructive mb-6"> <div className="rounded-md bg-destructive/10 border border-destructive/20 px-4 py-3 text-sm text-destructive mb-6">
{t('changePassword.passwordMismatch')} {t('changePassword.passwordMismatch')}
@@ -111,7 +82,6 @@ export default function ChangePasswordPage() {
)} )}
<form onSubmit={handleSubmit} className="space-y-5"> <form onSubmit={handleSubmit} className="space-y-5">
{/* Current password */}
<div className="space-y-2"> <div className="space-y-2">
<label <label
htmlFor="currentPassword" htmlFor="currentPassword"
@@ -131,7 +101,6 @@ export default function ChangePasswordPage() {
/> />
</div> </div>
{/* New password */}
<div className="space-y-2"> <div className="space-y-2">
<label <label
htmlFor="newPassword" htmlFor="newPassword"
@@ -151,7 +120,6 @@ export default function ChangePasswordPage() {
/> />
</div> </div>
{/* Confirm new password */}
<div className="space-y-2"> <div className="space-y-2">
<label <label
htmlFor="confirmPassword" htmlFor="confirmPassword"
+39
View File
@@ -95,6 +95,45 @@ export async function logout(): Promise<void> {
redirect('/login'); redirect('/login');
} }
export type ChangePasswordResult =
| { success: true }
| { success: false; error: 'wrongCurrentPassword' | 'networkError' };
export async function changePasswordAction(
currentPassword: string,
newPassword: string,
): Promise<ChangePasswordResult> {
const cookieStore = await cookies();
const session = cookieStore.get('session')?.value;
if (!session) {
return { success: false, error: 'networkError' };
}
try {
const response = await fetch(`${API_URL}/auth/change-password`, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
Cookie: `session=${session}`,
},
body: JSON.stringify({ currentPassword, newPassword }),
});
if (!response.ok) {
const data = await response.json().catch(() => null);
if (data?.message === 'Current password is incorrect') {
return { success: false, error: 'wrongCurrentPassword' };
}
return { success: false, error: 'networkError' };
}
return { success: true };
} catch {
return { success: false, error: 'networkError' };
}
}
/** /**
* Fetch the current authenticated user from the API. * Fetch the current authenticated user from the API.
* Uses the session cookie for authentication. * Uses the session cookie for authentication.