From f4ece4890d35bc75e131a1e69c66c4abd877f1eb Mon Sep 17 00:00:00 2001 From: Schalli Date: Tue, 30 Jun 2026 07:20:14 +0200 Subject: [PATCH] fix(web): redirect from server action after password change MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit client-side router.push races with Set-Cookie processing. redirect() in the server action sends cookie + redirect in one response — browser applies the new JWT before navigating, so middleware sees mustChangePassword=false. Co-Authored-By: Claude Sonnet 4.6 --- apps/web/src/app/(portal)/change-password/page.tsx | 10 +--------- apps/web/src/lib/auth-actions.ts | 4 +--- 2 files changed, 2 insertions(+), 12 deletions(-) diff --git a/apps/web/src/app/(portal)/change-password/page.tsx b/apps/web/src/app/(portal)/change-password/page.tsx index 28ba66f..1a14ad0 100644 --- a/apps/web/src/app/(portal)/change-password/page.tsx +++ b/apps/web/src/app/(portal)/change-password/page.tsx @@ -43,17 +43,9 @@ export default function ChangePasswordPage() { startTransition(async () => { const result = await changePasswordAction(currentPassword, newPassword); - if (!result.success) { + if (result) { setError(result.error); - return; } - - if (user) { - setUser({ ...user }); - } - - router.push('/'); - router.refresh(); }); } diff --git a/apps/web/src/lib/auth-actions.ts b/apps/web/src/lib/auth-actions.ts index 33630c7..380d389 100644 --- a/apps/web/src/lib/auth-actions.ts +++ b/apps/web/src/lib/auth-actions.ts @@ -96,7 +96,6 @@ export async function logout(): Promise { } export type ChangePasswordResult = - | { success: true } | { success: false; error: 'wrongCurrentPassword' | 'networkError' }; export async function changePasswordAction( @@ -136,7 +135,6 @@ export async function changePasswordAction( // Forward new session cookie from API (mustChangePassword=false baked in) const setCookieHeader = response.headers.get('set-cookie'); - console.log('[changePasswordAction] set-cookie header:', setCookieHeader); if (setCookieHeader) { const sessionMatch = setCookieHeader.match(/session=([^;]+)/); if (sessionMatch) { @@ -151,7 +149,7 @@ export async function changePasswordAction( } } - return { success: true }; + redirect('/'); } catch (err) { console.error('[changePasswordAction] fetch threw:', err); return { success: false, error: 'networkError' };