fix(web): redirect from server action after password change
Tessera CI/CD / Lint & Type Check (push) Successful in 44s
Tessera CI/CD / Tests (push) Successful in 40s
Tessera CI/CD / Build & Publish Images (push) Successful in 1m19s

client-side router.push races with Set-Cookie processing. redirect() in the
server action sends cookie + redirect in one response — browser applies the
new JWT before navigating, so middleware sees mustChangePassword=false.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-30 07:20:14 +02:00
parent 195354cd7a
commit f4ece4890d
2 changed files with 2 additions and 12 deletions
@@ -43,17 +43,9 @@ export default function ChangePasswordPage() {
startTransition(async () => { startTransition(async () => {
const result = await changePasswordAction(currentPassword, newPassword); const result = await changePasswordAction(currentPassword, newPassword);
if (!result.success) { if (result) {
setError(result.error); setError(result.error);
return;
} }
if (user) {
setUser({ ...user });
}
router.push('/');
router.refresh();
}); });
} }
+1 -3
View File
@@ -96,7 +96,6 @@ export async function logout(): Promise<void> {
} }
export type ChangePasswordResult = export type ChangePasswordResult =
| { success: true }
| { success: false; error: 'wrongCurrentPassword' | 'networkError' }; | { success: false; error: 'wrongCurrentPassword' | 'networkError' };
export async function changePasswordAction( export async function changePasswordAction(
@@ -136,7 +135,6 @@ export async function changePasswordAction(
// Forward new session cookie from API (mustChangePassword=false baked in) // Forward new session cookie from API (mustChangePassword=false baked in)
const setCookieHeader = response.headers.get('set-cookie'); const setCookieHeader = response.headers.get('set-cookie');
console.log('[changePasswordAction] set-cookie header:', setCookieHeader);
if (setCookieHeader) { if (setCookieHeader) {
const sessionMatch = setCookieHeader.match(/session=([^;]+)/); const sessionMatch = setCookieHeader.match(/session=([^;]+)/);
if (sessionMatch) { if (sessionMatch) {
@@ -151,7 +149,7 @@ export async function changePasswordAction(
} }
} }
return { success: true }; redirect('/');
} catch (err) { } catch (err) {
console.error('[changePasswordAction] fetch threw:', err); console.error('[changePasswordAction] fetch threw:', err);
return { success: false, error: 'networkError' }; return { success: false, error: 'networkError' };