fix(web): redirect from server action after password change
client-side router.push races with Set-Cookie processing. redirect() in the server action sends cookie + redirect in one response — browser applies the new JWT before navigating, so middleware sees mustChangePassword=false. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -43,17 +43,9 @@ export default function ChangePasswordPage() {
|
|||||||
startTransition(async () => {
|
startTransition(async () => {
|
||||||
const result = await changePasswordAction(currentPassword, newPassword);
|
const result = await changePasswordAction(currentPassword, newPassword);
|
||||||
|
|
||||||
if (!result.success) {
|
if (result) {
|
||||||
setError(result.error);
|
setError(result.error);
|
||||||
return;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (user) {
|
|
||||||
setUser({ ...user });
|
|
||||||
}
|
|
||||||
|
|
||||||
router.push('/');
|
|
||||||
router.refresh();
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -96,7 +96,6 @@ export async function logout(): Promise<void> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export type ChangePasswordResult =
|
export type ChangePasswordResult =
|
||||||
| { success: true }
|
|
||||||
| { success: false; error: 'wrongCurrentPassword' | 'networkError' };
|
| { success: false; error: 'wrongCurrentPassword' | 'networkError' };
|
||||||
|
|
||||||
export async function changePasswordAction(
|
export async function changePasswordAction(
|
||||||
@@ -136,7 +135,6 @@ export async function changePasswordAction(
|
|||||||
|
|
||||||
// Forward new session cookie from API (mustChangePassword=false baked in)
|
// Forward new session cookie from API (mustChangePassword=false baked in)
|
||||||
const setCookieHeader = response.headers.get('set-cookie');
|
const setCookieHeader = response.headers.get('set-cookie');
|
||||||
console.log('[changePasswordAction] set-cookie header:', setCookieHeader);
|
|
||||||
if (setCookieHeader) {
|
if (setCookieHeader) {
|
||||||
const sessionMatch = setCookieHeader.match(/session=([^;]+)/);
|
const sessionMatch = setCookieHeader.match(/session=([^;]+)/);
|
||||||
if (sessionMatch) {
|
if (sessionMatch) {
|
||||||
@@ -151,7 +149,7 @@ export async function changePasswordAction(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return { success: true };
|
redirect('/');
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
console.error('[changePasswordAction] fetch threw:', err);
|
console.error('[changePasswordAction] fetch threw:', err);
|
||||||
return { success: false, error: 'networkError' };
|
return { success: false, error: 'networkError' };
|
||||||
|
|||||||
Reference in New Issue
Block a user