From f96a0db7694c58d4be2c3904153564f83a4ccce3 Mon Sep 17 00:00:00 2001 From: Schalli Date: Mon, 29 Jun 2026 16:47:55 +0200 Subject: [PATCH] fix(web): forward new session cookie after password change After changePassword the API issues a new JWT with mustChangePassword=false. The server action now reads Set-Cookie from the API response and sets it in the browser so the middleware sees the updated flag and allows /dashboard. Co-Authored-By: Claude Sonnet 4.6 --- apps/web/src/lib/auth-actions.ts | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/apps/web/src/lib/auth-actions.ts b/apps/web/src/lib/auth-actions.ts index 17511a8..0573ee8 100644 --- a/apps/web/src/lib/auth-actions.ts +++ b/apps/web/src/lib/auth-actions.ts @@ -134,6 +134,22 @@ export async function changePasswordAction( return { success: false, error: 'networkError' }; } + // Forward new session cookie from API (mustChangePassword=false baked in) + const setCookieHeader = response.headers.get('set-cookie'); + if (setCookieHeader) { + const sessionMatch = setCookieHeader.match(/session=([^;]+)/); + if (sessionMatch) { + const maxAgeMatch = setCookieHeader.match(/Max-Age=(\d+)/i); + cookieStore.set('session', sessionMatch[1], { + httpOnly: true, + secure: process.env.NODE_ENV === 'production', + sameSite: 'lax', + path: '/', + ...(maxAgeMatch ? { maxAge: parseInt(maxAgeMatch[1]) } : {}), + }); + } + } + return { success: true }; } catch (err) { console.error('[changePasswordAction] fetch threw:', err);