fix(web): forward new session cookie after password change
After changePassword the API issues a new JWT with mustChangePassword=false. The server action now reads Set-Cookie from the API response and sets it in the browser so the middleware sees the updated flag and allows /dashboard. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -134,6 +134,22 @@ export async function changePasswordAction(
|
||||
return { success: false, error: 'networkError' };
|
||||
}
|
||||
|
||||
// Forward new session cookie from API (mustChangePassword=false baked in)
|
||||
const setCookieHeader = response.headers.get('set-cookie');
|
||||
if (setCookieHeader) {
|
||||
const sessionMatch = setCookieHeader.match(/session=([^;]+)/);
|
||||
if (sessionMatch) {
|
||||
const maxAgeMatch = setCookieHeader.match(/Max-Age=(\d+)/i);
|
||||
cookieStore.set('session', sessionMatch[1], {
|
||||
httpOnly: true,
|
||||
secure: process.env.NODE_ENV === 'production',
|
||||
sameSite: 'lax',
|
||||
path: '/',
|
||||
...(maxAgeMatch ? { maxAge: parseInt(maxAgeMatch[1]) } : {}),
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
return { success: true };
|
||||
} catch (err) {
|
||||
console.error('[changePasswordAction] fetch threw:', err);
|
||||
|
||||
Reference in New Issue
Block a user