fix(web): forward new session cookie after password change
Tessera CI/CD / Lint & Type Check (push) Successful in 39s
Tessera CI/CD / Tests (push) Successful in 35s
Tessera CI/CD / Build & Publish Images (push) Successful in 1m21s

After changePassword the API issues a new JWT with mustChangePassword=false.
The server action now reads Set-Cookie from the API response and sets it
in the browser so the middleware sees the updated flag and allows /dashboard.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-29 16:47:55 +02:00
parent c8210a2abc
commit f96a0db769
+16
View File
@@ -134,6 +134,22 @@ export async function changePasswordAction(
return { success: false, error: 'networkError' }; return { success: false, error: 'networkError' };
} }
// Forward new session cookie from API (mustChangePassword=false baked in)
const setCookieHeader = response.headers.get('set-cookie');
if (setCookieHeader) {
const sessionMatch = setCookieHeader.match(/session=([^;]+)/);
if (sessionMatch) {
const maxAgeMatch = setCookieHeader.match(/Max-Age=(\d+)/i);
cookieStore.set('session', sessionMatch[1], {
httpOnly: true,
secure: process.env.NODE_ENV === 'production',
sameSite: 'lax',
path: '/',
...(maxAgeMatch ? { maxAge: parseInt(maxAgeMatch[1]) } : {}),
});
}
}
return { success: true }; return { success: true };
} catch (err) { } catch (err) {
console.error('[changePasswordAction] fetch threw:', err); console.error('[changePasswordAction] fetch threw:', err);