Procházet zdrojové kódy

fix: a wrong password now shows why, instead of reloading the page

The response interceptor treated every 401 as an expired access token, so
a failed login went round the refresh path, found no refresh token to use,
logged out and set window.location - a full page reload that wiped the
error the form had just rendered. The red text was there for an instant
and then the page took it away.

A 401 from /auth/login or /auth/refresh is an answer, not a lapsed
session, so those fall through to the caller. The login form already read
the server's message; it never got the chance to keep it on screen.

Verified in a browser: submitting a wrong password now leaves "Invalid
username or password" on the page, with the form's contents intact and no
navigation.
fszontagh před 1 měsícem
rodič
revize
a4dc192601
1 změnil soubory, kde provedl 11 přidání a 1 odebrání
  1. 11 1
      webui/src/api/client.ts

+ 11 - 1
webui/src/api/client.ts

@@ -51,7 +51,17 @@ api.interceptors.response.use(
     // Reset failure count when we get a response (even errors)
     networkFailureCount = 0
 
-    if (error.response?.status === 401 && !originalRequest._retry) {
+    // A 401 from the auth endpoints themselves is an answer, not an expired
+    // session. Logging in with the wrong password returns 401, and treating
+    // that as "your token lapsed" sent it round the refresh path, found no
+    // refresh token to use, logged out and reloaded the page - which wiped the
+    // error the form had just rendered. The red text was there; the reload
+    // took it away before it could be read. Let these fall through so the
+    // caller can show what the server actually said.
+    const url = originalRequest?.url || ''
+    const isAuthAttempt = url.includes('/auth/login') || url.includes('/auth/refresh')
+
+    if (error.response?.status === 401 && !originalRequest._retry && !isAuthAttempt) {
       originalRequest._retry = true
 
       try {