|
@@ -51,7 +51,17 @@ api.interceptors.response.use(
|
|
|
// Reset failure count when we get a response (even errors)
|
|
// Reset failure count when we get a response (even errors)
|
|
|
networkFailureCount = 0
|
|
networkFailureCount = 0
|
|
|
|
|
|
|
|
- if (error.response?.status === 401 && !originalRequest._retry) {
|
|
|
|
|
|
|
+ // A 401 from the auth endpoints themselves is an answer, not an expired
|
|
|
|
|
+ // session. Logging in with the wrong password returns 401, and treating
|
|
|
|
|
+ // that as "your token lapsed" sent it round the refresh path, found no
|
|
|
|
|
+ // refresh token to use, logged out and reloaded the page - which wiped the
|
|
|
|
|
+ // error the form had just rendered. The red text was there; the reload
|
|
|
|
|
+ // took it away before it could be read. Let these fall through so the
|
|
|
|
|
+ // caller can show what the server actually said.
|
|
|
|
|
+ const url = originalRequest?.url || ''
|
|
|
|
|
+ const isAuthAttempt = url.includes('/auth/login') || url.includes('/auth/refresh')
|
|
|
|
|
+
|
|
|
|
|
+ if (error.response?.status === 401 && !originalRequest._retry && !isAuthAttempt) {
|
|
|
originalRequest._retry = true
|
|
originalRequest._retry = true
|
|
|
|
|
|
|
|
try {
|
|
try {
|