Fix access token not persisting on hard reload - #11
Open
MuhammadSadiqAli-EQ wants to merge 10 commits into
Open
Conversation
- Add LoginForm, SignupForm, HealthCheck components - Add CenteredPageLayout and TextField reusable UI - Add lib/api.ts, auth.ts, config.ts, health.ts, types.ts - Use clientAction for login/signup, clientLoader for health check - Update routes to use React Router data APIs
Removed docstring explaining public access for HealthCheckAPI and simplified response structure.
Refactor authentication views to remove AuthenticationService calls and directly handle user authentication and password management. Update token handling and response structure for login and signup endpoints.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Hard reload was logging the user out even when refresh token cookie was still valid. In-memory access token gets wiped on reload, but the code never tried the refresh token as fallback.
Fix
getValidAccessToken()inlib/auth.ts, checks memory first, falls back torefreshAccessToken()if emptyProtectedLayout(loader-based route guard) for the new/authpage, redirects to/loginif no valid token foundTesting
/authredirects to/loginwhen no refresh cookie present (tested by manually deleting it from web devtool)/authkeeps user logged in when refresh cookie is validmemoryRefreshTokencookie triggers redirect correctlyFixes #8