fix(webui): don't redirect on change-password 401 (wrong input, not expired session)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
m4
2026-08-08 10:25:33 +08:00
parent 2db00b5157
commit b36da152a3
2 changed files with 7 additions and 1 deletions
+4
View File
@@ -24,6 +24,10 @@ describe("shouldRedirectFor", () => {
expect(shouldRedirectFor("/api/auth/login", 401, "/")).toBe(false);
});
it("ignores the change-password endpoint (401 means wrong input, not expired session)", () => {
expect(shouldRedirectFor("/api/auth/password", 401, "/")).toBe(false);
});
it("ignores 401 while already on the login page", () => {
expect(shouldRedirectFor("/api/auth/me", 401, "/login")).toBe(false);
});
+3 -1
View File
@@ -12,7 +12,9 @@ export function shouldRedirectFor(
return false;
}
if (!path.startsWith("/api/")) return false;
if (path === "/api/auth/login") return false;
// /api/auth/password 401 means "wrong current password" (form error),
// not an expired session — redirecting would log the user out mid-session.
if (path === "/api/auth/login" || path === "/api/auth/password") return false;
return true;
}