diff --git a/src/lib/authRedirect.test.ts b/src/lib/authRedirect.test.ts index 50b61fa..7b81f18 100644 --- a/src/lib/authRedirect.test.ts +++ b/src/lib/authRedirect.test.ts @@ -24,6 +24,10 @@ describe("shouldRedirectFor", () => { expect(shouldRedirectFor("/api/auth/login", 401, "/")).toBe(false); }); + it("ignores the change-password endpoint (401 means wrong input, not expired session)", () => { + expect(shouldRedirectFor("/api/auth/password", 401, "/")).toBe(false); + }); + it("ignores 401 while already on the login page", () => { expect(shouldRedirectFor("/api/auth/me", 401, "/login")).toBe(false); }); diff --git a/src/lib/authRedirect.ts b/src/lib/authRedirect.ts index a1f03e5..b1080bc 100644 --- a/src/lib/authRedirect.ts +++ b/src/lib/authRedirect.ts @@ -12,7 +12,9 @@ export function shouldRedirectFor( return false; } if (!path.startsWith("/api/")) return false; - if (path === "/api/auth/login") return false; + // /api/auth/password 401 means "wrong current password" (form error), + // not an expired session — redirecting would log the user out mid-session. + if (path === "/api/auth/login" || path === "/api/auth/password") return false; return true; }