fix(auth): avoid stale redirects after auth changes

Use full-page navigation after login/logout so the dashboard reloads
with the fresh auth cookie, and mark login/logout responses no-store.

Fixes #2100

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Emirhan
2026-06-26 11:39:49 +07:00
committed by decolua
co-authored by Cursor
parent ab5ec52f28
commit 6e9c7bf448
5 changed files with 10 additions and 19 deletions
+2 -1
View File
@@ -8,6 +8,7 @@ import { checkLock, recordFail, recordSuccess, getClientIp } from "@/lib/auth/lo
import { isLocalRequest } from "@/dashboardGuard";
const RESET_HINT = "Forgot password? Reset to default via 9Router CLI → Settings → Reset Password to Default.";
const NO_STORE_HEADERS = { "Cache-Control": "no-store" };
function isTunnelRequest(request, settings) {
const host = (request.headers.get("host") || "").split(":")[0].toLowerCase();
@@ -61,7 +62,7 @@ export async function POST(request) {
const mustChangePassword =
!storedHash && !process.env.INITIAL_PASSWORD && !isLocalRequest(request);
return NextResponse.json({ success: true, mustChangePassword });
return NextResponse.json({ success: true, mustChangePassword }, { headers: NO_STORE_HEADERS });
}
const { remainingBeforeLock } = recordFail(ip);
+1 -1
View File
@@ -8,5 +8,5 @@ export async function POST() {
cookieStore.delete("oidc_state");
cookieStore.delete("oidc_nonce");
cookieStore.delete("oidc_code_verifier");
return NextResponse.json({ success: true });
return NextResponse.json({ success: true }, { headers: { "Cache-Control": "no-store" } });
}