fix: adopt orphan session cookie on first SPA load

This commit is contained in:
Linus Rath
2026-05-16 18:45:30 +02:00
parent 349406723c
commit 0e1036eb49
+33 -1
View File
@@ -1246,7 +1246,7 @@ export const useAuthStore = create<AuthState>()(
checkAuth: async () => {
const accountStore = useAccountStore.getState();
const accounts = accountStore.accounts;
let accounts = accountStore.accounts;
// If the only account is the demo account, re-initialize demo mode
// instead of trying to restore a server session (which doesn't exist).
@@ -1255,6 +1255,38 @@ export const useAuthStore = create<AuthState>()(
return;
}
// Orphan-cookie adoption — when no accounts are registered but a
// basic-auth session cookie is present (set by /api/auth/impersonate
// or by another server-side hand-off), promote it into the account
// registry so the normal restoration path picks it up. Without this
// the cookies sit unused and the SPA bounces to the login screen.
if (accounts.length === 0) {
try {
const restore = await apiFetch('/api/auth/session', { method: 'PUT' });
if (restore.ok) {
const data = await restore.json();
if (data?.serverUrl && data?.username && data?.password) {
accountStore.addAccount({
label: data.username,
serverUrl: data.serverUrl,
username: data.username,
authMode: 'basic',
rememberMe: true,
displayName: data.username,
email: data.username,
lastLoginAt: Date.now(),
isConnected: false,
hasError: false,
isDefault: true,
});
accounts = useAccountStore.getState().accounts;
}
}
} catch (err) {
debug.error('Orphan session cookie adoption failed:', err);
}
}
// Multi-account restoration: restore all registered accounts
if (accounts.length > 0) {
// Null out client so the page doesn't fire data-loading effects