Repository navigation
Conversation
Login on a production build served over plain HTTP (e.g. a LAN test server) never stored the access and refresh tokens: they were marked Secure because NODE_ENV is "production", and browsers drop Secure cookies set from HTTP pages, so /users/me answered 401. shouldUseSecureCookies() follows the page's protocol in the browser and keeps the NODE_ENV rule elsewhere; useLogin and refreshAccessToken use it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019P1oyApi4BLS8iLfMEGm8b
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Login on a production build served over plain HTTP never kept the user signed in. Stacked on #1 (
merge/baseapp-files), the branch whatplant pins.useLoginandrefreshAccessTokenset the access and refresh token cookies withsecure: process.env.NODE_ENV === 'production'. On anext startbuild served overhttp://(a LAN test server or a staging host without TLS), browsers dropSecurecookies set from HTTP pages, except on localhost.Authorization/Refreshcookie was stored, so/v1/users/meanswered401 Authentication credentials were not provided.shouldUseSecureCookies()in@baseapp-frontend/utils.window.location.protocol.NODE_ENVrule.useLoginandrefreshAccessTokenuse it.Securecookies.@baseapp-frontend/utilsand@baseapp-frontend/authentication.middleware.tswith the sameNODE_ENVrule should switch to the request's scheme (X-Forwarded-Protobehind a proxy). The whatplant frontend does this in its own PR.Worth upstreaming to silverlogic/baseapp-frontend: the bug is in the template's defaults.
Test plan
vitest:functions/token29 passed (newshouldUseSecureCookiestests),useLogin3 passed.http://10.244.99.39:3001:LanguageandCurrentProfilecookies exist;AuthorizationandRefreshare stored, and the account menu and signed-in navigation show.🤖 Generated with Claude Code
https://claude.ai/code/session_019P1oyApi4BLS8iLfMEGm8b