From f0e0e79d346a0fb479576c9f98cdc7af036a2a11 Mon Sep 17 00:00:00 2001 From: xCyanGrizzly Date: Thu, 23 Jul 2026 11:05:26 +0200 Subject: [PATCH] fix(auth): survive a stale session whose user was deleted A JWT session pointing at a user no longer in the DB (e.g. after a DB reset) made getUserSettings create settings for a non-existent user -> FK violation (P2003) -> Server Component render crash. getUserSettings now returns defaults on P2003; the (app) layout detects the missing user and redirects to a new server-side /logout route that clears the cookie, avoiding the middleware redirect loop that otherwise blocks reaching /login. Co-Authored-By: Claude Opus 4.8 (1M context) --- src/app/(app)/layout.tsx | 18 +++++++++++++++++- src/app/logout/route.ts | 9 +++++++++ src/data/settings.queries.ts | 35 ++++++++++++++++++++++++++--------- 3 files changed, 52 insertions(+), 10 deletions(-) create mode 100644 src/app/logout/route.ts diff --git a/src/app/(app)/layout.tsx b/src/app/(app)/layout.tsx index fb98185..5faf03a 100644 --- a/src/app/(app)/layout.tsx +++ b/src/app/(app)/layout.tsx @@ -1,7 +1,23 @@ +import { redirect } from "next/navigation"; +import { auth } from "@/lib/auth"; +import { prisma } from "@/lib/prisma"; import { Sidebar } from "@/components/layout/sidebar"; import { Header } from "@/components/layout/header"; -export default function AppLayout({ children }: { children: React.ReactNode }) { +export default async function AppLayout({ children }: { children: React.ReactNode }) { + // Guard against a stale JWT session whose user no longer exists in the + // database (e.g. after a DB reset). The signed cookie still passes edge + // middleware, but every downstream query keyed on session.user.id would fail. + // Send such sessions to /logout, which clears the cookie and returns to login. + const session = await auth(); + if (session?.user?.id) { + const user = await prisma.user.findUnique({ + where: { id: session.user.id }, + select: { id: true }, + }); + if (!user) redirect("/logout"); + } + return (
diff --git a/src/app/logout/route.ts b/src/app/logout/route.ts new file mode 100644 index 0000000..66b4f7d --- /dev/null +++ b/src/app/logout/route.ts @@ -0,0 +1,9 @@ +import { signOut } from "@/lib/auth"; + +// Server-side sign-out that clears the JWT session cookie and redirects to the +// login page. Used to recover from a stale session whose user no longer exists +// in the database (e.g. after a DB reset), which a client-only signOut can't +// reach because the app crashes before rendering the user menu. +export async function GET() { + await signOut({ redirectTo: "/login" }); +} diff --git a/src/data/settings.queries.ts b/src/data/settings.queries.ts index d353462..246fe41 100644 --- a/src/data/settings.queries.ts +++ b/src/data/settings.queries.ts @@ -1,20 +1,37 @@ +import { Prisma } from "@prisma/client"; import { prisma } from "@/lib/prisma"; +const DEFAULT_SETTINGS = { + lowStockThreshold: 20, + currency: "EUR", + theme: "dark", + units: "metric", +} as const; + export async function getUserSettings(userId: string) { let settings = await prisma.userSettings.findUnique({ where: { userId }, }); if (!settings) { - settings = await prisma.userSettings.create({ - data: { - userId, - lowStockThreshold: 20, - currency: "EUR", - theme: "dark", - units: "metric", - }, - }); + try { + settings = await prisma.userSettings.create({ + data: { userId, ...DEFAULT_SETTINGS }, + }); + } catch (err) { + // The session's user may no longer exist (e.g. a stale JWT cookie after a + // database reset). Creating settings then hits a foreign-key violation + // (P2003). Don't crash the Server Component render — return unsaved + // defaults. The (app) layout guard redirects such stale sessions to + // sign-out, so this fallback is only ever momentarily visible. + if ( + err instanceof Prisma.PrismaClientKnownRequestError && + err.code === "P2003" + ) { + return { id: "", userId, ...DEFAULT_SETTINGS }; + } + throw err; + } } return settings;