mirror of
https://github.com/xCyanGrizzly/DragonsStash.git
synced 2026-09-21 05:21:43 +00:00
fix(auth): survive a stale session whose user was deleted
A JWT session pointing at a user no longer in the DB (e.g. after a DB reset) made getUserSettings create settings for a non-existent user -> FK violation (P2003) -> Server Component render crash. getUserSettings now returns defaults on P2003; the (app) layout detects the missing user and redirects to a new server-side /logout route that clears the cookie, avoiding the middleware redirect loop that otherwise blocks reaching /login. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,7 +1,23 @@
|
|||||||
|
import { redirect } from "next/navigation";
|
||||||
|
import { auth } from "@/lib/auth";
|
||||||
|
import { prisma } from "@/lib/prisma";
|
||||||
import { Sidebar } from "@/components/layout/sidebar";
|
import { Sidebar } from "@/components/layout/sidebar";
|
||||||
import { Header } from "@/components/layout/header";
|
import { Header } from "@/components/layout/header";
|
||||||
|
|
||||||
export default function AppLayout({ children }: { children: React.ReactNode }) {
|
export default async function AppLayout({ children }: { children: React.ReactNode }) {
|
||||||
|
// Guard against a stale JWT session whose user no longer exists in the
|
||||||
|
// database (e.g. after a DB reset). The signed cookie still passes edge
|
||||||
|
// middleware, but every downstream query keyed on session.user.id would fail.
|
||||||
|
// Send such sessions to /logout, which clears the cookie and returns to login.
|
||||||
|
const session = await auth();
|
||||||
|
if (session?.user?.id) {
|
||||||
|
const user = await prisma.user.findUnique({
|
||||||
|
where: { id: session.user.id },
|
||||||
|
select: { id: true },
|
||||||
|
});
|
||||||
|
if (!user) redirect("/logout");
|
||||||
|
}
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="flex h-screen overflow-hidden">
|
<div className="flex h-screen overflow-hidden">
|
||||||
<div className="hidden lg:block">
|
<div className="hidden lg:block">
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
import { signOut } from "@/lib/auth";
|
||||||
|
|
||||||
|
// Server-side sign-out that clears the JWT session cookie and redirects to the
|
||||||
|
// login page. Used to recover from a stale session whose user no longer exists
|
||||||
|
// in the database (e.g. after a DB reset), which a client-only signOut can't
|
||||||
|
// reach because the app crashes before rendering the user menu.
|
||||||
|
export async function GET() {
|
||||||
|
await signOut({ redirectTo: "/login" });
|
||||||
|
}
|
||||||
@@ -1,20 +1,37 @@
|
|||||||
|
import { Prisma } from "@prisma/client";
|
||||||
import { prisma } from "@/lib/prisma";
|
import { prisma } from "@/lib/prisma";
|
||||||
|
|
||||||
|
const DEFAULT_SETTINGS = {
|
||||||
|
lowStockThreshold: 20,
|
||||||
|
currency: "EUR",
|
||||||
|
theme: "dark",
|
||||||
|
units: "metric",
|
||||||
|
} as const;
|
||||||
|
|
||||||
export async function getUserSettings(userId: string) {
|
export async function getUserSettings(userId: string) {
|
||||||
let settings = await prisma.userSettings.findUnique({
|
let settings = await prisma.userSettings.findUnique({
|
||||||
where: { userId },
|
where: { userId },
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!settings) {
|
if (!settings) {
|
||||||
|
try {
|
||||||
settings = await prisma.userSettings.create({
|
settings = await prisma.userSettings.create({
|
||||||
data: {
|
data: { userId, ...DEFAULT_SETTINGS },
|
||||||
userId,
|
|
||||||
lowStockThreshold: 20,
|
|
||||||
currency: "EUR",
|
|
||||||
theme: "dark",
|
|
||||||
units: "metric",
|
|
||||||
},
|
|
||||||
});
|
});
|
||||||
|
} catch (err) {
|
||||||
|
// The session's user may no longer exist (e.g. a stale JWT cookie after a
|
||||||
|
// database reset). Creating settings then hits a foreign-key violation
|
||||||
|
// (P2003). Don't crash the Server Component render — return unsaved
|
||||||
|
// defaults. The (app) layout guard redirects such stale sessions to
|
||||||
|
// sign-out, so this fallback is only ever momentarily visible.
|
||||||
|
if (
|
||||||
|
err instanceof Prisma.PrismaClientKnownRequestError &&
|
||||||
|
err.code === "P2003"
|
||||||
|
) {
|
||||||
|
return { id: "", userId, ...DEFAULT_SETTINGS };
|
||||||
|
}
|
||||||
|
throw err;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return settings;
|
return settings;
|
||||||
|
|||||||
Reference in New Issue
Block a user