[FIX] api.js: sessione scaduta → login invece di pagina bloccata "--"
Bug segnalato da un tester "sono tornato su nis2 e non funziona più" (utente/ aziende "--", inventario bloccato su Caricamento, niente FAB segnalazioni). Causa: un 401 su /auth/refresh (refresh token scaduto/invalido) rientrava nel handler di refresh (la condizione non escludeva l'endpoint auth) → ricorsione: doRefreshToken() non ritornava mai, quindi logout()/redirect a login non scattava e la pagina restava rotta. Riprodotto con puppeteer (access scaduto + refresh invalido → dashboard "--" identica allo screenshot). Fix: escludi /auth/refresh e /auth/login dall'auto-refresh; inoltre un 401 senza refresh token disponibile fa logout() → login. Ora un utente che torna dopo la scadenza del token viene mandato a login (ri-accede) invece di vedere "--". Bug PRE-ESISTENTE in api.js (non introdotto dal V3), critico ora col push tester. Cache-buster api.js ?v=20260627u su tutte le pagine. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
64e10b152b
commit
41476c88f2
+16
-5
@@ -40,11 +40,22 @@ class NIS2API {
|
||||
const response = await fetch(url, config);
|
||||
const json = await response.json();
|
||||
|
||||
// Token expired - try refresh
|
||||
if (response.status === 401 && this.refreshToken && !options._isRetry) {
|
||||
const refreshed = await this.doRefreshToken();
|
||||
if (refreshed) {
|
||||
return this.request(method, endpoint, data, { ...options, _isRetry: true });
|
||||
// Token expired - try refresh. ESCLUDI gli endpoint auth stessi: un 401 su
|
||||
// /auth/refresh (refresh token scaduto/invalido) NON deve ri-triggerare il
|
||||
// refresh → altrimenti ricorsione infinita, doRefreshToken() non ritorna mai,
|
||||
// logout()/redirect non scatta e l'utente resta su una pagina rotta ("--").
|
||||
// (Bug utente "sono tornato dopo un po'": access scaduto + refresh non valido.)
|
||||
const isAuthEndpoint = endpoint === '/auth/refresh' || endpoint === '/auth/login';
|
||||
if (response.status === 401 && !isAuthEndpoint && !options._isRetry) {
|
||||
if (this.refreshToken) {
|
||||
const refreshed = await this.doRefreshToken();
|
||||
if (refreshed) {
|
||||
return this.request(method, endpoint, data, { ...options, _isRetry: true });
|
||||
}
|
||||
// refresh fallito → doRefreshToken() ha già fatto logout()+redirect a login
|
||||
} else {
|
||||
// 401 senza refresh token → sessione non recuperabile → vai a login
|
||||
this.logout();
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user