diff --git a/fluxer_app/src/features/auth/components/pages/oauth_authorize_page/hooks/useOAuthPublicApp.ts b/fluxer_app/src/features/auth/components/pages/oauth_authorize_page/hooks/useOAuthPublicApp.ts index 0bd97eb08..93cb11483 100644 --- a/fluxer_app/src/features/auth/components/pages/oauth_authorize_page/hooks/useOAuthPublicApp.ts +++ b/fluxer_app/src/features/auth/components/pages/oauth_authorize_page/hooks/useOAuthPublicApp.ts @@ -39,6 +39,11 @@ export function useOAuthPublicApp(clientId: string | null): PublicAppState { const resp = await http.get(Endpoints.OAUTH_PUBLIC_APPLICATION(clientId)); if (cancelled) return; const currentUser = resp.body.current_user; + if (currentUserId && !currentUser) { + logger.warn('OAuth public app fetch returned no current user for a signed-in account'); + setState({status: 'session_expired', data: null, error: null}); + return; + } if (currentUser && currentUser.id === currentUserId) { const userData = authResponseUserToUserData(currentUser); if (userData) { diff --git a/fluxer_app/src/features/auth/components/pages/oauth_authorize_page/state/useAuthorizeFlow.ts b/fluxer_app/src/features/auth/components/pages/oauth_authorize_page/state/useAuthorizeFlow.ts index 33feddbd3..0dd59b787 100644 --- a/fluxer_app/src/features/auth/components/pages/oauth_authorize_page/state/useAuthorizeFlow.ts +++ b/fluxer_app/src/features/auth/components/pages/oauth_authorize_page/state/useAuthorizeFlow.ts @@ -29,6 +29,7 @@ import { import {getDefaultLandingPath} from '@app/features/navigation/utils/DefaultLandingUtils'; import type {BotPermissionOption} from '@app/features/permissions/utils/PermissionUtils'; import {http} from '@app/features/platform/transport/RestTransport'; +import {HttpError} from '@app/features/platform/types/EndpointError'; import {failureMessage} from '@app/features/platform/utils/ResponseInspection'; import {msg} from '@lingui/core/macro'; import {useLingui} from '@lingui/react/macro'; @@ -388,6 +389,12 @@ export function useAuthorizeFlow(options: UseAuthorizeFlowOptions = {}): Authori setSubmitting(null); setSubmitError(i18n._(AUTHORIZATION_FAILED_DESCRIPTOR)); } catch (err) { + if (err instanceof HttpError && err.status === 401) { + logger.warn('OAuth consent returned 401', err); + setSubmitting(null); + dispatch({type: 'INIT_SESSION_EXPIRED'}); + return; + } logger.error('Authorization failed', err); setSubmitting(null); setSubmitError(failureMessage(err) ?? i18n._(AUTHORIZATION_FAILED_DESCRIPTOR));