fix(app): send expired sessions to login on oauth authorize (#3181)

This commit is contained in:
Hampus
2026-10-03 20:39:34 +02:00
committed by GitHub
parent 0de7dde1ce
commit 5799ef705d
2 changed files with 12 additions and 0 deletions
@@ -39,6 +39,11 @@ export function useOAuthPublicApp(clientId: string | null): PublicAppState {
const resp = await http.get<PublicAppData>(Endpoints.OAUTH_PUBLIC_APPLICATION(clientId));
if (cancelled) return;
const currentUser = resp.body.current_user;
if (currentUserId && !currentUser) {
logger.warn('OAuth public app fetch returned no current user for a signed-in account');
setState({status: 'session_expired', data: null, error: null});
return;
}
if (currentUser && currentUser.id === currentUserId) {
const userData = authResponseUserToUserData(currentUser);
if (userData) {
@@ -29,6 +29,7 @@ import {
import {getDefaultLandingPath} from '@app/features/navigation/utils/DefaultLandingUtils';
import type {BotPermissionOption} from '@app/features/permissions/utils/PermissionUtils';
import {http} from '@app/features/platform/transport/RestTransport';
import {HttpError} from '@app/features/platform/types/EndpointError';
import {failureMessage} from '@app/features/platform/utils/ResponseInspection';
import {msg} from '@lingui/core/macro';
import {useLingui} from '@lingui/react/macro';
@@ -388,6 +389,12 @@ export function useAuthorizeFlow(options: UseAuthorizeFlowOptions = {}): Authori
setSubmitting(null);
setSubmitError(i18n._(AUTHORIZATION_FAILED_DESCRIPTOR));
} catch (err) {
if (err instanceof HttpError && err.status === 401) {
logger.warn('OAuth consent returned 401', err);
setSubmitting(null);
dispatch({type: 'INIT_SESSION_EXPIRED'});
return;
}
logger.error('Authorization failed', err);
setSubmitting(null);
setSubmitError(failureMessage(err) ?? i18n._(AUTHORIZATION_FAILED_DESCRIPTOR));