Commit 05d50ec
fix(auth): clear stale cookies on refresh token failure to stop infinite retry loop
When a user visits the login page with an expired/revoked refresh token,
the browser Supabase client retries token refresh endlessly (400 → 429).
Two fixes:
- middleware updateSession(): properly detect getUser() auth errors (returned,
not thrown) and clear all sb-* cookies via Set-Cookie maxAge=0
- proxy.ts: use getSetCookie() instead of get('set-cookie') to copy ALL
Set-Cookie headers to the response (was only copying the first one,
losing cookie-clearing headers for chunked auth tokens)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 278c910 commit 05d50ec
2 files changed
Lines changed: 27 additions & 17 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
48 | | - | |
| 48 | + | |
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
| |||
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
61 | | - | |
62 | | - | |
63 | | - | |
64 | | - | |
65 | | - | |
66 | | - | |
67 | | - | |
68 | | - | |
69 | | - | |
70 | | - | |
71 | | - | |
72 | | - | |
73 | | - | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
74 | 80 | | |
75 | 81 | | |
76 | 82 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
278 | 278 | | |
279 | 279 | | |
280 | 280 | | |
281 | | - | |
282 | | - | |
283 | | - | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
284 | 288 | | |
285 | 289 | | |
286 | 290 | | |
| |||
0 commit comments