From edcde8b34a46876935ae5bdcdf25ac9a26487686 Mon Sep 17 00:00:00 2001 From: Arnaud Date: Sun, 19 Jul 2026 09:26:26 +0200 Subject: [PATCH] fix: password sign-in for 2FA accounts could silently bounce to /login (v0.50.1) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit signIn.email() resolves with error: null and data.twoFactorRedirect: true for 2FA-enabled accounts — no full session exists yet. The login page's handleSubmit treated any non-error response as fully signed in and called router.push("/recipes"), racing better-auth's own window.location.href redirect to /verify-2fa (twoFactorClient's onSuccess hook). When the app's push won that race, middleware bounced the unauthenticated /recipes request straight back to /login with no error surfaced — looked like the page just reloaded. Now explicitly skips the /recipes push when twoFactorRedirect is set, leaving the SDK's own redirect to run uncontested. Co-Authored-By: Claude Sonnet 5 --- CHANGELOG.md | 5 +++++ apps/web/app/(auth)/login/page.tsx | 8 ++++++-- apps/web/lib/changelog.ts | 9 ++++++++- apps/web/package.json | 2 +- package.json | 2 +- 5 files changed, 21 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e61b35f..15f7938 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,11 @@ All notable changes to Epicure are documented here. This file is mirrored in-app at `/changelog` (and in the admin dashboard) via `apps/web/lib/changelog.ts` — update both together. +## 0.50.1 — 2026-07-19 09:30 + +### Fixed +- Password sign-in for 2FA-enabled accounts could silently bounce back to the login page with no error shown — the app was pushing straight to /recipes on any non-error sign-in response, racing the SDK's own redirect to the 2FA code screen and sometimes losing. Now waits for that case explicitly. + ## 0.50.0 — 2026-07-18 14:20 ### Added diff --git a/apps/web/app/(auth)/login/page.tsx b/apps/web/app/(auth)/login/page.tsx index 07da3c0..150a062 100644 --- a/apps/web/app/(auth)/login/page.tsx +++ b/apps/web/app/(auth)/login/page.tsx @@ -25,7 +25,7 @@ export default function LoginPage() { e.preventDefault(); setUnverified(false); setLoading(true); - const { error } = await authClient.signIn.email({ email, password, callbackURL: "/recipes" }); + const { data, error } = await authClient.signIn.email({ email, password, callbackURL: "/recipes" }); setLoading(false); if (error) { if (error.code === "EMAIL_NOT_VERIFIED") { @@ -33,7 +33,11 @@ export default function LoginPage() { } else { toast.error(error.message ?? "Sign in failed"); } - } else { + } else if (!(data as { twoFactorRedirect?: boolean } | null)?.twoFactorRedirect) { + // 2FA-enabled accounts resolve with no `error` but `twoFactorRedirect: true` — + // no full session exists yet, so pushing to /recipes here races the SDK's own + // window.location.href to /verify-2fa (see twoFactorClient's onSuccess hook) + // and can lose, bouncing off middleware back to /login with no visible error. router.push("/recipes"); } } diff --git a/apps/web/lib/changelog.ts b/apps/web/lib/changelog.ts index 2e46e16..c55e0f3 100644 --- a/apps/web/lib/changelog.ts +++ b/apps/web/lib/changelog.ts @@ -1,5 +1,5 @@ // Mirrors CHANGELOG.md at the repo root — update both together. -export const APP_VERSION = "0.50.0"; +export const APP_VERSION = "0.50.1"; export type ChangelogEntry = { version: string; @@ -11,6 +11,13 @@ export type ChangelogEntry = { }; export const CHANGELOG: ChangelogEntry[] = [ + { + version: "0.50.1", + date: "2026-07-19 09:30", + fixed: [ + "Password sign-in for 2FA-enabled accounts could silently bounce back to the login page with no error shown — the app was pushing straight to /recipes on any non-error sign-in response, racing the SDK's own redirect to the 2FA code screen and sometimes losing. Now waits for that case explicitly.", + ], + }, { version: "0.50.0", date: "2026-07-18 14:20", diff --git a/apps/web/package.json b/apps/web/package.json index 42fe724..deb7edc 100644 --- a/apps/web/package.json +++ b/apps/web/package.json @@ -1,6 +1,6 @@ { "name": "@epicure/web", - "version": "0.50.0", + "version": "0.50.1", "private": true, "scripts": { "dev": "next dev", diff --git a/package.json b/package.json index 0034162..e511343 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "epicure", - "version": "0.50.0", + "version": "0.50.1", "private": true, "scripts": { "dev": "pnpm --filter web dev",