fix: keep sessions on forbidden responses
All checks were successful
Build and Deploy / build-and-deploy (push) Successful in 1m32s
All checks were successful
Build and Deploy / build-and-deploy (push) Successful in 1m32s
This commit is contained in:
@@ -128,7 +128,7 @@ export const fetchStock = async (): Promise<StockData[]> => {
|
|||||||
'Authorization': `Bearer ${token}`
|
'Authorization': `Bearer ${token}`
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
if (response.status === 401 || response.status === 403) {
|
if (response.status === 401) {
|
||||||
logout();
|
logout();
|
||||||
return [];
|
return [];
|
||||||
}
|
}
|
||||||
@@ -171,7 +171,7 @@ export const fetchData = async (): Promise<OrderData[]> => {
|
|||||||
'Authorization': `Bearer ${token}`
|
'Authorization': `Bearer ${token}`
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
if (response.status === 401 || response.status === 403) {
|
if (response.status === 401) {
|
||||||
logout();
|
logout();
|
||||||
return [];
|
return [];
|
||||||
}
|
}
|
||||||
@@ -193,7 +193,10 @@ const authFetch = async (path: string, options: RequestInit = {}): Promise<Respo
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
if (response.status === 401 || response.status === 403) {
|
// A 403 means the signed-in user lacks permission for this specific
|
||||||
|
// resource. Keep their session intact so protected optional data cannot
|
||||||
|
// force a logout from an otherwise accessible page.
|
||||||
|
if (response.status === 401) {
|
||||||
logout();
|
logout();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user