fix: keep sessions on forbidden responses
All checks were successful
Build and Deploy / build-and-deploy (push) Successful in 1m32s
All checks were successful
Build and Deploy / build-and-deploy (push) Successful in 1m32s
This commit is contained in:
@@ -128,7 +128,7 @@ export const fetchStock = async (): Promise<StockData[]> => {
|
||||
'Authorization': `Bearer ${token}`
|
||||
}
|
||||
});
|
||||
if (response.status === 401 || response.status === 403) {
|
||||
if (response.status === 401) {
|
||||
logout();
|
||||
return [];
|
||||
}
|
||||
@@ -171,7 +171,7 @@ export const fetchData = async (): Promise<OrderData[]> => {
|
||||
'Authorization': `Bearer ${token}`
|
||||
}
|
||||
});
|
||||
if (response.status === 401 || response.status === 403) {
|
||||
if (response.status === 401) {
|
||||
logout();
|
||||
return [];
|
||||
}
|
||||
@@ -193,7 +193,10 @@ const authFetch = async (path: string, options: RequestInit = {}): Promise<Respo
|
||||
}
|
||||
});
|
||||
|
||||
if (response.status === 401 || response.status === 403) {
|
||||
// A 403 means the signed-in user lacks permission for this specific
|
||||
// resource. Keep their session intact so protected optional data cannot
|
||||
// force a logout from an otherwise accessible page.
|
||||
if (response.status === 401) {
|
||||
logout();
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user