mirror of
https://github.com/R0m1k3/Socialflow.git
synced 2026-10-11 17:26:45 +02:00
The SPA's session check (/api/auth/session) is cached indefinitely by react-query (staleTime: Infinity, no refetch on focus/interval), so once a protected page mounts successfully, the app never re-verifies auth. If the server-side session later becomes invalid (server restart with in-memory sessions, cookie/session expiry, etc.), every subsequent API call (pages, scheduled-posts, audio-tracks, media, media/upload, ...) starts failing with 401 in a loop with no way for the user to recover short of a manual page reload. Add a shared handleUnauthorized() in queryClient.ts that redirects to /login on any non-auth API 401, wired into both the shared fetch helpers (apiRequest/getQueryFn) and the raw fetch() calls used for file uploads and Remotion rendering, which also lacked this recovery path. Also add the missing credentials: "include" to those raw fetch() calls for consistency with the rest of the app's API requests.