Repository navigation
fix(tokens): /me/tokens sign-in gate must check /auth/user JSON, not resp.ok - #2071
Merged
Merged
Conversation
The approuter serves a lapsed/anonymous session as HTTP 200 + an XSUAA login-redirect HTML page (not 401), and Akamai can serve a cached anon /auth/user to a signed-in browser. The /me/tokens island gated on resp.ok alone, so it never set needsLogin, fell through to loadTokens(), and resp.json() threw on the HTML body -> the page showed "Couldn't load your tokens. Try refreshing." instead of a sign-in prompt. - Gate via isSignedIn(): require ok + JSON content-type + body.authenticated (mirrors homepage-personalizer/coordinator.ts). - Harden loadTokens(): a non-JSON 200 (HTML login page) now falls back to the sign-in prompt, not the generic load error. - Add regression tests for 200+HTML on /auth/user and /pats/MyPATs, and authenticated:false.
This was referenced Aug 28, 2026
Merged
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
/me/tokens/shows "Couldn't load your tokens. Try refreshing." for users whose session has lapsed, instead of a sign-in prompt.Root cause
The approuter serves an anonymous/expired session as HTTP 200 + an XSUAA login-redirect HTML page (not a 401), and Akamai can serve a cached anon
/auth/userto a signed-in browser. The tokens island'sonMountedgate checkedresp.okonly:resp.okistruefor the 200 login page →needsLoginnever set → falls through toloadTokens().loadTokens()then GETs/pats/MyPATs→ also 200 + HTML →resp.json()throws → caught → generic load error atApiTokens.vue:147.Confirmed live:
GET /auth/userandGET /pats/MyPATson PROD both return HTTP 200 with the login-redirect HTML for an anonymous request.Same class as prior incidents: island
/auth/userprobes must check JSON +body.authenticated, notr.ok(#1093 homepage-personalizer fix).Fix
isSignedIn()gate: requireok+ JSON content-type +body.authenticated(mirrorshomepage-personalizer/coordinator.ts).loadTokens(): a non-JSON 200 (session lapsed mid-flow) falls back to the sign-in prompt, not the load error./auth/userand/pats/MyPATs, plusauthenticated:false.Test
npx vitest run --project unit hugo-apps/src/tokens→ 8 passed.