fix(profile): add credentials to fetch calls so auth cookies are sent
Profile page showed "Not Authenticated" because fetch calls to /api/auth/me and /api/auth/change-password were missing credentials: 'same-origin', preventing HttpOnly cookies from being sent.
This commit is contained in:
@@ -25,7 +25,7 @@ function timeAgo(dateStr) {
|
|||||||
|
|
||||||
async function init() {
|
async function init() {
|
||||||
try {
|
try {
|
||||||
const resp = await fetch(API + '/auth/me', { headers: headers() });
|
const resp = await fetch(API + '/auth/me', { headers: headers(), credentials: 'same-origin' });
|
||||||
if (!resp.ok) { showError(); return; }
|
if (!resp.ok) { showError(); return; }
|
||||||
const user = await resp.json();
|
const user = await resp.json();
|
||||||
|
|
||||||
@@ -66,7 +66,7 @@ async function init() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const oidcResp = await fetch(API + '/auth/oidc/providers');
|
const oidcResp = await fetch(API + '/auth/oidc/providers', { credentials: 'same-origin' });
|
||||||
if (oidcResp.ok) {
|
if (oidcResp.ok) {
|
||||||
const oidcInfo = await oidcResp.json();
|
const oidcInfo = await oidcResp.json();
|
||||||
if (!oidcInfo.password_login_enabled) {
|
if (!oidcInfo.password_login_enabled) {
|
||||||
@@ -114,6 +114,7 @@ async function changePassword(e) {
|
|||||||
const resp = await fetch(API + '/auth/change-password', {
|
const resp = await fetch(API + '/auth/change-password', {
|
||||||
method: 'PUT',
|
method: 'PUT',
|
||||||
headers: headers(),
|
headers: headers(),
|
||||||
|
credentials: 'same-origin',
|
||||||
body: JSON.stringify({ current_password: currentPw, new_password: newPw })
|
body: JSON.stringify({ current_password: currentPw, new_password: newPw })
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user