From e2e888710af6db37bc290afb036fc981ec0a2f1d Mon Sep 17 00:00:00 2001 From: saopig1 <4x7sw862st@gmail.com> Date: Wed, 27 May 2026 13:56:14 +0800 Subject: [PATCH] fix(web): exclude /api/session/* from 401 auto-refresh to prevent re-entrancy --- web/src/api/http.ts | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/web/src/api/http.ts b/web/src/api/http.ts index 676be26..920c02b 100644 --- a/web/src/api/http.ts +++ b/web/src/api/http.ts @@ -15,7 +15,7 @@ export function apiFetch(input: RequestInfo | URL, init: RequestInit = {}): Prom headers: { ...(init.headers ?? {}) }, }; return fetch(input, merged).then(async (res) => { - if (res.status === 401 && isApiPath(input)) { + if (res.status === 401 && shouldTriggerRefresh(input)) { const session = useSession(); await session.refresh(); const current = router.currentRoute.value; @@ -27,9 +27,9 @@ export function apiFetch(input: RequestInfo | URL, init: RequestInit = {}): Prom }); } -function isApiPath(input: RequestInfo | URL): boolean { +function shouldTriggerRefresh(input: RequestInfo | URL): boolean { const url = typeof input === 'string' ? input : input instanceof URL ? input.toString() : input.url; - return url.startsWith('/api/'); + return url.startsWith('/api/') && !url.startsWith('/api/session/'); } /**