fix(auth): keep the session across a server action redirect - #604
Merged
Merged
Conversation
When a server action calls redirect(), Next.js renders the target page with an internal fetch whose cookie header it rebuilds through RequestCookies.toString(), which percent-encodes every value. The base64 padding in Ory's session cookie becomes %3D, Ory rejects the cookie, and the page the action lands on renders signed out — after creating a service account, and after creating a product (#296). The middleware now decodes Ory's session cookies before anything reads them; their values are base64url, so the decode is lossless. Fixes #296 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
|
Claude finished @alukach's task in 19s —— View job ✅ No blocking issues — safe to merge. The fix sits at the right choke point. The middleware runs on Next's internal redirect fetch, so Non-blocking notes
Simplify (ponytail)
Docs
💰 Estimated review cost: $0.12 · 0m18s · 6 turns |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
After creating a service account (and after creating a product, #296), the page you land on shows "Log In / Register" as if you had been signed out. Reloading fixes it.
Cause
When a server action calls
redirect(), Next.js doesn't send a bare redirect: it renders the target page itself with an internalfetchand streams that back (createRedirectRenderResultinnext/dist/server/app-render/action-handler.js). The cookie header for that fetch is rebuilt bygetForwardedHeadersthroughRequestCookies.toString(), which runs every value throughencodeURIComponent. Ory's session cookie is padded base64, so its=becomes%3D,whoamirejects the cookie,getPageSession()returns null, and the header and the settings layout render signed out.Fix
The middleware runs on that internal fetch too, so it now decodes Ory's session cookies (
ory_*session*) before anything downstream reads them. Ory's values are base64url and never contain%, so decoding restores the original exactly; other cookies are left as they are. Fixing it in one place coversgetServerSession, the step-up guard and the proxy-credentials reader without touching their test mocks.Testing
npx jest src/middleware.test.ts: new cases for the encoded and unencoded headers pass.npm run type-checkpasses.Docs and ADRs
No user-facing flow or platform decision changes. Checked
docs/using-source/and the data-proxy ADRs; none describe this.Fixes #296
🤖 Generated with Claude Code