Skip to content

fix(auth): écritures profil qui pendent + middleware auth inopérant - #19

Merged
Tbeaumont79 merged 1 commit into
mainfrom
fix/profile-writes-hang
Jun 10, 2026
Merged

Tbeaumont79 merged 1 commit into
mainfrom
fix/profile-writes-hang

Conversation

@Tbeaumont79

@Tbeaumont79 Tbeaumont79 commented Jun 10, 2026 •

Copy link
Copy Markdown
Owner

Symptômes (constatés par le fondateur et reproduits)

  • /profil affichait « Impossible de charger ton profil » pour un visiteur non connecté (au lieu de rediriger vers /connexion).
  • Toutes les écritures (PUT /api/profile, POST experiences/skills, import) pendaient indéfiniment en build de prod — l'édition de profil était inutilisable.

Causes

  1. getAuthSession → toWebRequest(event) : convertir l'événement H3 en Request touche au flux du corps ; le readBody(event) qui suit dans les handlers PUT/POST attend un corps déjà verrouillé → hang. Les GET (sans corps) passaient, d'où le symptôme asymétrique. Fix : passer event.headers directement (comme le middleware serveur le fait déjà).
  2. Middleware de navigation auth : il testait la truthiness de l'atom nanostores de useAuth() — un objet, toujours vrai → aucune redirection, jamais. Fix : vérification réelle de session via GET /api/auth/get-session (cookies transférés en SSR).

Vérification (build de prod + Postgres réel)

  • PUT /api/profile → 200 en ~20 ms (avant : timeout 12 s) ; POST expériences/compétences → 200 ; relecture GET OK.
  • /profil sans cookie → 302 /connexion ; avec session → 200.
  • ✅ lint · ✅ typecheck · ✅ 56 tests

🤖 Generated with Claude Code

Summary by CodeRabbit

Bug Fixes

  • Enhanced authentication reliability by migrating from hook-based session checks to a dedicated session endpoint, with proper cookie header forwarding during server-side rendering
  • Resolved potential request timeout issues in session utilities by optimizing event header processing, preventing body locking conflicts in PUT/POST handlers

Deux bugs qui cassaient tout le parcours profil :

1. getAuthSession utilisait toWebRequest(event), qui touche au flux du
   corps de la requête : le readBody(event) des handlers PUT/POST
   attendait ensuite un corps déjà verrouillé → toutes les écritures
   /api/profile* pendaient indéfiniment en build de prod (les GET, sans
   corps, passaient). On passe event.headers directement à
   auth.api.getSession, comme le fait déjà le middleware serveur.

2. Le middleware de navigation `auth` testait la truthiness de l'atom
   nanostores de useAuth() — toujours vrai → aucune redirection, et les
   visiteurs non connectés voyaient « Impossible de charger ton profil »
   (401) sur /profil. On vérifie désormais la session via
   GET /api/auth/get-session (cookies transférés en SSR).

Vérifié sur build de prod + Postgres : PUT/POST/DELETE profil en ~10 ms,
/profil anonyme → 302 /connexion, /profil connecté → 200.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jun 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: d3a3aec9-0981-49a5-973f-3347db64b59b

📥 Commits

Reviewing files that changed from the base of the PR and between 002fe77 and f42c768.

📒 Files selected for processing (2)
  • apps/app/middleware/auth.ts
  • apps/app/server/utils/session.ts

📝 Walkthrough

Walkthrough

The PR refactors authentication session handling by updating the server-side session utility to retrieve sessions using direct event headers instead of web request conversion, and modifies the middleware to call the session endpoint directly with proper cookie forwarding for SSR instead of relying on the useAuth() hook.

Changes

Authentication Session Handling

Layer / File(s) Summary
Server session utility refactoring
apps/app/server/utils/session.ts
getAuthSession now retrieves Better Auth sessions using event.headers directly instead of converting via toWebRequest(event), which prevents body-locking issues in PUT/POST handlers. Documentation updated to reflect this behavior.
Middleware authentication check via endpoint
apps/app/middleware/auth.ts
Auth middleware replaces useAuth() hook session checks with direct /api/auth/get-session endpoint calls. SSR requests forward the incoming cookie header; client navigation performs the same fetch without custom headers. Missing or errored sessions redirect to /connexion.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Poem

🐰 A rabbit hops through session calls,
No hooks to halt in auth's great halls,
Direct the headers, cookies true,
SSR and client paths break through!
Body safe from locks so deep, 🍃

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title directly describes the two main fixes: profile writes hanging and non-functional auth middleware, matching the core changes in the changeset.
Description check ✅ Passed The description comprehensively covers objectives, causes, and verification results, but lacks explicit checklist completion status and some required template sections.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/profile-writes-hang

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@netlify

netlify Bot commented Jun 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for monumental-speculoos-a69398 ready!

Name Link
🔨 Latest commit f42c768
🔍 Latest deploy log https://app.netlify.com/projects/monumental-speculoos-a69398/deploys/6a299dfd7413fb0008aeec7c
😎 Deploy Preview https://deploy-preview-19--monumental-speculoos-a69398.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@Tbeaumont79
Tbeaumont79 merged commit 6a532d4 into main Jun 10, 2026
5 of 7 checks passed
@Tbeaumont79
Tbeaumont79 deleted the fix/profile-writes-hang branch July 2, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant