memos/web/src/utils/auth-redirect.ts
Steven 6db58fae11 fix: prevent private memos from disappearing during token refresh (#5565)
Root cause: enabled={isInitialized && !!user} prevented displaying cached
data when user auth state transitioned during token refresh.

Changes:
- Remove !!user check from Home page enabled condition
- Add clearAccessToken() in redirectOnAuthFailure for clean logout

Fixes #5565
2026-02-02 21:45:24 +08:00

41 lines
1.5 KiB
TypeScript

import { clearAccessToken } from "@/auth-state";
import { getInstanceConfig } from "@/instance-config";
import { ROUTES } from "@/router/routes";
const PUBLIC_ROUTES = [
ROUTES.AUTH, // Authentication pages
ROUTES.EXPLORE, // Explore page
"/u/", // User profile pages (dynamic)
"/memos/", // Individual memo detail pages (dynamic)
] as const;
const PRIVATE_ROUTES = [ROUTES.ROOT, ROUTES.ATTACHMENTS, ROUTES.INBOX, ROUTES.ARCHIVED, ROUTES.SETTING] as const;
function isPublicRoute(path: string): boolean {
return PUBLIC_ROUTES.some((route) => path.startsWith(route));
}
function isPrivateRoute(path: string): boolean {
return PRIVATE_ROUTES.includes(path as (typeof PRIVATE_ROUTES)[number]);
}
export function redirectOnAuthFailure(): void {
const currentPath = window.location.pathname;
// Don't redirect if it's a public route
if (isPublicRoute(currentPath)) {
return;
}
const disallowPublicVisibility = getInstanceConfig().memoRelatedSetting.disallowPublicVisibility;
const target = disallowPublicVisibility ? ROUTES.AUTH : ROUTES.EXPLORE;
// Only redirect if it's a private route or disallowPublicVisibility is enabled
if (disallowPublicVisibility || isPrivateRoute(currentPath)) {
// Clear access token to ensure user is fully logged out
// This prevents the issue where user appears logged in but sees only public memos
// See: https://github.com/usememos/memos/issues/5565
clearAccessToken();
window.location.replace(target);
}
}