mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 11:12:35 +02:00
On mount, AuthContext.checkAuthStatus restores the persisted "Remember Me" token from localStorage and validates it via GET /auth/me. The catch around that call cleared the token on ANY failure, not just a definitive 401 invalid-token — so a brief backend-not-ready or reverse-proxy hiccup during page load (plausible right after a container restart, e.g. on Unraid) would delete a still-valid token. Because the token was deleted, a reload couldn't recover it and the user was bounced to the login screen. Token validation now retries transient failures (up to 3 attempts with short backoff) and only discards the token on a definitive 401 — which request() already handles (clears the token and dispatches auth:expired). Transient / 5xx / network errors leave the persisted token intact so the session survives a slow load. "Remember Me" stays client-storage only; it does not extend the server-side JWT lifetime (session_max_hours, default 24h). Adds AuthContext tests: transient /auth/me failure keeps the token, a definitive 401 clears it, and a valid token loads the user. Rebuilt frontend bundle.