a40afb9e7af753dddd16144ffe13c8a340be4e63
`GET /api/sites 401 (Unauthorized)` fired on the sign-in page for every visitor who had not signed in yet. WorkspaceProvider sits above the whole route tree, /login included, and it already carried a comment saying the estate was "gated on the session ... asking for the estate before anyone has signed in would put a guaranteed 401 in the console on every visit to the sign-in page". The gate was never applied. `useSites()` was called unconditionally and `isAuthenticated` only guarded the derived `stores` value below it — and a gate on a derived value cannot hold a fetch that has already gone out. useResource has taken `Endpoint<T> | null` for exactly this all along; the effect returns early on a null key, so nothing is sent. The gate goes in useSites rather than in one consumer because the rule belongs to the endpoint — no session, no estate — and /stores calls it too. Costs a signed-in user nothing: SessionProvider resolves `status` synchronously from the server-rendered `initialSession`, so there is no 'loading' pass to wait through before the request goes out. /stores is unaffected in the other direction too — AuthGuard renders a spinner instead of children once status is 'unauthenticated', so no consumer sits on a permanently held resource. Verified in the browser against a clean network buffer: with the gate reverted, /login issues GET /api/sites → 401; with it in place, /login issues 31 requests and none of them are /api/*. Worth being explicit about what this does NOT change: platform.loyaly.ai/api/* is the correct address for these calls. It is this app's own BFF, same-origin by design, and the hop to mcp.loyaly.ai happens server-side where the token lives. The 401 was a request that should never have been made, not a request made to the wrong host. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This is a Next.js project bootstrapped with create-next-app.
Getting Started
First, run the development server:
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
Open http://localhost:3000 with your browser to see the result.
You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.
This project uses next/font to automatically optimize and load Geist, a new font family for Vercel.
Learn More
To learn more about Next.js, take a look at the following resources:
- Next.js Documentation - learn about Next.js features and API.
- Learn Next.js - an interactive Next.js tutorial.
You can check out the Next.js GitHub repository - your feedback and contributions are welcome!
Deploy on Vercel
The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.
Check out our Next.js deployment documentation for more details.
Description
Languages
TypeScript
95.4%
CSS
2.9%
JavaScript
0.9%
Dockerfile
0.6%
Shell
0.2%