c01c750436eb8959122eb8681e55e4f6c7e5c6d2
`storeTokens()` and `createSessionToken()` ran outside any catch. Both read AUTH_SECRET — one derives the AES key that encrypts the platform bundle, the other signs the identity cookie — and in production both refuse to fall back to the development key. So an unset AUTH_SECRET threw after the credentials had already been accepted upstream, and the browser got a bare 500 on a sign-in that was entirely valid. The status was the smaller half. The upstream session minted moments earlier by `authApi.login` was ORPHANED: a live refresh token, issued to somebody who did not end up logged in, left to expire on its own. The platform-admin branch a few lines above already revokes for precisely this reason — declining because the server is broken is no different from declining because the account is wrong — so this now revokes too, best-effort, on the same terms. It fails closed. No cookie is set on this path, so a half-configured server cannot hand out a session it will be unable to verify on the next request. ConfigError moves to src/shared/errors/configError.ts because its throwers now span two runtimes: apiClient and tokenStore are server-only, while sessionToken is reached from src/proxy.ts, which Next compiles for Edge. Declaring it in apiClient would have dragged the whole platform client, `server-only` guard and all, into the proxy bundle to name one class. The new module imports nothing. Verified by exercising both functions directly: with AUTH_SECRET unset under NODE_ENV=production, sealTokens and createSessionToken each raise ConfigError rather than a bare Error; with it set, both succeed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This is a Next.js project bootstrapped with create-next-app.
Getting Started
First, run the development server:
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
Open http://localhost:3000 with your browser to see the result.
You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.
This project uses next/font to automatically optimize and load Geist, a new font family for Vercel.
Learn More
To learn more about Next.js, take a look at the following resources:
- Next.js Documentation - learn about Next.js features and API.
- Learn Next.js - an interactive Next.js tutorial.
You can check out the Next.js GitHub repository - your feedback and contributions are welcome!
Deploy on Vercel
The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.
Check out our Next.js deployment documentation for more details.
Description
Languages
TypeScript
95.4%
CSS
2.9%
JavaScript
0.9%
Dockerfile
0.6%
Shell
0.2%