sessionToken.ts throws when AUTH_SECRET is unset under NODE_ENV=production, so /api/auth/login answered 500 on valid credentials while still returning 401/400 correctly on bad ones. Verified against platform.loyaly.ai, whose responses match that signature exactly. Also reverts NEXT_PUBLIC_API_BASE. platform.loyaly.ai is this same app already deployed (identical /login markup), so the override pointed the app at itself cross-origin, and that endpoint returns no CORS headers. Verified on the production build: valid credentials 200 + session cookie, wrong password 401, malformed 400, and the cookie opens /dashboard, /settings, /stores and /api/stores while an unauthenticated request still gets 307/401. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2.1 KiB
2.1 KiB