f397e94418c07ca3f3f7486cf4445f57c8fc7e7e
sessionToken.ts throws when AUTH_SECRET is unset under NODE_ENV=production, so /api/auth/login answered 500 on valid credentials while still returning 401/400 correctly on bad ones. Verified against platform.loyaly.ai, whose responses match that signature exactly. Also reverts NEXT_PUBLIC_API_BASE. platform.loyaly.ai is this same app already deployed (identical /login markup), so the override pointed the app at itself cross-origin, and that endpoint returns no CORS headers. Verified on the production build: valid credentials 200 + session cookie, wrong password 401, malformed 400, and the cookie opens /dashboard, /settings, /stores and /api/stores while an unauthenticated request still gets 307/401. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This is a Next.js project bootstrapped with create-next-app.
Getting Started
First, run the development server:
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
Open http://localhost:3000 with your browser to see the result.
You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.
This project uses next/font to automatically optimize and load Geist, a new font family for Vercel.
Learn More
To learn more about Next.js, take a look at the following resources:
- Next.js Documentation - learn about Next.js features and API.
- Learn Next.js - an interactive Next.js tutorial.
You can check out the Next.js GitHub repository - your feedback and contributions are welcome!
Deploy on Vercel
The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.
Check out our Next.js deployment documentation for more details.
Description
Languages
TypeScript
94.4%
CSS
3.5%
JavaScript
1.6%
Dockerfile
0.3%
Shell
0.2%