diff --git a/src/app/(auth)/login/page.tsx b/src/app/(auth)/login/page.tsx index 4755523..651075d 100644 --- a/src/app/(auth)/login/page.tsx +++ b/src/app/(auth)/login/page.tsx @@ -15,19 +15,15 @@ export default function LoginPage() { const [loading, setLoading] = useState(false); const [userType, setUserType] = useState<'USER' | 'ADMIN'>('USER'); - // Safety net: clear logout flags when login page loads. - // This resets both the localStorage flag and the module-level flag in api.ts - // so the API interceptor stops blocking requests. - if (typeof window !== 'undefined') { - localStorage.removeItem('isLoggingOut'); - resetLogoutState(); - } - const handleSubmit = async (e: React.FormEvent) => { e.preventDefault(); setLoading(true); setError(''); + // Clear logout flags now that user is actively logging in + localStorage.removeItem('isLoggingOut'); + resetLogoutState(); + try { // First, validate credentials with backend to get proper error messages const validateRes = await fetch(`${process.env.NEXT_PUBLIC_API_URL}/auth/login`, { diff --git a/src/components/providers/session-provider.tsx b/src/components/providers/session-provider.tsx index 221737a..9b140fe 100644 --- a/src/components/providers/session-provider.tsx +++ b/src/components/providers/session-provider.tsx @@ -9,11 +9,13 @@ function TokenSync() { const hasInitialized = useRef(false); useEffect(() => { - // Never restore tokens if a logout is in progress or we're on the logout page + // Never restore tokens if a logout is in progress or we're on auth/logout pages const loggingOut = localStorage.getItem("isLoggingOut") === "true"; - const onLogoutPage = window.location.pathname === "/logout"; + const path = window.location.pathname; + const onAuthPage = path === "/login" || path === "/signup" || path === "/logout" + || path.startsWith("/forgot-password") || path.startsWith("/reset-password"); - if (status === "authenticated" && session?.user && !loggingOut && !onLogoutPage) { + if (status === "authenticated" && session?.user && !loggingOut && !onAuthPage) { const user = session.user as { accessToken?: string; refreshToken?: string }; // Only sync tokens from NextAuth to localStorage if: diff --git a/src/services/api.ts b/src/services/api.ts index 883bce8..e7fb789 100644 --- a/src/services/api.ts +++ b/src/services/api.ts @@ -76,7 +76,8 @@ const api: AxiosInstance = axios.create({ api.interceptors.request.use( (config: InternalAxiosRequestConfig) => { // Skip API calls during logout to prevent refresh loops - if (isLoggingOut) { + // Check both module flag and localStorage flag (logout page sets localStorage directly) + if (isLoggingOut || (typeof window !== 'undefined' && localStorage.getItem('isLoggingOut') === 'true')) { return Promise.reject(new axios.Cancel('Logging out')); } // Add auth token if available