Store Tracker is a PWA behind the shared Authentik forward-auth provider. When the session expires (Android Chrome evicts the PWA cookie), the same-origin /api XHR is 302'd cross-origin and CORS-blocked, the app showed only a generic "backend connection" error, and the service worker served the cached shell for any navigation — so re-auth was impossible without clearing all site data. Fix: - App swaps to a "Session expired" screen on an auth error (axios error with no response, or 401/403) while online. Its "Sign in" button unregisters the service worker + deletes all caches before navigating (programmatic "clear site data"), so the re-auth navigation reaches forward-auth -> Authentik. - vite.config: navigateFallbackDenylist [/[?&]reauth=/] keeps the SW from serving the cached shell for the re-auth navigation. Same bug class fixed in books (#19), speedracer, and vpn-stats. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018rXJ49eToZ6YFZzDYH8GXd
66 lines
1.8 KiB
TypeScript
66 lines
1.8 KiB
TypeScript
import { defineConfig } from 'vite'
|
|
import react from '@vitejs/plugin-react'
|
|
import tailwindcss from '@tailwindcss/vite'
|
|
import { VitePWA } from 'vite-plugin-pwa'
|
|
|
|
export default defineConfig({
|
|
plugins: [
|
|
react(),
|
|
tailwindcss(),
|
|
VitePWA({
|
|
registerType: 'autoUpdate',
|
|
includeAssets: ['favicon.svg'],
|
|
manifest: {
|
|
name: 'Store Tracker',
|
|
short_name: 'Stores',
|
|
description: 'Manage store matching rules for Firefly transaction categorization',
|
|
theme_color: '#0f1117',
|
|
background_color: '#0f1117',
|
|
display: 'standalone',
|
|
orientation: 'portrait',
|
|
scope: '/',
|
|
start_url: '/',
|
|
icons: [
|
|
{
|
|
src: 'pwa-192.png',
|
|
sizes: '192x192',
|
|
type: 'image/png',
|
|
},
|
|
{
|
|
src: 'pwa-512.png',
|
|
sizes: '512x512',
|
|
type: 'image/png',
|
|
},
|
|
{
|
|
src: 'pwa-512.png',
|
|
sizes: '512x512',
|
|
type: 'image/png',
|
|
purpose: 'any maskable',
|
|
},
|
|
],
|
|
},
|
|
workbox: {
|
|
globPatterns: ['**/*.{js,css,html,svg,png,ico}'],
|
|
// Re-auth navigations (?reauth=) must reach the network so Authentik's
|
|
// forward-auth redirect can fire — never serve the cached app shell for
|
|
// them (the default NavigationRoute otherwise blocks re-login).
|
|
navigateFallbackDenylist: [/[?&]reauth=/],
|
|
runtimeCaching: [
|
|
{
|
|
urlPattern: /^\/api\//,
|
|
handler: 'NetworkFirst',
|
|
options: {
|
|
cacheName: 'api-cache',
|
|
expiration: { maxEntries: 50, maxAgeSeconds: 300 },
|
|
},
|
|
},
|
|
],
|
|
},
|
|
}),
|
|
],
|
|
server: {
|
|
proxy: {
|
|
'/api': 'http://192.168.1.80:45581',
|
|
},
|
|
},
|
|
})
|