fix(auth,organizations): surface failures in org-create and email-verification flows - #4451
Conversation
…ification flows - organization.create.view.vue: the create() catch only logged to the console, leaving the user with no feedback on failure. Surface err.response.data.message (with fallbacks) via a v-alert, mirroring the pattern applied to organizationSetup.component.vue (f92003d). - verifyEmail.view.vue: the refreshAbilities() -> token() swap (#4431) dropped the "stay on page if the refresh fails" bail-out, since token() never throws. After the soft-refresh, bail out (no redirecting UI, no navigation) unless the store actually has a populated user, mirroring the isLoggedIn/!user check app.router.js already uses to detect a stale/failed refresh. Closes #4447 Claude-Session: https://claude.ai/code/session_01WfNC8bt1TgL4AsiYgCEGup
|
Warning Review limit reached
Next review available in: 56 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (5)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #4451 +/- ##
=======================================
Coverage 99.56% 99.56%
=======================================
Files 35 35
Lines 1391 1391
Branches 436 436
=======================================
Hits 1385 1385
Misses 6 6 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
…t race (#4464) * fix(auth,organizations): guard soft-refresh navigation and the signout race organization.create.view.vue's create() awaited authStore.token() (a soft-refresh that never throws on failure) and then pushed unconditionally. A transient blip left authStore.user.currentOrganization falsy, and the app-router org-guard bounced the just-created org straight back to /organization-required. Guard the navigation on currentOrganization being populated, mirroring organizations.required.view.vue's refresh()/ acceptInvitation() and verifyEmail.view.vue's bail (#4451). On a stalled refresh the organization already exists server-side, so it's kept for a manual retry instead of being lost behind a dead-end error. auth.store.js's signout() had no guard against an in-flight token()/ refreshAbilities() resolving after it and re-populating auth=true/user/ localStorage. Added a module-scope generation counter (mirrors the isRefreshingAbilities dedup flag in lib/services/axios.js): signout() bumps it synchronously before anything else; token()/refreshAbilities() capture it before their network await and drop stale continuations that resolve after a concurrent signout already ran. Closes #4459 Claude-Session: https://claude.ai/code/session_01WfNC8bt1TgL4AsiYgCEGup * fix(organizations): prevent duplicate org creation on pending-refresh retry Phase-0 review findings on #4459's soft-refresh guard: - HIGH: the error alert's `closable`/@click:close only cleared `error`, never `pendingOrg`. Dismissing the banner instead of clicking its inline Retry left the still-enabled primary "Create Organization" button wired to create() — clicking it called createOrganization() a second time with the same data, duplicating the org server-side. The primary button now routes through handlePrimaryAction(): while pendingOrg is set it always calls retryRefresh(), regardless of whether the alert was dismissed, and its label switches to "Retry" to match. - LOW: auth.store.js's refreshAbilities() catch path unconditionally called signout() + rethrew, even when the /token request only failed because a concurrent signout() had already invalidated the generation (e.g. the session cookie is gone). That could surface a stale "session expired" error right after a deliberate signout. The catch now checks the same generation guard as the success path and swallows silently when stale. Claude-Session: https://claude.ai/code/session_01WfNC8bt1TgL4AsiYgCEGup * docs(auth): scope the generation-guard comment to what it actually covers The doc comment implied signout() invalidates any concurrent soft-refresh continuation. It only covers calls captured before signout()'s synchronous bump — a call starting during signout()'s own async window is not guarded. No logic change, comment-only clarification.
# [2.3.0](v2.2.0...v2.3.0) (2026-08-01) ### Bug Fixes * **auth,organizations:** guard soft-refresh navigation and the signout race ([#4464](#4464)) ([6a2546e](6a2546e)), closes [#4451](#4451) [#4459](#4459) * **auth,organizations:** soft-refresh (token) at onboarding sites to prevent silent sign-out ([#4431](#4431)) ([5d88766](5d88766)) * **auth,organizations:** surface failures in org-create and email-verification flows ([#4451](#4451)) ([b161df5](b161df5)), closes [#4431](#4431) [#4447](#4447) * **auth:** surface requestJoin failures in the org-setup alert ([#4389](#4389)) ([#4397](#4397)) ([f92003d](f92003d)) * **auth:** token() soft-refresh also carries pendingRequests ([#4436](#4436)) ([0b40e8c](0b40e8c)) * **billing:** config-source the upgrade-prompt pricing copy ([#4465](#4465)) ([9cb370d](9cb370d)), closes [#4460](#4460) * **billing:** meter-mode upgrade prompt copy + single-entry route ([#4410](#4410)) ([df396cf](df396cf)), closes [pricing#units](https://github.com/pricing/issues/units) [pricing#units](https://github.com/pricing/issues/units) * **billing:** migrate default packs to the V4 pricing-card schema ([#4463](#4463)) ([84789b8](84789b8)), closes [pricing#units](https://github.com/pricing/issues/units) [#4458](#4458) * **core,organizations:** config-gate org-required header + unify first-org redirect ([#4423](#4423)) ([7adb298](7adb298)), closes [#4421](#4421) [#4422](#4422) * **core:** wire the computed theme into Vuetify so auto dark-mode works ([#4466](#4466)) ([ed35252](ed35252)), closes [#4462](#4462) * **prerender:** strip local server origin from captured HTML + fail-hard leak assert ([#4502](#4502)) ([#4503](#4503)) ([dbcf8d7](dbcf8d7)) * **skills:** flip PR to ready before waiting on CodeRabbit to avoid a draft deadlock ([#4473](#4473)) ([a733998](a733998)), closes [#4450](#4450) ### Features * **billing:** pricing feature rows wrap + explicit ✗ not-included marker ([#4390](#4390)) ([4bc2515](4bc2515)) * **invitations:** show invite form when user-facing invitations enabled with open signup ([#4501](#4501)) ([daa6688](daa6688)), closes [#4500](#4500) * **skills:** /feature non-interactive invocation — structured SKIP/STOP instead of prompts ([#4455](#4455)) ([197c5f3](197c5f3)), closes [#N](https://github.com/pierreb-devkit/Vue/issues/N) [#failure](https://github.com/pierreb-devkit/Vue/issues/failure) [#4454](#4454) * **ui:** config-overridable loader, plan-badge set, and copy strings ([#4475](#4475)) ([688911a](688911a)), closes [#4474](#4474)
Summary
organization.create.view.vue: thecreate()catch block only logged to the console, leaving the user with no feedback on failure. It now surfaceserr.response.data.message(witherr.message/ generic fallbacks) via a closablev-alert, mirroring the existing pattern inorganizationSetup.component.vue.verifyEmail.view.vue: regains its stay-on-page bail-out via a!authStore.userguard after the post-verificationtoken()soft-refresh.token()never throws (unlike therefreshAbilities()it replaced in fix(auth,organizations): soft-refresh (token) at onboarding sites to prevent silent sign-out #4431), so a failed soft-refresh previously fell through into the redirect branch and showed "Redirecting..." on stale state instead of the verified-success message.auth.store.js:token()now also populatespendingRequestsfrom the response (superset of whatrefreshAbilities()carried), so the org-required wall's join-banner/duplicate-request guard stays accurate after a soft-refresh.Scope
auth,organizationsValidation
npm run lintnpm run test:unit— 2463 tests green, including 7 new state-asserting tests covering both flowsnpm run buildGuardrails check
.env*,secrets/**, keys, tokens)Notes for reviewers
ERRORS.mddocuments the throwing-action → silent-action swap pitfall for future reference (see therefreshAbilities()→token()swap in fix(auth,organizations): soft-refresh (token) at onboarding sites to prevent silent sign-out #4431).https://claude.ai/code/session_01WfNC8bt1TgL4AsiYgCEGup