Signing in showed the "Welcome back!" toast but never left /login. The
session cookie was host-only on the API subdomain, so the Next middleware
guard on the site origin saw no cookie and bounced /dashboard straight
back to /login?redirect=/dashboard.
Add AUTH_COOKIE_DOMAIN, wiring Better Auth's crossSubDomainCookies so
the cookie also reaches the site origin. Unset in dev, where localhost
is single-host and must stay host-only.
Navigate after authentication with a full page load, via a shared
authRedirect helper: only a top-level request carries the httpOnly
cookie. Used by the login, register, magic-link and Google flows.
Show "Redirecting..." on the login and register pages and keep the
submit button disabled until the browser replaces the page, instead of
re-enabling it mid-navigation.
Guard against a redirect loop with a sessionStorage marker. A React ref
cannot do this: the full page load resets component state. If the
destination bounces back, explain it rather than navigating again.
Middleware: accept any *.session_token cookie so a cookiePrefix change
cannot lock everyone out, and preserve the destination's query string.
Trust any loopback port in dev, so reaching the dev server through a
forwarded port does not fail Better Auth's CSRF origin check.
Signing in showed the "Welcome back!" toast but never left /login. The
session cookie was host-only on the API subdomain, so the Next middleware
guard on the site origin saw no cookie and bounced /dashboard straight
back to /login?redirect=/dashboard.
- Add AUTH_COOKIE_DOMAIN, wiring Better Auth's crossSubDomainCookies so
the cookie also reaches the site origin. Unset in dev, where localhost
is single-host and must stay host-only.
- Navigate after authentication with a full page load, via a shared
authRedirect helper: only a top-level request carries the httpOnly
cookie. Used by the login, register, magic-link and Google flows.
- Show "Redirecting..." on the login and register pages and keep the
submit button disabled until the browser replaces the page, instead of
re-enabling it mid-navigation.
- Guard against a redirect loop with a sessionStorage marker. A React ref
cannot do this: the full page load resets component state. If the
destination bounces back, explain it rather than navigating again.
- Middleware: accept any *.session_token cookie so a cookiePrefix change
cannot lock everyone out, and preserve the destination's query string.
- Trust any loopback port in dev, so reaching the dev server through a
forwarded port does not fail Better Auth's CSRF origin check.
Signing in showed the "Welcome back!" toast but never left /login. The
session cookie was host-only on the API subdomain, so the Next middleware
guard on the site origin saw no cookie and bounced /dashboard straight
back to /login?redirect=/dashboard.
- Add AUTH_COOKIE_DOMAIN, wiring Better Auth's crossSubDomainCookies so
the cookie also reaches the site origin. Unset in dev, where localhost
is single-host and must stay host-only.
- Navigate after authentication with a full page load, via a shared
authRedirect helper: only a top-level request carries the httpOnly
cookie. Used by the login, register, magic-link and Google flows.
- Show "Redirecting..." on the login and register pages and keep the
submit button disabled until the browser replaces the page, instead of
re-enabling it mid-navigation.
- Guard against a redirect loop with a sessionStorage marker. A React ref
cannot do this: the full page load resets component state. If the
destination bounces back, explain it rather than navigating again.
- Middleware: accept any *.session_token cookie so a cookiePrefix change
cannot lock everyone out, and preserve the destination's query string.
- Trust any loopback port in dev, so reaching the dev server through a
forwarded port does not fail Better Auth's CSRF origin check.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Signing in showed the "Welcome back!" toast but never left /login. The
session cookie was host-only on the API subdomain, so the Next middleware
guard on the site origin saw no cookie and bounced /dashboard straight
back to /login?redirect=/dashboard.
the cookie also reaches the site origin. Unset in dev, where localhost
is single-host and must stay host-only.
authRedirect helper: only a top-level request carries the httpOnly
cookie. Used by the login, register, magic-link and Google flows.
submit button disabled until the browser replaces the page, instead of
re-enabling it mid-navigation.
cannot do this: the full page load resets component state. If the
destination bounces back, explain it rather than navigating again.
cannot lock everyone out, and preserve the destination's query string.
forwarded port does not fail Better Auth's CSRF origin check.