mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-10-06 17:42:05 -04:00
* fix(auth): return 401 JSON for AJAX requests on session timeout (#4696) IsLoggedIn previously threw RedirectException('login') for every request type. For XHR calls the browser transparently followed the 302 and fetched the login page's HTML where JSON was expected, so the table silently rendered empty and the failure looked like a broken sort. - Server: IsLoggedIn::before() now returns a JSON 401 response when the request is an AJAX call, keeping the redirect behavior for normal navigations. - Client: a global $(document).ajaxError handler in the authenticated layout redirects to the login URL on a 401 response. * fix(auth): run isLoggedIn before csrf for expired sessions (#4696) An expired-session AJAX POST with an invalid CSRF token was hitting the globally-configured csrf filter first, which throws a CSRF exception before isLoggedIn can return its 401. Reorder the global before-filters so the authentication check runs before CSRF validation; CSRF protection is fully retained for authenticated requests. --------- Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>