Store Tracker is a PWA behind the shared Authentik forward-auth provider.
When the session expires (Android Chrome evicts the PWA cookie), the same-origin
/api XHR is 302'd cross-origin and CORS-blocked, the app showed only a generic
"backend connection" error, and the service worker served the cached shell for
any navigation — so re-auth was impossible without clearing all site data.
Fix:
- App swaps to a "Session expired" screen on an auth error (axios error with no
response, or 401/403) while online. Its "Sign in" button unregisters the
service worker + deletes all caches before navigating (programmatic "clear
site data"), so the re-auth navigation reaches forward-auth -> Authentik.
- vite.config: navigateFallbackDenylist [/[?&]reauth=/] keeps the SW from
serving the cached shell for the re-auth navigation.
Same bug class fixed in books (#19), speedracer, and vpn-stats.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018rXJ49eToZ6YFZzDYH8GXd
Manifest with standalone display, dark theme color, 192/512 icons.
NetworkFirst workbox strategy for API routes. Dockerfile uses
--legacy-peer-deps for vite-plugin-pwa peer dep conflict with Vite 8.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>