store-matching-frontend/vite.config.ts
claude df951ff2ab fix: recover from expired Authentik session without clearing site data
Store Tracker is a PWA behind the shared Authentik forward-auth provider.
When the session expires (Android Chrome evicts the PWA cookie), the same-origin
/api XHR is 302'd cross-origin and CORS-blocked, the app showed only a generic
"backend connection" error, and the service worker served the cached shell for
any navigation — so re-auth was impossible without clearing all site data.

Fix:
- App swaps to a "Session expired" screen on an auth error (axios error with no
  response, or 401/403) while online. Its "Sign in" button unregisters the
  service worker + deletes all caches before navigating (programmatic "clear
  site data"), so the re-auth navigation reaches forward-auth -> Authentik.
- vite.config: navigateFallbackDenylist [/[?&]reauth=/] keeps the SW from
  serving the cached shell for the re-auth navigation.

Same bug class fixed in books (#19), speedracer, and vpn-stats.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018rXJ49eToZ6YFZzDYH8GXd
2026-06-27 09:10:09 -04:00

66 lines
1.8 KiB
TypeScript

import { defineConfig } from 'vite'
import react from '@vitejs/plugin-react'
import tailwindcss from '@tailwindcss/vite'
import { VitePWA } from 'vite-plugin-pwa'
export default defineConfig({
plugins: [
react(),
tailwindcss(),
VitePWA({
registerType: 'autoUpdate',
includeAssets: ['favicon.svg'],
manifest: {
name: 'Store Tracker',
short_name: 'Stores',
description: 'Manage store matching rules for Firefly transaction categorization',
theme_color: '#0f1117',
background_color: '#0f1117',
display: 'standalone',
orientation: 'portrait',
scope: '/',
start_url: '/',
icons: [
{
src: 'pwa-192.png',
sizes: '192x192',
type: 'image/png',
},
{
src: 'pwa-512.png',
sizes: '512x512',
type: 'image/png',
},
{
src: 'pwa-512.png',
sizes: '512x512',
type: 'image/png',
purpose: 'any maskable',
},
],
},
workbox: {
globPatterns: ['**/*.{js,css,html,svg,png,ico}'],
// Re-auth navigations (?reauth=) must reach the network so Authentik's
// forward-auth redirect can fire — never serve the cached app shell for
// them (the default NavigationRoute otherwise blocks re-login).
navigateFallbackDenylist: [/[?&]reauth=/],
runtimeCaching: [
{
urlPattern: /^\/api\//,
handler: 'NetworkFirst',
options: {
cacheName: 'api-cache',
expiration: { maxEntries: 50, maxAgeSeconds: 300 },
},
},
],
},
}),
],
server: {
proxy: {
'/api': 'http://192.168.1.80:45581',
},
},
})