Skip to content

Fix/cognito groups array and local cors - #25

Merged
Mahakisore7 merged 3 commits into
mainfrom
fix/cognito-groups-array-and-local-cors
Sep 20, 2026
Merged

Mahakisore7 merged 3 commits into
mainfrom
fix/cognito-groups-array-and-local-cors

Conversation

@Mahakisore7

Copy link
Copy Markdown
Contributor

No description provided.

decodeIdToken (apps/web/src/lib/cognito.ts) only handled cognito:groups
as a string, which is the shape API Gateway's HTTP API JWT authorizer
flattens it to server-side (authContext.ts). A real Cognito-issued ID
token always encodes it as a genuine JSON array (e.g. ["owner"]) — the
client-side decode never matched that shape, so every real signed-in
user's role silently resolved to undefined, hiding the Dashboard/Staff
nav links for owners and managers on the live site. Only caught because
a from-scratch signed-in test session showed no Dashboard link despite
the account being in the owner group.

Also fixes the local dev server's CORS config to allow the Authorization
header — apps/web always attaches a real bearer token now, even against
the local API server (which ignores it, per authContext.ts's documented
fallback), but the browser's preflight was rejecting the header before
the request ever reached that fallback.
@Mahakisore7
Mahakisore7 merged commit 1de5a95 into main Sep 20, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant