Fix production auth bugs: swallowed error message, dev hint leak

CompleteProfileScreen threw a raw PostgrestError (not an Error instance),
so `err instanceof Error` was false and the real message got swallowed.
LoginScreen's Mailpit hint was showing in production; gated behind DEV.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DUU6CnxECCDeqDNYJgr5x
This commit is contained in:
2026-09-28 09:42:26 -05:00
co-authored by Claude Sonnet 5
parent 26f41b3d4a
commit bcc1dbc284
2 changed files with 14 additions and 9 deletions
@@ -25,7 +25,10 @@ export default function CompleteProfileScreen({ onDone }: { onDone: () => void }
const { error } = await supabase.from('profiles').update({ username: username.trim() }).eq('id', user.id) const { error } = await supabase.from('profiles').update({ username: username.trim() }).eq('id', user.id)
if (error) { if (error) {
throw error.code === '23505' ? new Error('That username is already taken.') : error // PostgrestError is a plain object, not an Error instance — wrap it
// so its message survives the catch block below instead of falling
// through to the generic fallback message.
throw error.code === '23505' ? new Error('That username is already taken.') : new Error(error.message)
} }
onDone() onDone()
} catch (err) { } catch (err) {
+3 -1
View File
@@ -67,6 +67,7 @@ export default function LoginScreen() {
We sent a confirmation link to <span className="font-medium">{email}</span>. You'll need to confirm We sent a confirmation link to <span className="font-medium">{email}</span>. You'll need to confirm
before you can sign in. before you can sign in.
</p> </p>
{import.meta.env.DEV && (
<p className="mt-2 text-[11px] text-slate-400"> <p className="mt-2 text-[11px] text-slate-400">
Local dev: open Mailpit at{' '} Local dev: open Mailpit at{' '}
<a href="http://127.0.0.1:54324" className="underline" target="_blank" rel="noreferrer"> <a href="http://127.0.0.1:54324" className="underline" target="_blank" rel="noreferrer">
@@ -74,6 +75,7 @@ export default function LoginScreen() {
</a>{' '} </a>{' '}
to see it — no real email is sent. to see it — no real email is sent.
</p> </p>
)}
<button <button
onClick={() => { onClick={() => {
setConfirmSent(false) setConfirmSent(false)
@@ -91,7 +93,7 @@ export default function LoginScreen() {
return ( return (
<div className="flex h-screen items-center justify-center bg-slate-50"> <div className="flex h-screen items-center justify-center bg-slate-50">
<form onSubmit={handleSubmit} className="w-full max-w-sm rounded-lg border border-slate-200 bg-white p-6 shadow-sm"> <form onSubmit={handleSubmit} className="w-full max-w-sm rounded-lg border border-slate-200 bg-white p-6 shadow-sm">
<h1 className="text-sm font-semibold text-indigo-700">AV Planner</h1> <h1 className="text-sm font-semibold text-indigo-700">Diagrav</h1>
<p className="mt-1 text-xs text-slate-500">{mode === 'sign-in' ? 'Sign in' : 'Create an account'}</p> <p className="mt-1 text-xs text-slate-500">{mode === 'sign-in' ? 'Sign in' : 'Create an account'}</p>
<button <button