◐ Off-By-One · answer catalog

unauthorized-401-anonymous-error-cards-sign-in-prompt

1 answer(s)typescriptbunker-dogfood

unauthorized-401-anonymous-error-cards-sign-in-prompt

📦 Source in repository (JSON)

Answer

The solution is written to /workspace/SOLUTION.md. Note that the dexdat-core repository itself was not checked out in this environment — only /workspace/problem.json describing the bug was present — so I could not execute the build/tests/guard against real code. The solution is instead derived from the precise blueprint in the problem class description.

Here is the summary of the fix:

Root cause

The four server-component pages (/tags, /contexts, /identities, /datapoints) catch every failure from the shared client (frontend/src/lib/api.ts) and render the generic error card. When an anonymous user hits any of them, the API returns 401 Not authenticated (an ApiError with status === 401), so they see an opaque error card instead of an authentication prompt. A 401 is an auth condition, not a data/network failure, and deserves dedicated UX.

The three-part fix

  1. frontend/src/lib/api.ts — add an exported isUnauthorized(err) helper: err instanceof ApiError && err.status === 401, so pages share one well-named check.
  2. frontend/src/components/auth/SignInPrompt.tsx — new server-compatible component with role="alert", a heading "You need to sign in", and links to /auth/login and /auth/register.
  3. Four pages — in the catch block, if (isUnauthorized(error)) return <SignInPrompt />; and keep the existing error card for all other failures; success path unchanged.

Verification section

The full document with ready-to-adapt code for frontend/src/lib/api.ts, SignInPrompt.tsx, all four page files, and the test snippets is in /workspace/SOLUTION.md. If you can provide the actual repo checkout, I can drop the code in and run the build, vitest suites, guard, and judge to verify end-to-end.

Evidence & signatures

# Evidence
- Problem class: unauthorized-401-anonymous-error-cards-sign-in-prompt
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-18T03:10:02.820Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Bunker dogfood finding: anonymous users visiting FE pages /tags,/contexts,/identities,/datapoints get error cards instead of a sign-in prompt. Shared api client (frontend/src/lib/api.ts) throws ApiError with status 401; pages rendered generic error UI. Fix: isUnauthorized() helper in the shared client (status===401), new SignInPrompt component (links /auth/login + /auth/register), 4 pages render prompt on 401 and keep error card for other failures. 11 new vitest tests, next build OK, guard PASS 5/5, judge PASS f18e2bcf.", "environment": "bunker-dogfood", "language": "typescript", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "unauthorized-401-anonymous-error-cards-sign-in-prompt", "provider": "openrouter", "solved_at": "2026-08-18T03:10:02.821Z", "version": "nextjs-app-router"}
Generated from the verified corpus · MIT licensedBack to the catalog