From e4b6d5db21ac5b35ebb6cdb6f49e2b26ef34a01d Mon Sep 17 00:00:00 2001 From: openhands Date: Tue, 21 Jul 2026 15:37:52 +0200 Subject: [PATCH] fix: detect auth errors in SSE clients Audit and repair-icons clients now check the Content-Type before reading the stream. If the server returns JSON (e.g. CSRF/permission error), the error message is shown as a toast instead of silently consuming the response as an empty SSE stream. --- src/app/admin/import/audit/audit-client.tsx | 13 +++++++++++++ .../import/repair-icons/repair-icons-client.tsx | 13 +++++++++++++ 2 files changed, 26 insertions(+) diff --git a/src/app/admin/import/audit/audit-client.tsx b/src/app/admin/import/audit/audit-client.tsx index 64c918f3..a4e6a2db 100644 --- a/src/app/admin/import/audit/audit-client.tsx +++ b/src/app/admin/import/audit/audit-client.tsx @@ -104,6 +104,19 @@ export function AuditClient() { return; } + if (!res.headers.get("content-type")?.includes("text/event-stream")) { + let errMsg = "Audit failed"; + try { + const json = await res.json(); + errMsg = json.error || errMsg; + } catch { + // ignore + } + toast.error(errMsg); + setLoading(false); + return; + } + const reader = res.body.getReader(); const decoder = new TextDecoder(); let buf = ""; diff --git a/src/app/admin/import/repair-icons/repair-icons-client.tsx b/src/app/admin/import/repair-icons/repair-icons-client.tsx index 1c479dce..c126c305 100644 --- a/src/app/admin/import/repair-icons/repair-icons-client.tsx +++ b/src/app/admin/import/repair-icons/repair-icons-client.tsx @@ -49,6 +49,19 @@ export function RepairIconsClient() { return; } + if (!res.headers.get("content-type")?.includes("text/event-stream")) { + let errMsg = "Repair failed"; + try { + const json = await res.json(); + errMsg = json.error || errMsg; + } catch { + // ignore + } + toast.error(errMsg); + setRunning(false); + return; + } + const reader = res.body.getReader(); const decoder = new TextDecoder(); let buf = "";