Search code examples

Why i can access dahsboard even when my login fail?

I’m having trouble with authentication where I have a Laravel backend and a Nuxt frontend. When I log in and log out successfully, everything works fine. The problem occurs when the login fails due to incorrect credentials, yet I’m still able to access the dashboard. Even though the login fails, I can see a new XSRF token being added in the browser’s Application tab. The issue is that I can access the dashboard and even the profile section, but when I try to log out, I get an error saying I’m unauthorized, which makes sense because the token wasn’t provided. However, for some reason, a session with the XSRF token is hanging around, causing me to be partially logged in even though I’ve entered incorrect login credentials. Does anyone know what could be causing this issue? I’m new to REST APIs, so I’m probably doing something very wrong. This is my useAuth.js

export default function useAuth() {
    const user = useState('auth-user', () => null)

    const { errorBag, transformValidationErrors, resetErrorBag } = useCustomError()

    const { api, csrf } = useAxios()

    async function me() {
        try {
            const data = await api.get("/api/me")
            user.value =
        } catch (e) {
            user.value = null

    function login(userForm) {
        csrf().then(() => {
  "/login", userForm).then(({ data }) => {

                user.value = data.user

                $fetch('/api/set-cookie', {
                    method: "POST",
                    body: { token: data.token }
                }).then(res => {
            }).catch(err => {

    function logout() {"/api/logout").then(() => {
            user.value = null
            $fetch('/api/logout', {
                method: "POST",
            }).then(res => {


    function register(userForm) {

        csrf().then(() => {
  "/register", userForm).then(({ data }) => {
                //   verify email screen
            }).catch(err => {

    return { login, logout, register, errorBag, user, me }


this is my useAxios.js

import axios from "axios";

export default function useAxios(){

    const rtConfig = useRuntimeConfig()
    let api = axios.create({
        baseURL: rtConfig.public.API_URL,
        headers: {
            "Content-Type": "application/json",
            "Accept": "application/json",
            // "Authorization:": "Bearer " + localStorage.getItem("token"),
        withCredentials: true,
        withXSRFToken: true

    async function csrf(){
        return await api.get("/sanctum/csrf-cookie")

    return {
        api, csrf

guest middleware

export default defineNuxtRouteMiddleware((to, from) => {

    const key = process.server ? 'token' : 'XSRF-TOKEN'

    const token = useCookie(key)

        return navigateTo('/')


auth middlware

export default defineNuxtRouteMiddleware((to, from) => {

    const key = process.server ? 'token' : 'XSRF-TOKEN'

    const token = useCookie(key)

        return navigateTo('/')


So even when I defined auth middleware for dashboard page lije this

    middleware: ['auth']

I can still access it, but at all I'm not authorized. I don't understand where is mistake :/


  • It looks like there are a few key points causing the issue:

    1. XSRF Token Handling: The XSRF token (used to protect against CSRF attacks) is being set regardless of whether the login succeeds or fails. This means that even on a failed login, the token is being created and stored, allowing partial access to protected routes.

    2. Authorization Flow: Your auth middleware only checks for the presence of a token, not whether the user is actually authenticated. The XSRF token alone doesn't represent an authenticated session.

    3. Improper Error Handling on Failed Logins: When login fails, your code still sets the XSRF token, which allows partial access.

    Suggestions to Fix:

    1. Fix Login Error Handling: You need to ensure that the token is not set unless the login succeeds. This will prevent setting the XSRF token on failed login attempts. Modify the login function:

      function login(userForm) {
          csrf().then(() => {
    "/login", userForm)
              .then(({ data }) => {
                  user.value = data.user;
                  $fetch('/api/set-cookie', {
                      method: "POST",
                      body: { token: data.token }
                  }).then(res => {
              .catch(err => {
                  // Don't set the user or token on error
                  user.value = null;

      This ensures that if the login fails, the user and token are not set.

    2. Check Authentication in Middleware: The current auth middleware only checks for the presence of a token, which can lead to false positives. Modify it to check the user's authentication status instead of just the token:

      export default defineNuxtRouteMiddleware(async (to, from) => {
          const user = useState('auth-user');
          // Fetch the current user status
          if (!user.value) {
              try {
                  await me(); // Fetch user data from the backend
              } catch (e) {
                  return navigateTo('/login'); // Redirect if user is not authenticated
          // If the user is not authenticated, redirect to login
          if (!user.value) {
              return navigateTo('/login');

      This middleware will ensure that the user is fully authenticated before allowing access to protected routes.

    3. Ensure Session-Based Authentication: If you're using session-based authentication, ensure that withCredentials: true is properly set on all requests and that cookies are being handled correctly by the backend.

    4. Logout Function: The logout process is also critical. It should invalidate the session properly, removing both the user token and any session cookies.

      function logout() {
"/api/logout").then(() => {
              user.value = null;
              $fetch('/api/logout', { method: "POST" }).then(res => {
          }).catch(err => {
              // Handle any logout errors, if needed


    • Network Tab: Check if any Set-Cookie headers are being sent on failed logins. They should only be set on successful login.
    • Check Server-Side Authentication: Ensure that the /api/me route is correctly protected and doesn't return authenticated user data on failed logins.