TechnicalCollectible prompt
Fix a sign-in redirect loop that won't let users in
Act as a senior engineer who knows auth flows well. In my {{tech_stack}} app, signing in bounces between the sign-in page and a protected page forever, or lands back on sign-in with no error. What happens: {{steps_to_reproduce}}
Gather evidence first:
- In the network tab with Preserve log on, record the whole redirect chain: each URL, status code and Set-Cookie header
- In the application tab, whether the session cookie or token is actually saved, with its domain, path, SameSite and Secure flags
- Server or middleware logs for each request in the loop, showing whether it saw a session
- Whether it happens everywhere, or only on the live domain, in Safari, in a private window, or on preview URLs
Likely causes for this symptom:
1. The protected-route check runs before the session loads on the client, sees no user and redirects; then sign-in sees a user and sends them back
2. The cookie isn't sent: wrong domain (www versus bare domain), Secure on plain http, SameSite blocking it after an OAuth return, or third-party cookies blocked
3. Middleware protects the sign-in page or the auth callback route itself
4. The callback URL isn't in the provider's allowed list for this domain, so the code exchange fails quietly
5. Server and client disagree: the server reads a different cookie or storage than the client writes
6. A role or profile check that fails because new users don't have a profile row yet
Reproduce it, confirm the cause from the evidence, and make the smallest fix, usually waiting for the auth state before deciding, or correcting cookie and URL settings. Don't loosen cookie security or remove the route check. Add a test that signs in, refreshes a protected page and stays on it, and explain the fix in plain words.
Technicalnvoka.com/library/nvoka-fix-a-sign-in-redirect-loopScan to open
Technical
Fix a sign-in redirect loop that won't let users in
Trace why sign-in bounces between pages forever, from cookies to callback URLs, and fix the real cause.
Curated by Nvoka
Claude CodeCursorCodexLovable
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 2 filledYour prompt
Act as a senior engineer who knows auth flows well. In my {{tech_stack}} app, signing in bounces between the sign-in page and a protected page forever, or lands back on sign-in with no error. What happens: {{steps_to_reproduce}}
Gather evidence first:
- In the network tab with Preserve log on, record the whole redirect chain: each URL, status code and Set-Cookie header
- In the application tab, whether the session cookie or token is actually saved, with its domain, path, SameSite and Secure flags
- Server or middleware logs for each request in the loop, showing whether it saw a session
- Whether it happens everywhere, or only on the live domain, in Safari, in a private window, or on preview URLs
Likely causes for this symptom:
1. The protected-route check runs before the session loads on the client, sees no user and redirects; then sign-in sees a user and sends them back
2. The cookie isn't sent: wrong domain (www versus bare domain), Secure on plain http, SameSite blocking it after an OAuth return, or third-party cookies blocked
3. Middleware protects the sign-in page or the auth callback route itself
4. The callback URL isn't in the provider's allowed list for this domain, so the code exchange fails quietly
5. Server and client disagree: the server reads a different cookie or storage than the client writes
6. A role or profile check that fails because new users don't have a profile row yet
Reproduce it, confirm the cause from the evidence, and make the smallest fix, usually waiting for the auth state before deciding, or correcting cookie and URL settings. Don't loosen cookie security or remove the route check. Add a test that signs in, refreshes a protected page and stays on it, and explain the fix in plain words.