AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Navigation Race Condition In SignInPartner Causes Unintended Redirects On Unmount

SignInPartner component triggers asynchronous authentication calls in useEffect without checking if the component is still mounted. If the user navigates away before promises resolve, router.replace() is called regardless, causing unintended redirects that override the user's current navigation.

highConfidence 95%Next.js

Origin Analysis

The useEffect in SignInPartner.tsx launches an async IIFE that calls auth.getSession() and potentially auth.signInWithIdToken(). There is no cancellation or mounted check; even after unmount, the promise callbacks execute and invoke router.replace(), leading to ghost redirects.
1. Throttle network to Slow 3G. 2. Navigate to /sign-in-partner?partner=foo&id_token=bar. 3. While loader is spinning, press Back or navigate elsewhere. 4. Wait for auth promises to resolve. 5. Observe forced redirect to /sign-in-mfa or /sign-in despite current page.

Fixing Code Block

Edge Case Audit

The isMounted guard prevents post-unmount redirects but does not cancel the underlying network requests. In React 18 Strict Mode (development), effects run twice, causing duplicate auth calls unless properly handled. Also, if the component remounts quickly, the new effect resets isMounted, but any pending async from previous mount may still resolve after new mount; they are guarded by their own isMounted flag (which is false for the previous effect) so no duplicate redirects. However, the async operations themselves still consume resources. Consider using AbortController or a cancellation token if the auth library supports it. Rollback is straightforward: revert to original useEffect without isMounted.

Ecosystem Topology