Skip to content

HIGH: delete-account page broken — wrong URL path, no auth header, misleading error #3

Description

@d-e-v-14

Summary

Severity: High — Account deletion is broken: wrong URL path, no auth header, misleading error message.

Problem

src/app/(app)/delete-account/page.tsx:22-25:

await axios.delete(`${API_BASE_URL}/profile/deleteProfile`, {
  data: { password },
  withCredentials: true,
});
  1. Wrong path: every other endpoint lives under /api/... (e.g. /api/profile/...). /profile/deleteProfile almost certainly 404s.
  2. Bypasses the apiClient interceptor: no Authorization: Bearer header, no auto token-refresh, no error normalization — while every other API call uses apiClient (src/api/axios.ts).
  3. On failure the UI tells the user "Failed to delete profile. Please check your password." (page.tsx:30) even though the request never reached the backend.

Impact

  • Users cannot delete their account from the UI (destructive feature silently broken).
  • Misleading UX: users are told their password is wrong when it isn't.

Fix

Use the shared authenticated client with the correct path:

await apiClient.delete("/api/profile/deleteProfile", { data: { password } });

Confirm the backend route is DELETE /api/profile/deleteProfile (src/routes/profile.ts in the backend) and that it accepts { password } in the body. Remove the raw axios import; handle errors from apiClient (which already normalizes them).

Files

  • src/app/(app)/delete-account/page.tsx (lines 3, 11, 22-31)
  • Backend counterpart: echo-backend/src/routes/profile.ts, echo-backend/src/controllers/profileController.ts:95-107

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions