Summary
Severity: High — Account deletion is broken: wrong URL path, no auth header, misleading error message.
Problem
src/app/(app)/delete-account/page.tsx:22-25:
await axios.delete(`${API_BASE_URL}/profile/deleteProfile`, {
data: { password },
withCredentials: true,
});
- Wrong path: every other endpoint lives under
/api/... (e.g. /api/profile/...). /profile/deleteProfile almost certainly 404s.
- Bypasses the
apiClient interceptor: no Authorization: Bearer header, no auto token-refresh, no error normalization — while every other API call uses apiClient (src/api/axios.ts).
- On failure the UI tells the user
"Failed to delete profile. Please check your password." (page.tsx:30) even though the request never reached the backend.
Impact
- Users cannot delete their account from the UI (destructive feature silently broken).
- Misleading UX: users are told their password is wrong when it isn't.
Fix
Use the shared authenticated client with the correct path:
await apiClient.delete("/api/profile/deleteProfile", { data: { password } });
Confirm the backend route is DELETE /api/profile/deleteProfile (src/routes/profile.ts in the backend) and that it accepts { password } in the body. Remove the raw axios import; handle errors from apiClient (which already normalizes them).
Files
src/app/(app)/delete-account/page.tsx (lines 3, 11, 22-31)
- Backend counterpart:
echo-backend/src/routes/profile.ts, echo-backend/src/controllers/profileController.ts:95-107
Summary
Severity: High — Account deletion is broken: wrong URL path, no auth header, misleading error message.
Problem
src/app/(app)/delete-account/page.tsx:22-25:/api/...(e.g./api/profile/...)./profile/deleteProfilealmost certainly 404s.apiClientinterceptor: noAuthorization: Bearerheader, no auto token-refresh, no error normalization — while every other API call usesapiClient(src/api/axios.ts)."Failed to delete profile. Please check your password."(page.tsx:30) even though the request never reached the backend.Impact
Fix
Use the shared authenticated client with the correct path:
Confirm the backend route is
DELETE /api/profile/deleteProfile(src/routes/profile.tsin the backend) and that it accepts{ password }in the body. Remove the rawaxiosimport; handle errors fromapiClient(which already normalizes them).Files
src/app/(app)/delete-account/page.tsx(lines 3, 11, 22-31)echo-backend/src/routes/profile.ts,echo-backend/src/controllers/profileController.ts:95-107