chore: revert dev error when using use:enhance with +server - #13397
Merged
Conversation
added 2 commits
January 31, 2025 10:25
🦋 Changeset detectedLatest commit: 09580d5 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
6 tasks
dummdidumm
approved these changes
Jan 31, 2025
Merged
|
Thank you! :) |
This was referenced Apr 11, 2026
6 tasks
Rich-Harris
added a commit
that referenced
this pull request
Aug 19, 2026
…non-ActionResult error response (#16308) closes #15737 Submitting a `use:enhance` form that trips the CSRF origin check does nothing visible. The 403 response is right there in the network tab: ```json { "message": "Cross-site POST form submissions are forbidden" } ``` but it has no `type`, so it isn't an ActionResult and every branch in the submit handler and `applyAction` skips it. Non-JSON responses already become `{ type: 'error' }` through the catch around `deserialize`, so JSON that isn't an ActionResult was the one shape that failed silently. Error responses without a recognized `type` now throw into that same catch and render the nearest `+error.svelte`. A body shaped like an `App.Error` becomes `page.error` as-is, the way an `error(403, { message })` body does. Anything else goes through `handleError`, which #16162 routed this catch through, so the hook keeps seeing these failures and `page.error` keeps its declared shape. 2xx responses are untouched. PatrickG suggested rendering the error page in the issue. teemingc flagged the same gap in #10464 with a server-side shape fix in mind; doing it on the client also covers proxy and middleware responses that kit's server never shaped. #10855 reports the same class of unhelpful failure for non-action endpoints; the non-2xx half of it is covered here. Responses that do parse as an ActionResult pass through regardless of status, which keeps the pattern that prompted the #13197 revert (#13397) working. The docs line that revert added says posting to a `+server.js` endpoint results in an error; with this change that error surfaces instead of failing silently. The test mimics the CSRF response with an endpoint, since the real check can't fire same-origin in Playwright. It fails on `version-3` and passes with this change, in dev and build. The hook suffix in two of the assertions is `handleError` running. --- ### Please don't delete this checklist! Before submitting the PR, please make sure you do the following: - [x] It's really useful if your PR references an issue where it is discussed ahead of time. In many cases, features are absent for a reason. For large changes, please create an RFC: https://github.com/sveltejs/rfcs - [x] This message body should clearly illustrate what problems it solves. - [x] Ideally, include a test that fails without this PR but passes with it. ### Tests - [x] Run the tests with `pnpm test` and lint the project with `pnpm lint` and `pnpm check` ### Changesets - [x] If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running `pnpm changeset` and following the prompts. Changesets that add features should be `minor` and those that fix bugs should be `patch`. Please prefix changeset messages with `feat:`, `fix:`, or `chore:`. ### Edits - [x] Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed. --------- Co-authored-by: Nic Polumeyv <nicolas.polum@gmail.com> Co-authored-by: Rich Harris <rich.harris@vercel.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR reverts #13197 since it cause an error for users that used SuperForm's helper that made
+serverresponses compatible withuse:enhance.EDIT: In hindsight, we should probably update the
use:enhancedocs https://svelte.dev/docs/kit/form-actions#Progressive-enhancement to explain that it should only be used with SvelteKit form actions to address the original issue.Please don't delete this checklist! Before submitting the PR, please make sure you do the following:
Tests
pnpm testand lint the project withpnpm lintandpnpm checkChangesets
pnpm changesetand following the prompts. Changesets that add features should beminorand those that fix bugs should bepatch. Please prefix changeset messages withfeat:,fix:, orchore:.Edits