Skip to content

fix: render the nearest error page when a form submission receives a non-ActionResult error response - #16308

Merged
Rich-Harris merged 6 commits into
sveltejs:version-3from
Nic-Polumeyv:fix-enhance-non-action-response
Aug 19, 2026
Merged

fix: render the nearest error page when a form submission receives a non-ActionResult error response#16308
Rich-Harris merged 6 commits into
sveltejs:version-3from
Nic-Polumeyv:fix-enhance-non-action-response

Conversation

@Nic-Polumeyv

@Nic-Polumeyv Nic-Polumeyv commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

closes #15737

Submitting a use:enhance form that trips the CSRF origin check does nothing visible. The 403 response is right there in the network tab:

{ "message": "Cross-site POST form submissions are forbidden" }

but it has no type, so it isn't an ActionResult and every branch in the submit handler and applyAction skips it. Non-JSON responses already become { type: 'error' } through the catch around deserialize, so JSON that isn't an ActionResult was the one shape that failed silently.

Error responses without a recognized type now throw into that same catch and render the nearest +error.svelte. A body shaped like an App.Error becomes page.error as-is, the way an error(403, { message }) body does. Anything else goes through handleError, which #16162 routed this catch through, so the hook keeps seeing these failures and page.error keeps its declared shape. 2xx responses are untouched.

PatrickG suggested rendering the error page in the issue. teemingc flagged the same gap in #10464 with a server-side shape fix in mind; doing it on the client also covers proxy and middleware responses that kit's server never shaped. #10855 reports the same class of unhelpful failure for non-action endpoints; the non-2xx half of it is covered here.

Responses that do parse as an ActionResult pass through regardless of status, which keeps the pattern that prompted the #13197 revert (#13397) working. The docs line that revert added says posting to a +server.js endpoint results in an error; with this change that error surfaces instead of failing silently.

The test mimics the CSRF response with an endpoint, since the real check can't fire same-origin in Playwright. It fails on version-3 and passes with this change, in dev and build. The hook suffix in two of the assertions is handleError running.


Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

  • It's really useful if your PR references an issue where it is discussed ahead of time. In many cases, features are absent for a reason. For large changes, please create an RFC: https://github.com/sveltejs/rfcs
  • This message body should clearly illustrate what problems it solves.
  • Ideally, include a test that fails without this PR but passes with it.

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

@pkg-svelte-dev

pkg-svelte-dev Bot commented Jul 10, 2026

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 349456c:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/349456c2ad45d66f98915d54a1b61f605b4f5712

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16308

Note

This PR is from a fork. A maintainer must approve approve each commit before it can be built and installed.

@changeset-bot

changeset-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 349456c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@Nic-Polumeyv
Nic-Polumeyv changed the base branch from main to version-3 July 15, 2026 01:07
@Nic-Polumeyv
Nic-Polumeyv force-pushed the fix-enhance-non-action-response branch from bc20af6 to 6a8cd3b Compare July 15, 2026 01:07
Rich-Harris pushed a commit that referenced this pull request Jul 25, 2026
`data-sveltekit-preload-data` fails intermittently under server-side
route resolution, about 1 in 6 locally on `version-3`, and anything that
shifts hydration timing makes it worse (a one-line import change on
#16308 took it to 3 failed retries in CI).

The test navigates between phases with the cursor still parked over the
previous phase's link. When the fresh page hydrates, Chromium fires a
mouse event at that position and the router preloads that link's target,
so the phase that expects zero requests counts a preload it never
triggered. A request timeline shows the target's `__route.js`, node
script and `__data.json` all arriving before the phase's `goto`
resolves, ahead of any hover.

Parking the mouse before each navigation removes the carryover. 10 of 10
runs green under `ROUTER_RESOLUTION=server` with the change.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:
- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests
- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets
- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.
@Nic-Polumeyv
Nic-Polumeyv force-pushed the fix-enhance-non-action-response branch from 07b9af5 to 42d7751 Compare August 6, 2026 19:00
@Rich-Harris
Rich-Harris force-pushed the fix-enhance-non-action-response branch from 42d7751 to 690a6b3 Compare August 18, 2026 17:57
@Rich-Harris
Rich-Harris merged commit 7570a62 into sveltejs:version-3 Aug 19, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

use:enhance does not update form.message when running into a CSRF error

2 participants