From 217f411f744179443cdb7a66748853548a402ff9 Mon Sep 17 00:00:00 2001 From: John O'Keefe Date: Mon, 28 Sep 2026 08:45:01 -0400 Subject: [PATCH] =?UTF-8?q?fix(auth):=20GetProfile=20reads=20the=20user=20?= =?UTF-8?q?row=20=E2=80=94=20the=20JWT=20context=20stub=20has=20no=20theme?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit GetProfile returned the theme from the JWT-claims context stub, which carries only id/email/username/role — user.Theme was always empty, so the profile response omitted the field and the app's account-theme read-back (SERVER sync mode) could never see the stored theme. GetProfile now loads the full user row by id (h.db.GetUser). --- internal/handlers/auth.go | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/internal/handlers/auth.go b/internal/handlers/auth.go index 991ba0c..796939c 100644 --- a/internal/handlers/auth.go +++ b/internal/handlers/auth.go @@ -486,7 +486,14 @@ window.location.href = '%s'; // GetProfile handles GET /api/auth/profile func (h *AuthHandler) GetProfile(c *echo.Context) error { - user := MustGetAuthenticatedUser(c) + ctxUser := MustGetAuthenticatedUser(c) + // The context user is a JWT-claims stub (id/email/username/role) — + // it carries no theme. Read the full row: clients (the Android app) + // sync their app-chrome theme from this field. + user, err := h.db.GetUser(c.Request().Context(), ctxUser.ID) + if err != nil { + return c.JSON(http.StatusInternalServerError, map[string]string{"error": "failed to load profile"}) + } firstName := "" if user.FirstName.Valid {