Per ADR-009's known negative: once barback.pezza.dev is behind Cloudflare Access, an expired Access session (~monthly at a 30-day session) makes background fetch calls to /bar/ and /search/ receive an HTML login redirect instead of JSON. Without handling, this surfaces as opaque query failures until the user happens to reload.
- Detect the condition at the API-client boundary (e.g. non-JSON
content-type or a redirect to the Access login on a request that expected JSON)
- Surface a clear "session expired — reload to sign in" state (toast or banner with a reload action) instead of generic query errors
- Keep it inert on LAN/dev origins where Access is not in the path
- TanStack Query note: mark the condition non-retryable so it fails fast rather than burning retries
Per ADR-009's known negative: once barback.pezza.dev is behind Cloudflare Access, an expired Access session (~monthly at a 30-day session) makes background
fetchcalls to/bar/and/search/receive an HTML login redirect instead of JSON. Without handling, this surfaces as opaque query failures until the user happens to reload.content-typeor a redirect to the Access login on a request that expected JSON)