Index: interfejs/change-password.html
===================================================================
--- interfejs/change-password.html	(revision 69f2a41cff81a4c7825abb68eb0f0eff6818e4e5)
+++ interfejs/change-password.html	(revision 4dff800e0e61b01aeb1b15846b32fb42aed69027)
@@ -27,10 +27,8 @@
         <p class="form-subtitle" id="password-message">Please set a new password</p>
 
+        <div id="error-message" class="error-message" style="display: none; color: red; margin-bottom: 1rem; padding: 10px; background-color: #ffeeee; border-radius: 5px;"></div>
+        <div id="success-message" class="success-message" style="display: none; color: green; margin-bottom: 1rem; padding: 10px; background-color: #eeffee; border-radius: 5px;"></div>
+
         <form id="change-password-form" class="form">
-            <div class="form-group">
-                <label for="current-password">Current Password</label>
-                <input type="password" id="current-password" name="current-password" required>
-            </div>
-
             <div class="form-group">
                 <label for="new-password">New Password</label>
@@ -45,5 +43,5 @@
 
             <div class="form-group">
-                <button type="submit" class="btn-primary btn-full">Change Password</button>
+                <button type="submit" class="btn-primary btn-full" id="submit-btn">Change Password</button>
             </div>
         </form>
@@ -75,4 +73,5 @@
         const urlParams = new URLSearchParams(window.location.search);
         const isForced = urlParams.get('forced') === 'true';
+        let userType = 'admin'; // Default
 
         if (isForced) {
@@ -82,17 +81,50 @@
 
         const form = document.getElementById('change-password-form');
+        const submitBtn = document.getElementById('submit-btn');
+        const errorDiv = document.getElementById('error-message');
+        const successDiv = document.getElementById('success-message');
+
+        // Check if user is authenticated for password change and get user type
+        checkAuthStatus();
+
         form.addEventListener('submit', async (e) => {
             e.preventDefault();
 
+            // Clear previous messages
+            errorDiv.style.display = 'none';
+            successDiv.style.display = 'none';
+
+            // Disable submit button to prevent double submission
+            submitBtn.disabled = true;
+            submitBtn.textContent = 'Changing Password...';
+
             const newPassword = document.getElementById('new-password').value;
             const confirmPassword = document.getElementById('confirm-password').value;
 
+            // Client-side validation
+            if (!newPassword || !confirmPassword) {
+                showError('All fields are required');
+                submitBtn.disabled = false;
+                submitBtn.textContent = 'Change Password';
+                return;
+            }
+
             if (newPassword !== confirmPassword) {
-                alert('New passwords do not match');
+                showError('New passwords do not match');
+                submitBtn.disabled = false;
+                submitBtn.textContent = 'Change Password';
                 return;
             }
 
+            // Validate password strength
+            const passwordRegex = /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[@$!%*?&])[A-Za-z\d@$!%*?&]{8,}$/;
+            if (!passwordRegex.test(newPassword)) {
+                showError('Password must have at least 8 characters, including uppercase, lowercase, number and special character');
+                submitBtn.disabled = false;
+                submitBtn.textContent = 'Change Password';
+                return;
+            }
+
             const formData = {
-                currentPassword: document.getElementById('current-password').value,
                 newPassword: newPassword,
                 confirmPassword: confirmPassword
@@ -100,23 +132,93 @@
 
             try {
+                console.log('Sending password change request...');
                 const response = await fetch('/api/force-change-password', {
                     method: 'POST',
-                    headers: { 'Content-Type': 'application/json' },
-                    body: JSON.stringify(formData)
+                    headers: {
+                        'Content-Type': 'application/json'
+                    },
+                    body: JSON.stringify(formData),
+                    credentials: 'include' // Important: include cookies
                 });
 
                 const data = await response.json();
+                console.log('Response:', data);
 
                 if (data.success) {
-                    alert('Password changed successfully!');
-                    window.location.href = data.redirectTo || 'dashboard.html';
+                    showSuccess('Password changed successfully! Redirecting...');
+
+                    // Clear form
+                    form.reset();
+
+                    // Redirect after short delay
+                    setTimeout(() => {
+                        window.location.href = data.redirectTo || 'dashboard.html';
+                    }, 1500);
                 } else {
-                    alert(data.message || 'Failed to change password');
+                    showError(data.message || 'Failed to change password');
+                    submitBtn.disabled = false;
+                    submitBtn.textContent = 'Change Password';
                 }
             } catch (error) {
                 console.error('Password change error:', error);
-                alert('An error occurred');
+                showError('Network error: ' + error.message);
+                submitBtn.disabled = false;
+                submitBtn.textContent = 'Change Password';
             }
         });
+
+        async function checkAuthStatus() {
+            try {
+                const response = await fetch('/api/user', {
+                    credentials: 'include'
+                });
+                const data = await response.json();
+
+                if (!data.success) {
+                    // Not authenticated, redirect to login
+                    window.location.href = 'login.html';
+                } else if (data.isTempSession) {
+                    console.log('Valid temporary session for password change');
+                    if (data.user && data.user.userType) {
+                        userType = data.user.userType;
+                    }
+                } else {
+                    // Already have full session, redirect to appropriate dashboard
+                    if (data.user && data.user.userType) {
+                        switch(data.user.userType) {
+                            case 'admin':
+                                window.location.href = 'admin.html';
+                                break;
+                            case 'store_owner':
+                                window.location.href = 'store-owner.html';
+                                break;
+                            case 'store_employee':
+                                window.location.href = 'store-employee.html';
+                                break;
+                            case 'client':
+                                window.location.href = 'client-dashboard.html';
+                                break;
+                            default:
+                                window.location.href = 'dashboard.html';
+                        }
+                    }
+                }
+            } catch (error) {
+                console.error('Auth check error:', error);
+            }
+        }
+
+        function showError(message) {
+            errorDiv.textContent = message;
+            errorDiv.style.display = 'block';
+            setTimeout(() => {
+                errorDiv.style.display = 'none';
+            }, 5000);
+        }
+
+        function showSuccess(message) {
+            successDiv.textContent = message;
+            successDiv.style.display = 'block';
+        }
     });
 </script>
