Commit 75bd574
committed
fix(cloud): a sign-in replaces the whole session — it no longer keeps the last one's refresh token
From review on #95. storeSession wrote the access token, and the refresh token only if the
sign-in brought one. With none, the previous session's stayed in SecretStorage — and it is
what the new session's first renewal was then made with. The generation counter does not
help: by then the stale token IS the current session's, as far as this window can tell.
Reproduced on the reviewed code, both ways it can go:
- the old token is refused: the refresh is sent with it, its 401 ends the session — the
access token minted by the sign-in is deleted and the "session expired" card shown to
someone who signed in hours ago. This is the reviewer's case.
- the old token is still good: the server renews the PREVIOUS account, and the editor ends
up holding that account's access token under the new account's name and plan. Requests
then run, and bill, as someone else. The review did not mention this one; it is worse.
So a sign-in now settles the refresh token either way — stored, or forgotten when there is
none. And it settles it FIRST, before the access token. The same bad pairing was reachable
without an absent token at all: with the access token written first, a sign-in cut short
before its second write (the editor closing, a keychain that locks) left the new access token
over the old refresh token. Written the other way round, what a cut-short sign-in leaves is
the old access token over the new refresh token, which the next renewal resolves to the
account the user was signing in to.
How reachable: today's backend sends a refresh token on both callback forms, so this needs a
callback that arrives without one — the legacy `?token=` form accepts that. Latent, then, but
the client documents the refresh token as optional and already had a test for a sign-in
without one.
Three cases in sessionExpiredHost.test.js (57 -> 60), run against the real functions. With
the delete removed, exactly those three fail; with the old write order, exactly the ordering
case. tsc --checkJs reports no new undefined names.1 parent 76445f5 commit 75bd574
2 files changed
Lines changed: 58 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3193 | 3193 | | |
3194 | 3194 | | |
3195 | 3195 | | |
3196 | | - | |
| 3196 | + | |
| 3197 | + | |
| 3198 | + | |
| 3199 | + | |
| 3200 | + | |
| 3201 | + | |
| 3202 | + | |
| 3203 | + | |
| 3204 | + | |
| 3205 | + | |
| 3206 | + | |
| 3207 | + | |
3197 | 3208 | | |
3198 | 3209 | | |
3199 | 3210 | | |
3200 | 3211 | | |
3201 | | - | |
3202 | 3212 | | |
| 3213 | + | |
| 3214 | + | |
3203 | 3215 | | |
3204 | 3216 | | |
3205 | 3217 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
561 | 561 | | |
562 | 562 | | |
563 | 563 | | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
564 | 608 | | |
565 | 609 | | |
566 | 610 | | |
| |||
0 commit comments