Skip to content

fix(auth): retain session across pre-refresh discovery outages - #194

Merged
adrianwebb merged 1 commit into
stagingfrom
codex/preserve-session-before-refresh
Sep 11, 2026
Merged

fix(auth): retain session across pre-refresh discovery outages#194
adrianwebb merged 1 commit into
stagingfrom
codex/preserve-session-before-refresh

Conversation

@adrianwebb

Copy link
Copy Markdown
Contributor

Outcome

Do not erase a valid encrypted session when API/issuer discovery fails before renewal submits a refresh token.

Work authority

Plan

Keep discovery and renewal within the serialized session transaction. Begin failure invalidation only immediately before refresh invocation.

Changes and commits

251a50e introduces a transaction invalidation predicate. Unavailable discovery preserves the session and team. Ambiguous refresh continues to clear the selected session. No alternate credential storage or authentication bypass.

Verification

Three synthetic resource/issuer/refresh outage tests pass; all four existing custody tests passed in the preceding focused run. Strict TypeScript and file architecture pass. CLI distribution rebuilt without touching unrelated generated docs/schema edits. Actions required on exact head.

Risk and rollback

Session invalidation behavior is deliberately unchanged once refresh begins, including uncertain token rotation. Revert this commit to restore prior behavior. Already-erased credentials are not recovered; browser sign-in remains required.

Completion summary

The identified pre-refresh outage defect is fixed. This does not assert successful live source-enabled agent execution.

Submission checklist

  • The change is bounded to the stated work item and target repository.
  • Exact base and head refs are recorded and the branch is ready for review.
  • Verification and compatibility evidence are recorded above.
  • No plaintext secrets, credentials, machine state, or unrelated residue are included.
  • Plan, status, commits, and completion summary form a complete durable record.
  • Rollback or recovery steps are documented and executable.

@adrianwebb
adrianwebb merged commit badc74f into staging Sep 11, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant