fix: sessions that end when you end them (#112) #138
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!138
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/sessions"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
PR 1 of the #137 stack. Closes #112.
Four commits:
sidclaim. The auth interceptor refuses the token once the chain has no live record, through a new nil-toleratedConfig.LookupChainseam. Revoking a session now ends that device's access on its next request, not at token expiry.Session.current(proto, additive) marks the chain the request rode.ListSessionsskips chains already past the 90-day idle window: they can never exchange again, so listing them as signed-in devices was a lie. This is where the phantom session pile-up came from.Verified against the live deploy:
sidpresent in the minted token,current: trueon the calling chain, and a still-unexpired access token gets 401 on the very next request after its chain is revoked.make check, the hermetic integration suite, and the Android unit tests all pass.🤖 Generated with Claude Code
Test report
Coverage: 28.2%
Updated by the check workflow · commit
892c7b55bcAndroid test report
Coverage: 2.4% of lines
Updated by the android workflow · commit
892c7b55bc