Skip to content

fix(auth): harden session and image resilience - #1416

Merged
mftee merged 2 commits into
CodeGirlsInc:mainfrom
Muhammadjazuli:feature/session-and-image-resilience
Sep 25, 2026
Merged

mftee merged 2 commits into
CodeGirlsInc:mainfrom
Muhammadjazuli:feature/session-and-image-resilience

Conversation

@Muhammadjazuli

Copy link
Copy Markdown
Contributor

Summary

  • add a Next-compatible image loader with negotiated WebP/AVIF output
  • postpone session-expiry prompts during continuous editing activity
  • consume preserved session state transactionally after successful resume
  • document the actual client-only bundle boundary

Issues

Validation

  • static diff, whitespace, import/export, and secret review completed
  • automated tests, lint/typecheck, builds, dependency installation, and CI were not run per maintainer request

Closes #1313
Closes #1314
Closes #1315
Closes #1316

Add WebP-aware image loading, activity-aware expiry warnings, transactional session-state consumption, and accurate bundle-boundary documentation.

Closes CodeGirlsInc#1313
Closes CodeGirlsInc#1314
Closes CodeGirlsInc#1315
Closes CodeGirlsInc#1316
@vercel

vercel Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

@Muhammadjazuli is attempting to deploy a commit to the Mftee's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 25, 2026

Copy link
Copy Markdown

@Muhammadjazuli Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Both CodeGirlsInc#1415 (already merged) and this PR independently rewrote api-client.ts
and auth-session.ts with different, incompatible session-refresh designs.
Synthesized rather than picked a side:

- Kept this PR's authGeneration/AbortController invalidation mechanism
  (invalidateRefresh/RefreshInvalidatedError) since this PR's own
  auth-session.ts (storeSession) depends on it, non-conflicting call sites
  confirm the sync clearSession() -> SessionStateResult contract (e.g.
  settings/security/page.tsx checks .ok synchronously, would not type-check
  against CodeGirlsInc#1415's Promise<boolean>), and the resume-aware redirectToLogin
  (appends ?resume= from a pending session-state group) is real, tested
  functionality from this PR's own scope.
- Kept CodeGirlsInc#1415's refresh-token ROTATION handling (persisting the server's
  rotated refresh_token) and its RefreshError(status, definitive)/
  isDefinitiveRefreshError distinction + cross-tab refresh adoption, since
  dropping either would regress against CodeGirlsInc#1398's already-merged
  reuse-detection/family-revocation, and SessionRefreshClient.tsx (already
  merged, not touched by this PR) imports isDefinitiveRefreshError directly.
- clearSession is now synchronous (SessionStateResult, matching this PR's
  real non-conflicting call sites) but still fires the backend logout call
  fire-and-forget so CodeGirlsInc#1415's server-side revocation still happens.
- Removed a dead cookie-clearing line (document.cookie = 'token=...') present
  in both sides' versions of this logic — nothing in the codebase ever sets a
  cookie named 'token'; the real session cookies are named via
  ACCESS_COOKIE_NAME/REFRESH_COOKIE_NAME in auth-cookie.ts.
- Rewrote test-utils/api-client.test.ts and LoginForm.test.tsx assertions
  that depended on the losing side's implementation details (async boolean
  clearSession, /dashboard redirect, relative request URLs).

Could not run tsc or jest locally to verify this (no node_modules on this
machine) — CI is the real check for this commit.

@mftee mftee left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the auth/session hardening changes: transactional session-state preservation across redirects (bound to JWT subject + token fingerprint, with rollback on partial storage failures), request generation counters to stop stale refresh responses from racing a fresh login/logout, and the custom Next image loader correctly passing through signed URLs and rejecting protocol-relative ones. Test coverage is thorough. Looks good to merge.

@mftee
mftee merged commit 323ebe5 into CodeGirlsInc:main Sep 25, 2026
0 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants