Conversation
Add WebP-aware image loading, activity-aware expiry warnings, transactional session-state consumption, and accurate bundle-boundary documentation. Closes CodeGirlsInc#1313 Closes CodeGirlsInc#1314 Closes CodeGirlsInc#1315 Closes CodeGirlsInc#1316
|
@Muhammadjazuli is attempting to deploy a commit to the Mftee's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@Muhammadjazuli Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Both CodeGirlsInc#1415 (already merged) and this PR independently rewrote api-client.ts and auth-session.ts with different, incompatible session-refresh designs. Synthesized rather than picked a side: - Kept this PR's authGeneration/AbortController invalidation mechanism (invalidateRefresh/RefreshInvalidatedError) since this PR's own auth-session.ts (storeSession) depends on it, non-conflicting call sites confirm the sync clearSession() -> SessionStateResult contract (e.g. settings/security/page.tsx checks .ok synchronously, would not type-check against CodeGirlsInc#1415's Promise<boolean>), and the resume-aware redirectToLogin (appends ?resume= from a pending session-state group) is real, tested functionality from this PR's own scope. - Kept CodeGirlsInc#1415's refresh-token ROTATION handling (persisting the server's rotated refresh_token) and its RefreshError(status, definitive)/ isDefinitiveRefreshError distinction + cross-tab refresh adoption, since dropping either would regress against CodeGirlsInc#1398's already-merged reuse-detection/family-revocation, and SessionRefreshClient.tsx (already merged, not touched by this PR) imports isDefinitiveRefreshError directly. - clearSession is now synchronous (SessionStateResult, matching this PR's real non-conflicting call sites) but still fires the backend logout call fire-and-forget so CodeGirlsInc#1415's server-side revocation still happens. - Removed a dead cookie-clearing line (document.cookie = 'token=...') present in both sides' versions of this logic — nothing in the codebase ever sets a cookie named 'token'; the real session cookies are named via ACCESS_COOKIE_NAME/REFRESH_COOKIE_NAME in auth-cookie.ts. - Rewrote test-utils/api-client.test.ts and LoginForm.test.tsx assertions that depended on the losing side's implementation details (async boolean clearSession, /dashboard redirect, relative request URLs). Could not run tsc or jest locally to verify this (no node_modules on this machine) — CI is the real check for this commit.
mftee
left a comment
There was a problem hiding this comment.
Reviewed the auth/session hardening changes: transactional session-state preservation across redirects (bound to JWT subject + token fingerprint, with rollback on partial storage failures), request generation counters to stop stale refresh responses from racing a fresh login/logout, and the custom Next image loader correctly passing through signed URLs and rejecting protocol-relative ones. Test coverage is thorough. Looks good to merge.
Summary
Issues
Validation
Closes #1313
Closes #1314
Closes #1315
Closes #1316