From 6f4b2b8a17fd285fc4558e4a647f85f8669ae6a6 Mon Sep 17 00:00:00 2001 From: Codeman maintainer Date: Fri, 17 Jul 2026 00:15:29 +0200 Subject: [PATCH] chore: version packages Release 1.3.5. Consumes the changeset from PR #155: re-issue the codeman_session cookie on every authenticated request so the browser cookie lifetime tracks the server-side sliding TTL, fixing the recurring native Basic Auth dialog during active use. Co-Authored-By: Claude Opus 4.8 (1M context) --- .changeset/sliding-auth-cookie.md | 13 ------------- CHANGELOG.md | 14 ++++++++++++++ CLAUDE.md | 2 +- package-lock.json | 4 ++-- package.json | 2 +- 5 files changed, 18 insertions(+), 17 deletions(-) delete mode 100644 .changeset/sliding-auth-cookie.md diff --git a/.changeset/sliding-auth-cookie.md b/.changeset/sliding-auth-cookie.md deleted file mode 100644 index 205fe62e..00000000 --- a/.changeset/sliding-auth-cookie.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -"aicodeman": patch ---- - -fix(auth): slide the session cookie so active users aren't logged out - -Re-issue the `codeman_session` cookie on every authenticated request so the -browser cookie lifetime tracks the server-side sliding TTL (the session store -already uses `refreshOnGet`). Previously the cookie was only set on the Basic -Auth path with a fixed 24h lifetime from login, so the browser dropped it -mid-use; the next request arrived cookie-less, fell through to Basic Auth and -popped the native username/password dialog — perceived as a random logout while -actively working. diff --git a/CHANGELOG.md b/CHANGELOG.md index dda95fc9..e90c26c6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,19 @@ # aicodeman +## 1.3.5 + +### Patch Changes + +- a842f2d: fix(auth): slide the session cookie so active users aren't logged out + + Re-issue the `codeman_session` cookie on every authenticated request so the + browser cookie lifetime tracks the server-side sliding TTL (the session store + already uses `refreshOnGet`). Previously the cookie was only set on the Basic + Auth path with a fixed 24h lifetime from login, so the browser dropped it + mid-use; the next request arrived cookie-less, fell through to Basic Auth and + popped the native username/password dialog, perceived as a random logout while + actively working. + ## 1.3.4 ### Patch Changes diff --git a/CLAUDE.md b/CLAUDE.md index 92ebd9ce..e39051e5 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -56,7 +56,7 @@ When user says "COM": CI runs `npm run check:lockfile` on every push/PR, so lockfile drift fails the build even if the `version-packages` script is bypassed. -**Version**: 1.3.4 (must match `package.json`) +**Version**: 1.3.5 (must match `package.json`) ## Project Overview diff --git a/package-lock.json b/package-lock.json index 121d0baa..b0753b94 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "aicodeman", - "version": "1.3.4", + "version": "1.3.5", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "aicodeman", - "version": "1.3.4", + "version": "1.3.5", "hasInstallScript": true, "license": "MIT", "workspaces": [ diff --git a/package.json b/package.json index 022344ce..17d61aa5 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "aicodeman", - "version": "1.3.4", + "version": "1.3.5", "description": "Mission control for AI coding agents - run 20 autonomous agents with real-time monitoring and session persistence", "type": "module", "main": "dist/index.js",