mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 16:09:43 +02:00
Merge PR #155 from dennisentruencer/fix/sliding-auth-cookie: slide the session cookie so active users aren't logged out
Re-issue the codeman_session cookie on every authenticated request so the browser cookie lifetime tracks the server-side sliding TTL (authSessions already used refreshOnGet: true). Fixes the recurring native Basic Auth dialog during active use. Reviewed: no token rotation (same server-generated token re-issued, so no fixation vector), forged cookies are not blessed, logout still emits only the clearing cookie and server-side invalidation holds, cookie attributes identical to the Basic Auth path. Verified against the merge result: tsc --noEmit, lint, format:check, check:frontend-syntax, check:lockfile, and npm run test:ci (3404 passed) all green.
This commit is contained in:
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
"aicodeman": patch
|
||||||
|
---
|
||||||
|
|
||||||
|
fix(auth): slide the session cookie so active users aren't logged out
|
||||||
|
|
||||||
|
Re-issue the `codeman_session` cookie on every authenticated request so the
|
||||||
|
browser cookie lifetime tracks the server-side sliding TTL (the session store
|
||||||
|
already uses `refreshOnGet`). Previously the cookie was only set on the Basic
|
||||||
|
Auth path with a fixed 24h lifetime from login, so the browser dropped it
|
||||||
|
mid-use; the next request arrived cookie-less, fell through to Basic Auth and
|
||||||
|
popped the native username/password dialog — perceived as a random logout while
|
||||||
|
actively working.
|
||||||
@@ -151,6 +151,19 @@ export function registerAuthMiddleware(app: FastifyInstance, https: boolean): Au
|
|||||||
// Use get() instead of has() so refreshOnGet extends the TTL on active sessions
|
// Use get() instead of has() so refreshOnGet extends the TTL on active sessions
|
||||||
const sessionToken = req.cookies[AUTH_COOKIE_NAME];
|
const sessionToken = req.cookies[AUTH_COOKIE_NAME];
|
||||||
if (sessionToken && authSessions.get(sessionToken) !== undefined) {
|
if (sessionToken && authSessions.get(sessionToken) !== undefined) {
|
||||||
|
// Sliding cookie: re-issue on every authenticated request so the browser
|
||||||
|
// cookie lifetime tracks the server-side sliding TTL (refreshOnGet above).
|
||||||
|
// Without this the cookie has a fixed lifetime from login; the browser
|
||||||
|
// drops it mid-use, the next request arrives cookie-less and falls through
|
||||||
|
// to Basic Auth — popping the native username/password dialog, which reads
|
||||||
|
// as a random logout while actively working.
|
||||||
|
reply.setCookie(AUTH_COOKIE_NAME, sessionToken, {
|
||||||
|
httpOnly: true,
|
||||||
|
secure: https,
|
||||||
|
sameSite: 'lax',
|
||||||
|
maxAge: AUTH_SESSION_TTL_MS / 1000, // seconds
|
||||||
|
path: '/',
|
||||||
|
});
|
||||||
done();
|
done();
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user