mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
fix(auth): re-issue session cookie on each request (sliding expiry)
The codeman_session cookie was only set on the Basic Auth path with a fixed lifetime from login and never refreshed, while the server-side session store slides its TTL (refreshOnGet). So the browser cookie expired mid-use, the next request arrived cookie-less and fell through to Basic Auth, popping the native username/password dialog — perceived as a random logout while actively working. Re-issue the cookie on every authenticated (valid-cookie) request so the browser lifetime tracks the server-side sliding TTL. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
1fa88cd187
commit
a842f2db4d
@@ -0,0 +1,13 @@
|
||||
---
|
||||
"aicodeman": patch
|
||||
---
|
||||
|
||||
fix(auth): slide the session cookie so active users aren't logged out
|
||||
|
||||
Re-issue the `codeman_session` cookie on every authenticated request so the
|
||||
browser cookie lifetime tracks the server-side sliding TTL (the session store
|
||||
already uses `refreshOnGet`). Previously the cookie was only set on the Basic
|
||||
Auth path with a fixed 24h lifetime from login, so the browser dropped it
|
||||
mid-use; the next request arrived cookie-less, fell through to Basic Auth and
|
||||
popped the native username/password dialog — perceived as a random logout while
|
||||
actively working.
|
||||
@@ -151,6 +151,19 @@ export function registerAuthMiddleware(app: FastifyInstance, https: boolean): Au
|
||||
// Use get() instead of has() so refreshOnGet extends the TTL on active sessions
|
||||
const sessionToken = req.cookies[AUTH_COOKIE_NAME];
|
||||
if (sessionToken && authSessions.get(sessionToken) !== undefined) {
|
||||
// Sliding cookie: re-issue on every authenticated request so the browser
|
||||
// cookie lifetime tracks the server-side sliding TTL (refreshOnGet above).
|
||||
// Without this the cookie has a fixed lifetime from login; the browser
|
||||
// drops it mid-use, the next request arrives cookie-less and falls through
|
||||
// to Basic Auth — popping the native username/password dialog, which reads
|
||||
// as a random logout while actively working.
|
||||
reply.setCookie(AUTH_COOKIE_NAME, sessionToken, {
|
||||
httpOnly: true,
|
||||
secure: https,
|
||||
sameSite: 'lax',
|
||||
maxAge: AUTH_SESSION_TTL_MS / 1000, // seconds
|
||||
path: '/',
|
||||
});
|
||||
done();
|
||||
return;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user