mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 08:29:42 +02:00
The codeman_session cookie was only set on the Basic Auth path with a fixed lifetime from login and never refreshed, while the server-side session store slides its TTL (refreshOnGet). So the browser cookie expired mid-use, the next request arrived cookie-less and fell through to Basic Auth, popping the native username/password dialog — perceived as a random logout while actively working. Re-issue the cookie on every authenticated (valid-cookie) request so the browser lifetime tracks the server-side sliding TTL. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
14 lines
583 B
Markdown
14 lines
583 B
Markdown
---
|
|
"aicodeman": patch
|
|
---
|
|
|
|
fix(auth): slide the session cookie so active users aren't logged out
|
|
|
|
Re-issue the `codeman_session` cookie on every authenticated request so the
|
|
browser cookie lifetime tracks the server-side sliding TTL (the session store
|
|
already uses `refreshOnGet`). Previously the cookie was only set on the Basic
|
|
Auth path with a fixed 24h lifetime from login, so the browser dropped it
|
|
mid-use; the next request arrived cookie-less, fell through to Basic Auth and
|
|
popped the native username/password dialog — perceived as a random logout while
|
|
actively working.
|