fix: never resurrect auth.json after sign-out (refresh race) - #285
Merged
Conversation
Contributor
|
🎉 PR Validation ✅ PASSED Commit: Checks:
Ready to merge! ✨ 🔗 View workflow run |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A token refresh whose
mutateAuthre-read came back null was folding the in-memoryauthback onto disk (current ?? auth), so a sign-out that landed while the refresh was on the wire got itsauth.jsonwritten straight back - the session the user just ended came back alive, violatingmutateAuth's own documented contract ("leave a null re-read null"). The refresh mutator now returns null on a null re-read (the in-flight request still retries with the fresh tokens in memory; nothing is persisted), anddeleteAuthtakes the samewithFileLockthe mutate path uses so sign-out can no longer interleave with someone else's read-modify-write. Its single caller (setup.ts disconnect) already ran in an async context. Regression cover: a deterministic sign-out-during-refresh case plus a 50-iteration race loop (both fail on the old code), and a lock-contention test fordeleteAuth.Closes #236