Skip to content

fix: recover expired sessions instead of failing silently - #94

Merged
thermcampos merged 1 commit into
mainfrom
fix/session-expiry-recovery
Sep 28, 2026
Merged

thermcampos merged 1 commit into
mainfrom
fix/session-expiry-recovery

Conversation

@thermcampos

Copy link
Copy Markdown
Owner

Fixes #93

Summary

  • A tab left open through sleep/browser throttling missed the 25-minute refresh interval, so every /rest/** request failed with auth errors while the private layout kept rendering. The client now revalidates the session on visibilitychange/focus/online (throttled to once a minute), so a waking tab re-authenticates immediately.
  • Any 401/403 on an authenticated request now notifies the auth layer, which signs out and redirects to login while preserving REDIRECT_PATH; public and /auth/** calls (e.g. failed logins) are exempt.
  • The refresh endpoint now accepts tokens expired up to 12 hours ago (still bound to the same user and invalidated by password changes), so sleep/wake no longer forces a full re-login.

Verification

  • Frontend gate green: lint, build, 169 tests (7 new: wake refresh, 401 sign-out/redirect, API handler scoping).
  • Backend gate green: checkstyle, 228 unit + 22 integration tests (10 new: grace-window validation and filter fallback paths).

💘 Generated with Crush

Tabs left open through sleep or browser throttling missed the refresh
interval, so every request failed with auth errors while the private
layout kept rendering. Now the client revalidates the session on
visibilitychange/focus/online, any 401/403 on an authenticated request
signs out and redirects to login preserving the intended path, and the
server lets the refresh endpoint exchange tokens expired up to 12 hours
ago so waking tabs resume without a forced re-login.

Fixes #93

💘 Generated with Crush

Assisted-by: Crush:kimi-k3
@thermcampos
thermcampos merged commit 97c26a4 into main Sep 28, 2026
2 checks passed
@thermcampos
thermcampos deleted the fix/session-expiry-recovery branch September 28, 2026 17:57
@thermcampos thermcampos self-assigned this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Long-open tab: expired session fails requests silently instead of redirecting to login

1 participant