redirect to auth callback if session / realm aren't found in memory #3
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Problem
If the server restarts after a user authenticates, when they revisit a protected page they'll be greeted with an unfriendly 401 unless their cookie has already expired. The workaround for this is to have a user clear their cookies, but this is less than ideal.
Solution
When a user provides a token with an invalid session or realm, redirect them to the Discord authentication page instead of completely blocking them out.
Additional changes
While I was poking around, I figured I'd add configuration for the name of the cookie that gets set in the browser by this plugin as allowing only the default exposes an implementation detail, which is better avoided where possible.
EDIT: Still not working as intended, following up with maintainer