Repository navigation
AuthKit v0.138.0
AuthKit v0.138.0
MINOR (#395):
- Fixes the v0.137.0 refresh-cookie regression: a browser still holding the pre-0.137
authkit_rt; Path={api}/tokencookie sent twoauthkit_rtcookies and every refresh failed with 400 (signed out on each load, never self-healing). A cookie registry (authhttp/cookies.go) now lists every refresh and OIDC state cookie variant AuthKit has issued. Setting or rotating the cookie expires the historical variants the browser sends; sign-out expires all of them. The refresh reader prefers the current cookie, reads a lone pre-0.137 cookie until 2026-12-31 and migrates it, and still refuses same-path duplicates.TestCookieRegistryfails any future cookie change that does not go through the registry. Seedocs/security/cookies.md. @openrails/auth-uiowns the client session lifecycle:useAuth()(loading|restoring|signed_in|signed_out, user kept across same-user rotation, authenticated fetch, sign-out);AuthProvider onUserChangefires only when the user changes; a non-secret localStorage session hint (user id, username, expiry) renders the signed-in shell on reload and syncs tabs (sessionHint: falsedisables); requests made while restoring wait for the session (client.ready());client.onContactProofRequiredplus<ContactProofDialog />/<VerifyContactForm />handle403 verification_required/contact_unprovenand retry the refused request once. The refresh token stays in its HttpOnly cookie.AuthSession's loading state may carryhint.