Skip to content

AuthKit v0.138.0

Choose a tag to compare

@PaulFidika PaulFidika released this 24 Sep 21:07
· 118 commits to master since this release
8ce88dc

AuthKit v0.138.0
MINOR (#395):

  • Fixes the v0.137.0 refresh-cookie regression: a browser still holding the pre-0.137 authkit_rt; Path={api}/token cookie sent two authkit_rt cookies and every refresh failed with 400 (signed out on each load, never self-healing). A cookie registry (authhttp/cookies.go) now lists every refresh and OIDC state cookie variant AuthKit has issued. Setting or rotating the cookie expires the historical variants the browser sends; sign-out expires all of them. The refresh reader prefers the current cookie, reads a lone pre-0.137 cookie until 2026-12-31 and migrates it, and still refuses same-path duplicates. TestCookieRegistry fails any future cookie change that does not go through the registry. See docs/security/cookies.md.
  • @openrails/auth-ui owns the client session lifecycle: useAuth() (loading | restoring | signed_in | signed_out, user kept across same-user rotation, authenticated fetch, sign-out); AuthProvider onUserChange fires only when the user changes; a non-secret localStorage session hint (user id, username, expiry) renders the signed-in shell on reload and syncs tabs (sessionHint: false disables); requests made while restoring wait for the session (client.ready()); client.onContactProofRequired plus <ContactProofDialog /> / <VerifyContactForm /> handle 403 verification_required / contact_unproven and retry the refused request once. The refresh token stays in its HttpOnly cookie.
  • AuthSession's loading state may carry hint.