Skip to content

Prevent late refresh responses from resurrecting or overwriting SPA sessions #310

Description

@mforce

Parent: #244
Epic: #15
Severity: Medium
Execution mode: AFK

What to build

Treat login, bootstrap refresh, explicit refresh, and logout as one browser-session state machine. Today an in-flight refresh can complete after logout and restore authenticated state, or an older bootstrap refresh can overwrite a newer login. Logout also swallows server errors without making the local invalidation ordering explicit.

Use a monotonically increasing session generation and cancellation where possible. A completion may update tokens and user state only if it belongs to the active generation. Local logout must win immediately even when the server revoke call fails; the error can be reported without restoring the session.

Acceptance criteria

  • Starting logout invalidates the current generation before awaiting network I/O and clears in-memory authentication state.
  • A refresh that resolves after logout is discarded and cannot navigate, schedule another refresh, or restore a user.
  • A bootstrap refresh that resolves after a successful explicit login cannot overwrite the newer session.
  • Late failures from obsolete generations do not clear or corrupt a newer session.
  • The server-side logout/revocation request is still attempted and a failure is observable without exposing tokens.
  • Deterministic frontend tests cover each race with deferred promises.
  • SPA UI verification track: Playwright E2E smoke + canary-under-load over the #243 sim fixture #277 gains real-browser coverage for logout during refresh after this fix lands.

Blocked by

None.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:frontendReact/Vite web clientbugSomething isn't workingepic-1.5sliceThin vertical work item

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions