Skip to content

fix(web): make login take the cross-tab cookie lock so a racing refresh cannot restore the wrong session - #648

Merged
mforce merged 4 commits into
mainfrom
fix/438-cross-tab-login-cookie-lock
Sep 2, 2026
Merged

mforce merged 4 commits into
mainfrom
fix/438-cross-tab-login-cookie-lock

fix(web): let an abandoned login give its session generation back

913dbd6
Select commit
Loading
Failed to load commit list.
GitGuardian / GitGuardian Security Checks completed Sep 2, 2026 in 2s

3 secrets uncovered!

3 secrets were uncovered from the scan of 4 commits in your pull request. ❌

Please have a look to GitGuardian findings and remediate in order to secure your code.

Details

🔎 Detected hardcoded secrets in your pull request

  • Pull request #648: fix/438-cross-tab-login-cookie-lock 👉 main
GitGuardian id GitGuardian status Secret Commit Filename
35010655 Triggered Generic Password 38e4b32 web/src/api/client.test.ts View secret
35010655 Triggered Generic Password 38e4b32 web/src/api/client.test.ts View secret
35010655 Triggered Generic Password 38e4b32 web/src/api/client.test.ts View secret

🛠 Guidelines to remediate hardcoded secrets

  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.