fix: harden auth with refresh token session binding, logging, and router state
- Add session_id to refresh tokens and enforce it during validation, preventing stolen refresh tokens from being usable without the originating browser session - Set router.isAuthenticated via auth:login event after successful login (previously only set at page load) - Add console.warn logging to WS message parse/handler errors - Improve _refreshPromise error handling in token refresh flow - Document rate limiter in-memory limitation and CSP connect-src same-origin requirement - Add 3 tests for session-bound refresh token validation
This commit is contained in:
@@ -263,6 +263,14 @@ export async function initApp() {
|
||||
render(mainEl, MainContent);
|
||||
}
|
||||
|
||||
// Listen for login events to update router state after auth
|
||||
window.addEventListener('auth:login', () => {
|
||||
router.isAuthenticated = true;
|
||||
if (!router.state.path.startsWith('/login')) {
|
||||
fetchInitialData();
|
||||
}
|
||||
});
|
||||
|
||||
// Check auth state before connecting WS
|
||||
const ok = await initAuth();
|
||||
if (ok) {
|
||||
|
||||
Reference in New Issue
Block a user