fix: preserve downstream session cookie precedence - #126
workos-tars-staging[bot] wants to merge 1 commit into
Conversation
|
|
This finding does not apply to the configured storage adapter.
The deletion therefore follows the auto-refresh cookie in the pending queue, as tested. No code change needed; all 71 targeted middleware, storage, and server-function tests passed. |
| // Queue auto-refresh cookies first so downstream session writes take precedence. | ||
| if (refreshedSessionData) { | ||
| const { response: sessionResponse } = await authkit.saveSession(undefined, refreshedSessionData); | ||
| for (const cookie of sessionResponse?.headers.getSetCookie() ?? []) { | ||
| pendingHeaders.append('Set-Cookie', cookie); | ||
| } |
There was a problem hiding this comment.
Sign-out cookie loses precedence
When auto-refresh and signOut() happen on the same request, sign-out puts its session-clear cookie in the redirect response, while this code queues the refreshed session cookie separately. The final merge appends the queued cookie after the redirect headers, so the refreshed session can override the deletion and leave the browser signed in. The new sign-out test writes its deletion cookie through the pending-header path instead, so it does not cover this case.
Knowledge Base Used:
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/server/middleware-body.ts
Line: 18-23
Comment:
**Sign-out cookie loses precedence**
When auto-refresh and `signOut()` happen on the same request, sign-out puts its session-clear cookie in the redirect response, while this code queues the refreshed session cookie separately. The final merge appends the queued cookie *after* the redirect headers, so the refreshed session can override the deletion and leave the browser signed in. The new sign-out test writes its deletion cookie through the pending-header path instead, so it does not cover this case.
**Knowledge Base Used:**
- [Middleware, session, and request context](https://app.greptile.com/workos/-/custom-context/knowledge-base/workos/authkit-tanstack-start/-/docs/middleware-session-context.md)
- [Authentication actions and route bodies](https://app.greptile.com/workos/-/custom-context/knowledge-base/workos/authkit-tanstack-start/-/docs/auth-actions-and-route-bodies.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
Summary
Validation
Closes #125
Requested by garen.torikian@workos.com in GitHub (TARS chain)