fix(auth): preserve password replacement across concurrent 401s - #9607
Open
wunianze666-netizen wants to merge 3 commits into
Open
wunianze666-netizen wants to merge 3 commits into
wunianze666-netizen wants to merge 3 commits into
Conversation
wunianze666-netizen
requested review from
JPPhoto,
Pfannkuchensack,
blessedcoolant,
dunkeroni and
lstein
as code owners
September 28, 2026 17:28
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User impact and scope
Password changes advance the backend token epoch and return a replacement in
X-Refreshed-Token. A concurrent request made with the old token can receive 401 before the password response arrives. Logging out immediately destroys the session before the replacement can be committed. On current main, this affects both the legacywebv1client and the defaultwebv2client. This is distinct from the routine-refresh-first race addressed by #9599.Root cause and fix
PATCH /auth/meor an admin self-reset; when an old-token 401 arrives first, defer expiry and recheck the live credential after the operation completes.The bounded wait can delay a genuine 401 when the password-changing tab disappears, but cannot suppress it indefinitely. The implementation keeps token policy in Identity and passes only a narrow callback through Platform HTTP.
Red/green evidence
Before the fix, a controlled old-token-401-first request signed the user out and prevented the password response from installing its replacement. The new webv2 regression also failed because the success header was ignored. After the fix:
webv1: seven auth/API test files, 61 tests passed; targeted ESLint and Prettier passed. Full webv1tsc --noEmitcurrently reports unrelated model-type fixture errors on the updated main, with no diagnostics in the five changed webv1 files.webv2: identity plus HTTP transport tests, seven files / 61 tests passed, including 401-first, same-epoch-refresh-before-replacement, failed change, and admin self-reset cases.tsc --noEmit, targeted oxfmt/oxlint, secure-context and dependency architecture checks,git diff --check, and a production Vite build passed. The build reports existing chunk-size/dynamic-import warnings.The branch is updated through commits
e724d69ee(carry the webv1 change across the frontend move) anddc6aa7176(default webv2 fix). Full browser/release checks were not run locally; CI results should be considered separately.Developed with Codex AI assistance. The checks above were run locally; no claim of upstream adoption is made until maintainer review and merge.