fix(auth): prefer current session cookies#1079
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughChangesSupabase authentication cookie resolution
DOM test teardown stabilization
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant Request
participant resolveOptionalAuthentication
participant SupabaseAuth
participant SSRServerClient
Request->>resolveOptionalAuthentication: provide request cookies
resolveOptionalAuthentication->>SupabaseAuth: validate current or legacy access token
resolveOptionalAuthentication->>SSRServerClient: decode current SSR session when needed
SSRServerClient-->>resolveOptionalAuthentication: return session or failure
resolveOptionalAuthentication-->>Request: return authenticated, invalid, or absent
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
This pull request has been ignored for the connected project Preview Branches by Supabase. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 068941dd41
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex resolve actionable Codex review findings for this pull request and current head using the repository instructions. This is the pull request's single automatic repair pass: do not perform a fresh review, create new standalone findings, or request another review. Work only the existing unresolved Codex threads on the current head. Always fix P0 and P1 findings. For P2 and lower findings, fix only clear, scoped, low-risk issues; otherwise disposition them with a concise reason. After fixing or dispositioning a thread, reply in that thread with as the first line, followed by a concise summary; that marker authorizes the workflow to close that exact thread. If human input or new authorization is required, do not use the marker and leave the thread open with the blocker. Finish only after every actionable thread is fixed or dispositioned and closed, or explicitly left open for a human decision. Do not update the branch from main, address unrelated reviews, broaden scope, or create more than one scoped fix commit. Do not use external APIs, paid services, credentials, dependency changes, or broad refactors unless explicitly authorized. Add targeted tests where behavior changes and run the narrowest relevant validation. |
CI triageCI failed on this PR. Automated classification of the 2 failed job(s):
Compared with main CI run #4479 (failure). Classification is evidence routing, not permission to ignore a failure. Exact quarantined Playwright identities remain governed by the flake ledger. |
Summary
sb-<ref>-auth-tokensession over a stale legacysb-access-tokencookie, while ignoring cookies from the retired project.Verification
npm run verify:pr-local— not repeated: two attempts were blocked by other Database worktrees holding the shared heavyweight lock; focused auth coverage passed and hosted full gates are required before mergenpm exec vitest run tests/auth-tri-state.test.ts tests/account-access-model.test.ts tests/private-access-routes.test.ts— 4 files, 148 tests passednpm run check:production-readiness— not repeated: fix(auth): reject invalid optional credentials #1078 code guards passed, while this clean worktree lacks provider environment variables; this follow-up changes only cookie precedenceRed proof: on merged #1078, the new mixed-cookie test returned
{ status: "invalid" }because the stale legacy cookie was validated first.Risk and rollout
Clinical Governance Preflight
Clinical KB Database(sjrfecxgysukkwxsowpy)Notes
Summary by CodeRabbit
sb-access-tokenvalues.