Skip to content

feat(auth): implement admin session timeout and tab presence management - #831

Merged
aXenDeveloper merged 2 commits into
feat(passkeys)--Add-passkeys-support-and-related-UI-componentsfrom
feat(auth)--implement-admin-session-timeout-and-tab-presence-management
Sep 29, 2026
Merged

aXenDeveloper merged 2 commits into
feat(passkeys)--Add-passkeys-support-and-related-UI-componentsfrom
feat(auth)--implement-admin-session-timeout-and-tab-presence-management

Conversation

@aXenDeveloper

Copy link
Copy Markdown
Owner

Improving Documentation

Description

What?

Why?

@github-actions github-actions Bot added the 💡 Feature A new feature label Sep 29, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c051a05fd7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +49 to +50
}): boolean =>
expiresAt.getTime() - now < idleTimeoutMs - ADMIN_SESSION_EXTEND_INTERVAL_MS;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep sub-minute idle timeouts renewable

When an installation configures adminCookieExpires to 60 seconds or less, the right-hand side becomes zero or negative, so this predicate cannot become true while the session is still active. Consequently, even continuous AdminCP requests never call extendSession, and the administrator is forcibly signed out at the original expiry. Either validate a minimum timeout above the extension interval or derive an extension threshold that remains reachable for shorter configured timeouts.

Useful? React with 👍 / 👎.

Comment on lines +31 to +34
return {
available: true,
heartbeat: localStorage.getItem(ADMIN_TAB_HEARTBEAT_KEY),
};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Align tab presence with domain-scoped admin cookies

For installations using authorization.cookieDomain to share authentication across subdomains, the admin cookie and database session are shared, but this heartbeat is stored in origin-scoped localStorage (and the fallback BroadcastChannel is origin-scoped as well). Opening the AdminCP on a second configured subdomain therefore sees no heartbeat, concludes that every tab was closed, and deletes the session even while an AdminCP tab is active on the first subdomain. The presence mechanism needs a scope compatible with domain cookies, or it must avoid treating an absent heartbeat as abandonment in that configuration.

Useful? React with 👍 / 👎.

@aXenDeveloper
aXenDeveloper added this pull request to stack #832 September 29, 2026 12:02

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e504850b91

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


const leaveAbandonedSession = React.useEffectEvent(async () => {
if (leavingRef.current) return;
leavingRef.current = true;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Retry the abandoned-session sign-out after failure

When the abandonment check runs during a transient network or server failure, signOut returns { ok: false } but leavingRef remains permanently set and the presence effect neither retries nor starts a heartbeat. The session can therefore continue being extended by subsequent AdminCP requests; moreover, once it eventually expires, leaveExpiredSession also returns early because it shares this ref, so the router is never invalidated to leave the stale AdminCP screen. Reset the guard or schedule another attempt when sign-out fails.

Useful? React with 👍 / 👎.

@aXenDeveloper
aXenDeveloper merged commit f4d14b0 into canary Sep 29, 2026
5 checks passed
@aXenDeveloper
aXenDeveloper deleted the feat(auth)--implement-admin-session-timeout-and-tab-presence-management branch September 29, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

💡 Feature A new feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant