Repository navigation
The guest prompt's yes said nothing, and no kept the guest session (GRYT-1225) - #587
Merged
Merged
Conversation
…RYT-1225) Yes now shows what the server did, from identityClaim on server:joined, and only for the join right after the click. chat:merge_user rewrites the sender and reactions on messages the client holds, in the channel and an open thread. No drops this device's session for that server and rejoins as the account. The guest's keys and visit history stay on the device, and the guest stays as it was on the server. Ask me later is unchanged. A join bumps tokenRevision now, as a refresh does. Hooks reading the access token from useServerState kept the guest's old one after either answer. After a merge, the membership_required that token got back wiped the new session. A second tab that gets token:revoked with identity_merged drops its refresh token too and rejoins. That token names a membership that's gone. Co-Authored-By: Claude Opus 5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GRYT-1225. This needs Gryt-chat/server#193 merged and released first, and that one is review-required. Against a server without it, yes still says nothing and a merge can't happen.
Nothing here touches
src/packages/common/src/auth/.Yes
After yes, the client now says what the server did, going by
identityClaimonserver:joined:carriedmergedno_prior_membershipfailedOnly the join within 20 seconds of the click gets one, since every later join reports the stored yes again. A server without the field gets no toast.
chat:merge_userrewrites the sender and reactions on messages the client holds, in the channel, the message cache and an open thread. Somebody who reacted as both the guest and the account counts once.No
No now drops this device's session for that server and rejoins, so from then on it's the account there. The guest's keys and visit history stay on the device, since "I've used this server before" needs them later. On the server, the guest stays as it was. If the account isn't allowed in, the usual refusal shows, and with the server change the socket stops being the guest too.
Ask me later is unchanged: nothing is stored, nothing reconnects, and it asks again next launch.
Two bugs found while checking it
useServerStatememoized the access token ontokenRevision, and onlytoken:refreshedbumped it. After either answer, the reports list, admin actions, the sidebar editor and report user kept sending the guest's old token. After a merge that token belongs to nobody. Themembership_requiredit got back wiped the session the join had just stored, and the confirmation never showed. A join bumpstokenRevisionnow too.token:revokedwithidentity_merged. Its usual retry reads the refresh token from storage. When the other tab's change to storage hadn't reached it yet, that sent the guest's revoked token, gotrefresh_token_invalidand gave up. Foridentity_mergedit now drops the refresh token first and rejoins.scripts/check-identity-claim.mjs(yarn test:identity-claim, added to CI) checks the toasts, the 20 second window andmergeSender.Checked
I drove this branch in headless Chromium against a throwaway server running the server branch. I read the DOM, the socket frames and the server's database. A real Keycloak sign-in needs credentials I can't type, so I faked the account. These were local, uncommitted changes, and they're reverted:
getValidIdentityToken,useAccountanduseUserIdanswered for a fake account when localStorage had agryt_fake_accountkey.GRYT_TRUSTED_CERT_ISSUERS.65 checks passed across yes with a merge, yes with a move, ask me later, no, no when refused, a second tab, nothing to move, and a failed merge. The toasts above were read off the page. After either answer, every token the client sent belonged to the account. Taking out the
tokenRevisionbump brought back "You are no longer a member of this server" and areports:listwith the guest's token. Taking out thechat:merge_userhandler left the phone showing the guest's name on the moved message.After no, a relaunch restored the account's session, and nothing asked again.
yarn lint,yarn build, everytest:*step inci.ymlandyarn tsc -p e2epass.yarn e2epassed 14 of 14 againstghcr.io/gryt-chat/server:latest. Against the server branch 13 passed, and the phone settings test skipped because it needs a server of its own.🤖 Generated with Claude Code