Monorepo for Tangled โ€” https://tangled.org

appview/oauth: use ResumeSession when fetching currently logged in user #723

merged
opened by oppi.li targeting master from push-orvkryxksqsz

the final addition to my collection of oauth fixes: the session cookie is not a sufficient indication of a logged-in-ness of a user, we additionally validate this cookie against the session on redis using ResumeSession and kick users out if their session is invalid.

previously, a user may have appeared to be logged in (via the profile picture on the top right), but creating an auth'd request would have login-prompted them.

Signed-off-by: oppiliappan me@oppi.li

0
by oppi.li 0 comments
expand 1 commit
appview/oauth: use ResumeSession when fetching currently logged in user
Labels

None yet.

assignee

None yet.

Participants 1
AT URI
at://did:plc:qfpnj4og54vl56wngdriaxug/sh.tangled.repo.pull/3m4diskcvxo22