Skip to content

[DEVOPS-4768] fix(auth): do not send stale tokenId on login - #49

Merged
Danny Bédard (DannyBedard) merged 2 commits into
masterfrom
devops/DEVOPS-4768-token-refresh
Sep 30, 2026
Merged

Danny Bédard (DannyBedard) merged 2 commits into
masterfrom
devops/DEVOPS-4768-token-refresh

Conversation

@DannyBedard

@DannyBedard Danny Bédard (DannyBedard) commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Après l'expiration de la session DVLS (environ 7 min), le client détecte bien is-logged = false et se reconnecte, mais le login renvoyait le header tokenId expiré, et DVLS rend alors un nouveau jeton déjà mort (401). Le login part maintenant sans tokenId : le jeton est passé explicitement à la fonction interne rawRequestWithContext, sans toucher au jeton partagé ni à l'API publique.

Validé sur dvls-ops : connexion, attente de 8 min, requête. master reçoit 401, cette branche passe. Bump en 0.21.1.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Token clearing introduces a race that can cause concurrent requests to omit authentication.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Fixes token refresh by preventing expired tokens from being sent during login.

Changes:

  • Clears expired tokens before re-authentication.
  • Omits empty tokenId headers and adds refresh coverage.
  • Bumps the patch version.
File Description
VERSION Bumps version to 0.21.1.
authentication.go Clears the token before login.
dvls.go Omits empty token headers.
dvls_unit_test.go Tests expired-token refresh.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread authentication.go Outdated
@DannyBedard Danny Bédard (DannyBedard) changed the title Devops/devops 4768 token refresh [DEVOPS-4768] fix(auth): do not send stale tokenId on login Sep 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Extending the exported options struct breaks consumers using positional struct literals.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread dvls.go Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation fixes stale-token reauthentication without changing the public API and includes focused regression coverage.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@DannyBedard
Danny Bédard (DannyBedard) merged commit 70bcb8b into master Sep 30, 2026
3 checks passed
@DannyBedard
Danny Bédard (DannyBedard) deleted the devops/DEVOPS-4768-token-refresh branch September 30, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants