fix(auth): stateless session cookie — stop logging users out on deploy (ADR-029)
Pilot feedback: lots of re-logging-in on iPhone. Three causes: sessions lived in an in-memory map (wiped on every pod restart/deploy), a 1h TTL (idle >1h forced re-login on a check-back-tomorrow reader), and a session cookie with no Max-Age (dropped on Safari close). Each re-login is the full IdP redirect dance. Make sessions stateless: identity + absolute expiry live inside the existing HMAC-signed cookie (no server table), TTL 1h → 30 days sliding, cookie now persistent (Max-Age). Survives restarts (test: a cookie from one instance is accepted by a fresh instance with the same secret), browser-close, and idle. Trade: no server-side revocation — logout clears the cookie client-side; rotating tapir-session-secret is the global logout lever. Accepted for the Stage-0 reader. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -306,13 +306,42 @@ func TestLogoutClearsSession(t *testing.T) {
|
||||
require.Equal(t, http.StatusFound, rec.Code)
|
||||
require.Equal(t, "/welcome", rec.Header().Get("Location"), "logout lands on the public page")
|
||||
cleared := sessionCookie(t, rec.Result())
|
||||
require.Less(t, cleared.MaxAge, 0, "logout expires the cookie")
|
||||
require.Less(t, cleared.MaxAge, 0, "logout expires the cookie so the browser drops it")
|
||||
require.Empty(t, cleared.Value, "logout blanks the cookie value")
|
||||
|
||||
// The server-side session is gone: the original cookie no longer resolves.
|
||||
// Sessions are stateless (ADR-029): logout clears the cookie client-side, so a
|
||||
// request carrying the cleared (empty) cookie is unauthenticated. The original
|
||||
// signed cookie remains technically valid until its expiry — the accepted
|
||||
// trade for no server-side store; the browser no longer holds it.
|
||||
check := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
check.AddCookie(cookie)
|
||||
check.AddCookie(cleared)
|
||||
_, ok := auth.CurrentUser(check)
|
||||
require.False(t, ok)
|
||||
require.False(t, ok, "the cleared cookie does not authenticate")
|
||||
}
|
||||
|
||||
// TestSessionSurvivesRestart is the core of ADR-029: a cookie issued by one
|
||||
// process is accepted by a FRESH instance with the same session secret — so a
|
||||
// deploy/pod-restart no longer logs users out (the old in-memory store did).
|
||||
func TestSessionSurvivesRestart(t *testing.T) {
|
||||
f := newFakeIssuer(t)
|
||||
auth1 := newAuth(t, f)
|
||||
cookie := authenticate(t, auth1, f)
|
||||
|
||||
auth2 := newAuth(t, f) // simulate a redeploy: new process, same SessionSecret
|
||||
req := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
req.AddCookie(cookie)
|
||||
user, ok := auth2.CurrentUser(req)
|
||||
require.True(t, ok, "a session must survive a restart (stateless signed cookie)")
|
||||
require.Equal(t, testSubject, user.Subject)
|
||||
}
|
||||
|
||||
// TestSessionCookieIsPersistent: the cookie carries a positive Max-Age so it
|
||||
// survives the browser/app being closed (a session cookie was dropped on iOS).
|
||||
func TestSessionCookieIsPersistent(t *testing.T) {
|
||||
f := newFakeIssuer(t)
|
||||
auth := newAuth(t, f)
|
||||
cookie := authenticate(t, auth, f)
|
||||
require.Greater(t, cookie.MaxAge, 0, "session cookie must be persistent (Max-Age set)")
|
||||
}
|
||||
|
||||
func TestExpiredSessionRejected(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user