Bound stalled session refresh bodies after HTTP 200 - #194
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
On a 401 from an ordinary API call,
runSessionRefresh()applied a 10-second signal to the refreshfetchbut awaited the HTTP 200 JSON body directly. A body reader that did not settle when the fetch signal aborted could pin the shared refresh flight. A later 401 would join that dead flight instead of making a new refresh attempt.Race refresh headers, body parsing and the pre-commit token read against the existing combined cancellation/deadline signal. An expired or sole-caller-cancelled flight now settles and clears, while one caller's abort still leaves the flight available to another active waiter. Keep the original 401 as the user-visible outcome when refresh fails; never rotate a token after cancellation before the commit boundary.
Verification
npm run buildnode --test --test-isolation=none dist/test/auth_401.test.js dist/test/transport_request.test.js(46 passed)auth_401.test.jsafter updating the shared-flight body-phase case (28 passed)git diff --checkThe new regression supplies a synthetic HTTP 200 refresh response whose JSON body ignores abort, cancels its only caller, and requires a later 401 to start a fresh refresh instead of hanging. The shared-refresh regression now holds the body after 200 headers, cancels one waiter and verifies the other still completes with one refresh. No live account call was made for this change. This PR does not tag or publish a package.