Skip to content

Bound stalled session refresh bodies after HTTP 200 - #194

Merged
AetherAI3 merged 1 commit into
mainfrom
fix/refresh-body-timeout
Sep 27, 2026
Merged

AetherAI3 merged 1 commit into
mainfrom
fix/refresh-body-timeout

Conversation

@AetherAI3

Copy link
Copy Markdown
Owner

Summary

On a 401 from an ordinary API call, runSessionRefresh() applied a 10-second signal to the refresh fetch but awaited the HTTP 200 JSON body directly. A body reader that did not settle when the fetch signal aborted could pin the shared refresh flight. A later 401 would join that dead flight instead of making a new refresh attempt.

Race refresh headers, body parsing and the pre-commit token read against the existing combined cancellation/deadline signal. An expired or sole-caller-cancelled flight now settles and clears, while one caller's abort still leaves the flight available to another active waiter. Keep the original 401 as the user-visible outcome when refresh fails; never rotate a token after cancellation before the commit boundary.

Verification

  • npm run build
  • node --test --test-isolation=none dist/test/auth_401.test.js dist/test/transport_request.test.js (46 passed)
  • Repeated auth_401.test.js after updating the shared-flight body-phase case (28 passed)
  • git diff --check

The new regression supplies a synthetic HTTP 200 refresh response whose JSON body ignores abort, cancels its only caller, and requires a later 401 to start a fresh refresh instead of hanging. The shared-refresh regression now holds the body after 200 headers, cancels one waiter and verifies the other still completes with one refresh. No live account call was made for this change. This PR does not tag or publish a package.

@AetherAI3
AetherAI3 merged commit 60ed1b2 into main Sep 27, 2026
9 checks passed
@AetherAI3
AetherAI3 deleted the fix/refresh-body-timeout branch September 27, 2026 21:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant