Skip to content

chore(soe): make the Arcane long-lived login an opt-in - #84

Merged
catinspace-au merged 1 commit into
mainfrom
fix/arcane-long-session
Sep 3, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/arcane-long-session

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Arcane's default login lasts about a day, which is a login prompt every morning on a dev box. Two knobs move it and both are needed - either one alone still logs you out.

  • authSessionTimeout (settings table, minutes) sets the access token's life, and the access-token cookie is the only thing that survives a browser restart. The server clamps it to 15..525600 and has no never-expire value, so a year from each login is the practical ceiling.
  • JWT_REFRESH_EXPIRY (env) stamps the session row's expiry at login and is never extended on refresh. Left at the image's 168h, every request 401s at day seven whatever the timeout says.

Off by default. Arcane holds the Docker socket, so a year-long cookie is a per-machine decision. Both settings stay absent while the flag is off rather than being written at a default, so a value set by hand in the UI survives a re-run.

-e soe_arcane_enabled=true -e soe_arcane_long_session=true

Verified on desktop-derek, real runs

  • Flag off: no JWT_REFRESH_EXPIRY in the container env or arcane.env.
  • Flag on: JWT_REFRESH_EXPIRY=87600h in the container env, and authSessionTimeout = 525600 read from the SQLite settings table.
  • Flag off again: the timeout stays 525600 rather than being reset, and the env var is removed.
  • ansible-lint clean on the role, run-tests.sh green.

Two things worth knowing

The brief's premise was v2.8.0; desktop-derek runs v2.10.1. On v2.10.1 the settings GET returns 22 keys and includes none of the ones the role manages, so changed=0 on a re-run is not achievable. That predates this change - with the flag off, carrying exactly what main carries, the assert still reports changed. Filed as #83 rather than widened into here.

Not verified: that changed_when on Start Arcane fires when only arcane.env moves. It correctly reported ok on the second run, where the file was unchanged, but I did not isolate a run that moved only that file.

dragonfly's Arcane was left alone deliberately - hand-rolled stack, no ADMIN_STATIC_API_KEY, JWT_REFRESH_EXPIRY inline in compose, pinned v2.8.0, 16MB live database. A role run there would rewrite both files and recreate the container.

Arcane's default login lasts about a day, which is a prompt every morning on a
dev box. Two knobs move it and both are needed -- either alone still logs you
out.

authSessionTimeout sets the access token's life, and the access-token cookie is
the only thing that survives a browser restart. The server clamps it to
15..525600 minutes with no never-expire value, so a year from each login is the
ceiling. JWT_REFRESH_EXPIRY stamps the session row's expiry at login and is
never extended on refresh, so the image's 168h means every request 401s at day
seven whatever the timeout says.

Off by default: Arcane holds the Docker socket, so a year-long cookie is a
per-machine decision. Both settings stay absent while the flag is off rather
than being written at a default, so a value set by hand in the UI survives a
re-run.

Verified on desktop-derek with real runs. Flag off: neither JWT_REFRESH_EXPIRY
nor a written authSessionTimeout. Flag on: JWT_REFRESH_EXPIRY=87600h in the
container env and authSessionTimeout=525600 in the settings table. Flag off
again: the timeout is left at 525600 rather than reset.

Not achievable on v2.10.1: changed=0 on a re-run. That version's settings GET
returns none of the keys the role manages, so the diff always fires. It
predates this change -- with the flag off, carrying exactly what main carries,
the assert still reports changed.
@catinspace-au
catinspace-au merged commit 8c3f774 into main Sep 3, 2026
16 checks passed
@catinspace-au
catinspace-au deleted the fix/arcane-long-session branch September 3, 2026 00:31
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant