Skip to content

fix(auth): harden the optimistic auth identity guard - #475

Merged
zbeyens merged 10 commits into
udecode:mainfrom
EfficiencyCorp:feat/optimistic-auth-hardening-v2
Oct 1, 2026
Merged

zbeyens merged 10 commits into
udecode:mainfrom
EfficiencyCorp:feat/optimistic-auth-hardening-v2

Conversation

@EfficiencyCorp

@EfficiencyCorp EfficiencyCorp commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
  • Auto release

🐛 Fixes ➖ N/A
🧭 Task plan: docs/plans/2026-09-30-harden-optimistic-auth-identity-guard.md
🟢 95% confidence

Phase 🧪 Tests 🌐 Browser
Reproduced 🔴 38 original hardening cases; late guard notification and post-callback stale-token publication ➖ N/A
Verified 🟢 295 focused tests; 10 built-entrypoint cases; package typecheck/build; full repository/runtime gate ➖ N/A

✅ Outcome

Guarded tokens match the page identity and current provider baselines before
storage, auth publication, Convex handout, HTTP dispatch, or Start loaders.
Admission rechecks after onTokenIdentityAdmitted. A page trip freezes every
provider; each guarded provider closes its client and notifies once, including
guards enabled after the trip. Convex's first auth result ends the client's
optimistic window.

⚠️ Caveat

One optimisticAuth setting per client. Mixed kitcn revisions on one page are
unsupported until reload. Protected code-owner/last-push approval remains a
separate landing gate; Vercel contributor-preview authorization is not required
by the branch's check rules.

🏗️ Design

One dependency-free browser registry owns admission, page identity and terminal
trip state across separately built package entries. Server requests do not
share that state. Store publication and async token consumers reuse admission;
quarantine and guarded notification have separate once-only lifecycles.

🧪 Verified

  • Both additional regressions failed before repair and pass afterward.
  • Focused auth-client/react/auth-start: 295 pass, 0 fail. Built public
    entrypoints: 10 pass, 0 fail. Package typecheck and fresh builds pass.
  • bun check: lint, typecheck, Bun/Vitest suites, CLI, Concave smoke,
    fixture freshness, consumer verify and runtime scenarios pass.
  • Published auth guidance and generated mirror match; intent validation,
    staleness and MDX compilation pass. Existing patch changeset updated.
  • Independent verifier uses its own worktree; final head/base/patch-id verdict
    and feedback receipts are posted in PR comments. Final autoreview and its
    TruffleHog scan are clean.

Follow-up to udecode#473. One admission gate (react/identity-guard-registry.ts)
that every token write and hand-out passes: SSR, fetcher, restore,
hydration fallback, sign-in, auth-state publication, cRPC HTTP and the
TanStack Start loader. State is shared across separately bundled entries
through a globalThis registry; a trip is page-wide; the optimistic window
ends at the Convex client's first auth result; JWTs are classified by
structure.
@changeset-bot

changeset-bot Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 15e1fb2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
kitcn Patch
@kitcn/resend Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Sep 30, 2026

Copy link
Copy Markdown

@EfficiencyCorp is attempting to deploy a commit to the udecode Team on Vercel.

A member of the Team first needs to authorize it.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Repo admins can enable using credits for code reviews in their settings.

EfficiencyCorp and others added 9 commits September 30, 2026 19:10
A trip can happen while no guarded provider is mounted (a token refresh
that finishes after its provider unmounted, or the Start loader before any
provider mounts). A provider mounting on the tripped page took the trip as
already reported, so onTokenIdentityChange never ran and the app never
reloaded. Every guarded provider that mounts or shows again on a tripped
page now closes its client and calls it once.
create-next-app (Next 16.3.6), TanStack Start and Vite templates moved after
0.33.6's CI ran, so fixtures:check fails on every branch. Regenerated with
bun run fixtures:sync; no scaffold or kitcn source change.
@zbeyens

zbeyens commented Oct 1, 2026

Copy link
Copy Markdown
Member

Independent shipping verification PASS.

Head 15e1fb214e100e056703e14c59014aea5c70fc00. Destination udecode/kitcn:main at 126f3e992110b6ded7d7c9a7d8ce178b6ede61f8. Stable base-to-head patch ID 6a155377389d37893f15d53b0504b81912b93b57.

I did not author this patch. A separate clean worktree passed fresh package typecheck and build. The parent passed 123 focused and built-package tests. This exact head passed all 295 auth-client, React, and Start tests, plus a separate 10-test built-entrypoint replay. All runs had zero failures.

Reviewed the 13 source-listed auth contract groups and both added regressions. Late guard enablement closes and reports once. An admission callback that changes the baseline cannot publish the stale JWT. No remaining correctness defects found.

This is an independent code and package-behavior verdict, not a protected approving review.

@zbeyens

zbeyens commented Oct 1, 2026

Copy link
Copy Markdown
Member

Autoclosure exact-head proof receipt.

Head: 15e1fb214e100e056703e14c59014aea5c70fc00.
Destination: udecode/kitcn:main at
126f3e992110b6ded7d7c9a7d8ce178b6ede61f8.
Stable base-to-head patch ID: 6a155377389d37893f15d53b0504b81912b93b57.

Task evidence is COMPLETE: the body names the dedicated plan, that plan
exists at this head and owns #475. Source/plan updates were pushed before
this receipt; no receipt-only branch update.

Both accepted P1 findings are fixed and replayed after the final push:

  • Enabling a guard after a page trip closes the client and notifies once.
  • A baseline changed by the admission callback cannot publish the stale JWT.

Exact-head replay: both regressions 2/0, auth-client/react/auth-start 295/0,
built entrypoints 10/0, both plan completion checks pass. Full repaired-source
bun check passes, including lint/typecheck, Bun1556/0, Vitest1053 pass/14
skipped, CLI124/0, Concave, fixture freshness, consumer verify and runtime.
Fresh package typecheck/build, MDX, intent validation/staleness and source/mirror
parity pass. Autoreview at source-equivalent 90a1653 and TruffleHog are clean;
only versioned evidence changed afterward.

Independent final-head verification is PASS:
#475 (comment).
This is an informational nonauthor/verifier verdict, not protected approval.

Unfiltered final inventory before this receipt: 4 top-level comments,
0 review bodies, 0 inline threads (resolved/unresolved/outdated included;
pagination exhausted). Helper: 3 comments, 0 reviews, 0 threads. The omitted
Vercel item was read and classified, not ignored by author/bot identity.
Zero actionable P0-P3 feedback; no P2/P3 deferrals.

Exact informational URL verdicts:

Required CI passed at this exact head:
https://github.com/udecode/kitcn/actions/runs/36841319291.
Landing remains gated by another authorized code-owner/last-push approval.
No admin bypass, automatic merge or queue request was armed.

@zbeyens
zbeyens merged commit 9e513f8 into udecode:main Oct 1, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants