Repository navigation
fix(auth): harden the optimistic auth identity guard - #475
Conversation
Follow-up to udecode#473. One admission gate (react/identity-guard-registry.ts) that every token write and hand-out passes: SSR, fetcher, restore, hydration fallback, sign-in, auth-state publication, cRPC HTTP and the TanStack Start loader. State is shared across separately bundled entries through a globalThis registry; a trip is page-wide; the optimistic window ends at the Convex client's first auth result; JWTs are classified by structure.
🦋 Changeset detectedLatest commit: 15e1fb2 The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
@EfficiencyCorp is attempting to deploy a commit to the udecode Team on Vercel. A member of the Team first needs to authorize it. |
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
A trip can happen while no guarded provider is mounted (a token refresh that finishes after its provider unmounted, or the Start loader before any provider mounts). A provider mounting on the tripped page took the trip as already reported, so onTokenIdentityChange never ran and the app never reloaded. Every guarded provider that mounts or shows again on a tripped page now closes its client and calls it once.
create-next-app (Next 16.3.6), TanStack Start and Vite templates moved after 0.33.6's CI ran, so fixtures:check fails on every branch. Regenerated with bun run fixtures:sync; no scaffold or kitcn source change.
|
Independent shipping verification PASS. Head I did not author this patch. A separate clean worktree passed fresh package typecheck and build. The parent passed 123 focused and built-package tests. This exact head passed all 295 auth-client, React, and Start tests, plus a separate 10-test built-entrypoint replay. All runs had zero failures. Reviewed the 13 source-listed auth contract groups and both added regressions. Late guard enablement closes and reports once. An admission callback that changes the baseline cannot publish the stale JWT. No remaining correctness defects found. This is an independent code and package-behavior verdict, not a protected approving review. |
|
Autoclosure exact-head proof receipt. Head: Task evidence is COMPLETE: the body names the dedicated plan, that plan Both accepted P1 findings are fixed and replayed after the final push:
Exact-head replay: both regressions 2/0, auth-client/react/auth-start 295/0, Independent final-head verification is PASS: Unfiltered final inventory before this receipt: 4 top-level comments, Exact informational URL verdicts:
Required CI passed at this exact head: |
🐛 Fixes ➖ N/A
🧭 Task plan: docs/plans/2026-09-30-harden-optimistic-auth-identity-guard.md
🟢 95% confidence
✅ Outcome
Guarded tokens match the page identity and current provider baselines before
storage, auth publication, Convex handout, HTTP dispatch, or Start loaders.
Admission rechecks after
onTokenIdentityAdmitted. A page trip freezes everyprovider; each guarded provider closes its client and notifies once, including
guards enabled after the trip. Convex's first auth result ends the client's
optimistic window.
One
optimisticAuthsetting per client. Mixed kitcn revisions on one page areunsupported until reload. Protected code-owner/last-push approval remains a
separate landing gate; Vercel contributor-preview authorization is not required
by the branch's check rules.
🏗️ Design
One dependency-free browser registry owns admission, page identity and terminal
trip state across separately built package entries. Server requests do not
share that state. Store publication and async token consumers reuse admission;
quarantine and guarded notification have separate once-only lifecycles.
🧪 Verified
entrypoints: 10 pass, 0 fail. Package typecheck and fresh builds pass.
bun check: lint, typecheck, Bun/Vitest suites, CLI, Concave smoke,fixture freshness, consumer verify and runtime scenarios pass.
staleness and MDX compilation pass. Existing patch changeset updated.
and feedback receipts are posted in PR comments. Final autoreview and its
TruffleHog scan are clean.