Files
Git'Fellow 1c9e5205f9 fix(auth): keep remember-me cookies pointing at a live session token
The remember-me cookie outlives the session token it refers to in two
cases, and cookie login then fails on every request.

A session token created as DO_NOT_REMEMBER (user_oidc, Apache login) is
removed by the cleanup job after session_lifetime, while the cookies last
remember_login_cookie_lifetime. loginWithApache() now creates its token
as REMEMBER, and createRememberMeToken() marks a DO_NOT_REMEMBER token
as REMEMBER for other callers with the same mismatch.

ISession::regenerateId(true, true) moves the token to the new session id
but left nc_session_id pointing at the old one (password protected share
unlock, Talk password rooms). The cookie is now rewritten with the new id.

Signed-off-by: Git'Fellow <12234510+solracsf@users.noreply.github.com>
2026-09-22 12:22:00 +02:00
..
2025-07-01 16:26:50 +02:00
2026-09-20 14:36:15 +00:00