mirror of
https://github.com/nextcloud/server.git
synced 2026-10-01 14:59:25 +02:00
loginWithCookie() regenerated the session id before validating the remember-me cookie. With stale cookies (e.g. after the session token was invalidated by an OIDC backchannel logout) every request rotated the session and failed. Parallel requests then forked the same session, and the browser could end up with a copy lacking data stored during the login, such as user_oidc's OIDC state or the login flow v2 state token. Regenerate the session id only once the cookie has been validated. Signed-off-by: Jonas <jonas@freesources.org> Assisted-by: ClaudeCode:claude-opus-5.5