Files
Jonas 0bbfe2e4d9 fix(session): only regenerate session id after valid remember-me cookie
loginWithCookie() regenerated the session id before validating the
remember-me cookie. With stale cookies (e.g. after the session token was
invalidated by an OIDC backchannel logout) every request rotated the
session and failed. Parallel requests then forked the same session, and
the browser could end up with a copy lacking data stored during the
login, such as user_oidc's OIDC state or the login flow v2 state token.

Regenerate the session id only once the cookie has been validated.

Signed-off-by: Jonas <jonas@freesources.org>
Assisted-by: ClaudeCode:claude-opus-5.5
2026-09-30 10:46:09 +00:00
..
2025-07-01 16:26:50 +02:00