Skip to content

fix(nhis): skip the last-logged update on read-only storages - #158

Merged
albanm merged 1 commit into
masterfrom
chore-dev-nhis
Sep 29, 2026
Merged

albanm merged 1 commit into
masterfrom
chore-dev-nhis

Conversation

@albanm

@albanm albanm commented Sep 29, 2026

Copy link
Copy Markdown
Member

The NHI token exchange no longer calls updateLogged when the global storage is read-only. This is the same readonly guard the password login path already uses in confirmLog.

Why: with file or LDAP storage, an NHI could not get a session at all. FileStorage.updateLogged and LdapStorage.updateLogged throw Method not implemented. synchronously, so the .catch() on the returned promise never attached and the exchange failed with a 500. Found while seeding dev NHIs for the data-fair/agents stack.

Two unit tests in file-storage.unit.spec.ts pin that the storage declares itself readonly and that updateLogged throws synchronously.

The NHI token exchange called updateLogged unconditionally, while the password
path guards it with `if (!storage.readonly)` in confirmLog. Under file storage
that made the exchange fail outright: FileStorage.updateLogged throws
`Method not implemented.` SYNCHRONOUSLY — it is not async — so the `.catch()` on
the returned promise never attached and the throw propagated as a 500.

The effect was that an NHI could not obtain a session at all under file storage,
even though everything else on that path works: getUser is a read FileStorage
implements, and it carries an `nhi` field through verbatim. This was the only
thing standing between a file-storage deployment and a working exchange.

Fixed by applying the same readonly guard the login path already uses, so the
two call sites agree. Two unit tests pin it: that the storage declares itself
readonly (the flag callers must branch on), and that updateLogged throws
synchronously — the second is what makes a `.catch()` insufficient, so if it
ever becomes an async rejection the test fails and the guard can be removed.

Found while giving the data-fair/agents dev stack fixture NHIs so its autonomous
agents could complete a real token exchange in dev rather than only in staging.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@albanm
albanm merged commit 7e4ea64 into master Sep 29, 2026
4 checks passed
@github-actions github-actions Bot added the fix label Sep 29, 2026
@albanm
albanm deleted the chore-dev-nhis branch September 29, 2026 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant