Repository navigation
Refactor cookie-mode anonymous history hand-off - #144
akshatmalik-bruh wants to merge 1 commit into
Conversation
|
Thanks for the PR. I reviewed the current HEAD and I still see a few blockers before this is ready to merge.
After a successful server-side adoption, the visitor pass is never cleared from
That means the flow becomes: We need an explicit acknowledgement/consumption mechanism so the widget can clear the pass after a successful hand-off. Invalid/expired passes should also not be sent forever.
That means bearer/token-authenticated requests can also enter the new implicit hand-off path, while #131 was specifically about fixing zero-code cookie mode without changing the existing bearer flow. Please either:
The current
The TypeScript implementation changed substantially, but The existing widget tests still expect the old Please update the frontend tests to cover the new contract and rebuild/commit
Since concurrency is an explicit acceptance criterion in #131, please add a real concurrent/racing test that proves two first authenticated requests cannot adopt the same visitor history twice or produce inconsistent ownership.
This PR also changes: from: to: That is unrelated to anonymous-history hand-off and should be removed from this PR. The overall server-side opportunistic hand-off direction is good and matches the architecture proposed in #131. I don't think the core approach needs to be redesigned — these are mainly lifecycle, auth-boundary, and regression-coverage issues. One final repo-state point: the branch is currently behind |
Context
Fixes the issue where the frontend was forced to guess when an anonymous visitor logged into a cookie-authenticated host app by repeatedly polling
POST /auth/linkand receiving401 Unauthorizedresponses. This guessing game resulted in unnecessary network spam, latency, and a fragile dependency on window/cookie events.fixes #131
What Changed
Implemented Server-Side Opportunistic Hand-off. The server is now the authoritative source of truth for when an authenticated session begins.
Backend (
deps.py)X-Extra-Visitor-Passheader.get_principalintercepts this header. If the request has an authenticated session cookie and a visitor pass header, the backend opportunistically callslink_anonymousbefore serving the request.Frontend (
tokenSource.ts&AgentChatClient.ts)identityCheckDirty,cookieSnapshotChanged,forceCheck, and focus/visibility/storage event listeners).POST /auth/linkprobes in cookie mode.AgentChatClientsimply attaches theX-Extra-Visitor-Passheader to everyfetch.Verification
test_api.pycovering all edge cases (immediate login, already-adopted pass, invalid pass, concurrent requests, bearer mode preservation).make checkpasses perfectly (linting, typechecking, and all 57 tests).