Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Sign in / Register
  • L Lanestel Page Web
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 0
    • Merge requests 0
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Packages & Registries
    • Packages & Registries
    • Package Registry
    • Infrastructure Registry
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • Quang dung Truong
  • Lanestel Page Web
  • Merge requests
  • !21

Merged
Created Aug 07, 2026 by Quang dung Truong@quangdungMaintainer

fix(auth): stop refresh-token replay killing the session, and the login spinner it left behind

  • Overview 0
  • Commits 3
  • Pipelines 1
  • Changes 6

Refresh dedupe was keyed by in-flight duration: the entry was evicted 5s after the Java call settled. Rotation only writes the new cookie onto the response of the request that triggered it, so every request that left the browser earlier still carries the old token — an RSC navigation, a client hook's 401 handler, another open tab. After a tab idles past token expiry those arrive in a burst spread over seconds, and the stragglers landed outside the 5s window and replayed the token against Java, which treats a second use as an attack and kills the whole session family.

Keep each refresh_token mapped to its rotated result for 60s instead. Late callers are answered from the cache and still relay the rotated cookies, so their stale copy gets repaired. Failed refreshes are evicted immediately — they rotated nothing, so a genuine retry must get through.

Assignee
Assign to
Reviewer
Request review from
Time tracking
Source branch: fix/auth-refresh-replay-session-spinner