Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions src/lib/common/shared/TimeRangePicker.svelte
Original file line number Diff line number Diff line change
Expand Up @@ -330,7 +330,7 @@
>
<button
type="button"
class="form-control text-start d-flex align-items-center justify-content-between"
class="form-control text-start d-flex align-items-center justify-content-between clickable"
on:click={() => {
showDatePicker = !showDatePicker;
if (showDatePicker) {
Expand All @@ -344,9 +344,10 @@
}
}
}}
style="cursor: pointer;"
>
<span>{timeRangeDisplayText || 'Select time range'}</span>
<span style="overflow: hidden; text-overflow: ellipsis; white-space: nowrap;">
{timeRangeDisplayText || 'Select time range'}
</span>
<i class="bx bx-chevron-down"></i>
</button>
{#if showDatePicker}
Expand Down
2 changes: 1 addition & 1 deletion src/lib/helpers/http.js
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ const retryQueue = {
isRefreshingToken: false,

/** @type {number} */
timeout: 20,
timeout: 200,

/** @type {number} */
maxRenewTokenCount: 30,
Expand Down
15 changes: 8 additions & 7 deletions src/lib/helpers/store.js
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
// @ts-nocheck
import { writable } from 'svelte/store';
import { writable, get } from 'svelte/store';
import { browser } from '$app/environment';

const userKey = "user";
Expand Down Expand Up @@ -42,17 +42,18 @@ export const userStore = writable({ id: "", full_name: "", expires: 0, token: nu
*/
export function getUserStore() {
if (browser) {
// Access localStorage only if in the browser context
const storeValue = get(userStore);
if (storeValue?.token) {
return storeValue;
}

let json = sessionStorage.getItem(userKey);
if (json) {
return JSON.parse(json);
} else {
return userStore;
}
} else {
// Return a default value for SSR
return userStore;
}

return get(userStore);
Comment on lines +45 to +56

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. Logout token not cleared 🐞 Bug ⛨ Security

getUserStore() now returns the in-memory userStore value when it has a token, but logout only clears
sessionStorage via resetStorage(true) and never clears userStore, so the SPA can continue sending
the old Authorization token after logout. This breaks logout guarantees and can keep a user
effectively authenticated until a full reload.
Agent Prompt
### Issue description
Logout calls `resetStorage(true)` which clears `sessionStorage`, but does not clear the in-memory `userStore`. After the PR change, `getUserStore()` prefers `get(userStore)` when it has a token, so the app can keep sending an Authorization header even after logout.

### Issue Context
`axios.interceptors.request.use` reads `getUserStore().token` for every request; therefore logout must clear both persisted and in-memory auth state.

### Fix Focus Areas
- src/lib/helpers/store.js[296-307]
- src/lib/helpers/store.js[37-57]
- src/lib/common/dropdowns/ProfileDropdown.svelte[16-28]
- src/lib/helpers/http.js[105-125]

### Suggested change
- In `resetStorage(resetUser=true)`, call `userStore.set({ id: '', full_name: '', expires: 0, token: null })` (and clear any other user fields used elsewhere, e.g. `renew_token_count`).
- Optionally, update the `userStore.subscribe` persistence logic to `removeItem(userKey)` when `value.token` is falsy to prevent stale resurrection in other flows.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

};


Expand Down
Loading