Commit 39ef3bd
committed
fix(auth): prefer a mid-flight published version over the default on read failure
Review catch. The success path re-checks the cache after its await so a
concurrent publish wins, but the catch path returned `DEFAULT_VERSION`
unconditionally.
The default is not the safe fallback it looks like — it is precisely the version
a never-bumped org carries. So a lookup that started before a revoke, and then
failed, could report `1` while this process already held the bumped counter:
the cookie-cache version would still MATCH pre-bump cookies and the
just-revoked session would keep being served from cache, which is the one thing
the bump exists to stop.
The catch now returns the cached value when one is present. It can only be
equal to or higher than the default, so it forces the same revalidation or more.1 parent b237aa4 commit 39ef3bd
2 files changed
Lines changed: 24 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
76 | 76 | | |
77 | 77 | | |
78 | 78 | | |
79 | | - | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
80 | 92 | | |
81 | 93 | | |
82 | 94 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
69 | | - | |
70 | | - | |
71 | | - | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
72 | 75 | | |
73 | 76 | | |
74 | 77 | | |
| |||
96 | 99 | | |
97 | 100 | | |
98 | 101 | | |
99 | | - | |
100 | | - | |
101 | | - | |
102 | | - | |
103 | | - | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
104 | 107 | | |
105 | 108 | | |
106 | 109 | | |
| |||
0 commit comments