Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: duplicate session token issue when cookieDomain is changed #408

Conversation

furkansenharputlu
Copy link
Contributor

Summary of change

  • Added OlderCookieDomain config option in the session recipe. This will allow users to clear cookies from older domain when the CookieDomain is changed.
  • Fixed an issue where the access token wasn't cleared if refresh token API was called without a refresh token

Related issues

supertokens/supertokens-node#790

Test Plan

(Write your test plan here. If you changed any code, please provide us with clear instructions on how you verified your changes work. Bonus points for screenshots and videos!)

Documentation changes

(If relevant, please create a PR in our docs repo, or create a checklist here highlighting the necessary changes)

Checklist for important updates

  • Changelog has been updated
  • coreDriverInterfaceSupported.json file has been updated (if needed)
    • Along with the associated array in supertokens/constants.go
  • frontendDriverInterfaceSupported.json file has been updated (if needed)
  • Changes to the version if needed
    • In supertokens/constants.go > version variable
  • Had installed and ran the pre-commit hook
  • If new thirdparty provider is added,
    • update switch statement in recipe/thirdparty/providers/config_utils.go file, createProvider function.
    • add an icon on the user management dashboard.
  • Issue this PR against the latest non released version branch.
    • To know which one it is, run find the latest released tag (git tag) in the format vX.Y.Z, and then find the latest branch (git branch --all) whose X.Y is greater than the latest released tag.
    • If no such branch exists, then create one from the latest released branch.
  • If access token structure has changed
    • Modified test in session/accessTokenVersions_test.go to account for any new claims that are optional or omitted by the core

@furkansenharputlu furkansenharputlu force-pushed the fix/cookie-domain-inconsistency branch from 49a1792 to f4429bc Compare April 30, 2024 12:25
@furkansenharputlu furkansenharputlu force-pushed the fix/cookie-domain-inconsistency branch from f4429bc to 197c6be Compare April 30, 2024 12:27
@rishabhpoddar rishabhpoddar changed the base branch from 0.17 to cookie-domain-fix April 30, 2024 13:36
@rishabhpoddar rishabhpoddar merged commit cfc4942 into supertokens:cookie-domain-fix Apr 30, 2024
6 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants