Skip to content

Document session readiness and handover - #12

Open
stsepelin wants to merge 8 commits into
mainfrom
docs/session-readiness
Open

stsepelin wants to merge 8 commits into
mainfrom
docs/session-readiness

Conversation

@stsepelin

Copy link
Copy Markdown
Owner

First of three stacked docs PRs. Merge bottom-up.

Waiting for the session, telling a failed restore from signed out, session handover, a redirect validator that parses the URL, BFF guards for replaced sessions, and corrected plugin and caching notes.

…ed out

Documents `ready`, `whenReady()` and `restoreFailed` on useLukkAuth:
which to gate decisions on versus render on, the deep-link restore and
useAsyncData patterns, middleware that defers while the session is
unknown, and a retry UI for a restore that couldn't reach the server.

States where the gap actually is — a server render that didn't hydrate a
user — rather than client setup(), which Nuxt already runs after the
restore. Notes that the built-in lukk-auth middleware does not check
`ready` or `restoreFailed` yet.

Also corrects transport-modes: an access token expired at render time is
refreshed and re-sealed in place, not deferred to the client.
From review of ca72f74.

- The deep-link example put a raw query value into a credentialed URL
  (`?id=../me/export` reached another endpoint) and did not compile.
  It now validates and encodes the value.
- Data loading uses `server: ready.value` rather than `server: false`, so
  the BFF path keeps server-rendered data (checked against Nuxt's
  useAsyncData hydration logic).
- whenReady() is shown where it is needed — a store or plugin — since
  middleware, setup() and onMounted already run after the restore; a
  plugin awaiting it needs dependsOn: ['lukk:session-restore'].
- New warnings: reading ready/restoreFailed in a template causes a
  hydration mismatch; validate a `redirect` parameter before following
  it; don't cache routes that hydrate a user; a BFF without
  clientIpHeader lets one client put every visitor into the
  "couldn't reach the server" state.
- The middleware example gains a /login guard and states that deferring
  renders the protected page on the server.
- "Exactly" claims about when `ready` is false and what sets
  `restoreFailed` were wrong and are corrected.

All seven code examples type-check in the playground.
…rected plugin and caching notes

- Sign-in/logout handover and its limits (10s cap, BFF proxy refreshes,
  other tabs).
- safeRedirect parses the URL: the old pattern let /.//evil.com through.
- Deep-link example checks restoreFailed before redirecting to /login.
- whenReady() plugin example lives in a .client.ts file; lukk:client
  dependency doesn't help; Nuxt 3 vs 4 reporting.
- Nitro swr/cache routes render without cookies (hydration off), not a leak;
  varies: ['cookie'] warning.
- restoreFailed doesn't survive clearNuxtState(); clientIpHeader needs
  TrustProxies and shares a 30/min bucket.
…viour

- Logout: 401 means nothing left to end; anything else may still be live,
  so offer a retry; await before navigating.
- Refresh-and-retry exceptions and logout({ retry }) across lukk-core,
  rotation, architecture and introduction pages.
- SSR hydration/no-store wording, restore diagram failure path, user.md
  loggedIn and LukkUser augmentation, step-up 409, limits list, cross-tab
  sync, grace_seconds > 0 in direct mode.
- lukk facts: grace window returns a full pair, login route throttle, event
  reasons and lockout purposes, export example, per-guard 2FA.
- lukk 0.7.0: logout by refresh token + CSRF rule + 429, logout_all and
  removed flags, 2FA with block_unverified_login, export lockouts.
- Seven dead anchors fixed.
Queued on the shared `pages` group, GitHub keeps only the newest pending
run and cancels the others — opening three docs PRs together left one with
no checks at all. Deploys still serialize.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant