Conversation
…ed out Documents `ready`, `whenReady()` and `restoreFailed` on useLukkAuth: which to gate decisions on versus render on, the deep-link restore and useAsyncData patterns, middleware that defers while the session is unknown, and a retry UI for a restore that couldn't reach the server. States where the gap actually is — a server render that didn't hydrate a user — rather than client setup(), which Nuxt already runs after the restore. Notes that the built-in lukk-auth middleware does not check `ready` or `restoreFailed` yet. Also corrects transport-modes: an access token expired at render time is refreshed and re-sealed in place, not deferred to the client.
From review of ca72f74. - The deep-link example put a raw query value into a credentialed URL (`?id=../me/export` reached another endpoint) and did not compile. It now validates and encodes the value. - Data loading uses `server: ready.value` rather than `server: false`, so the BFF path keeps server-rendered data (checked against Nuxt's useAsyncData hydration logic). - whenReady() is shown where it is needed — a store or plugin — since middleware, setup() and onMounted already run after the restore; a plugin awaiting it needs dependsOn: ['lukk:session-restore']. - New warnings: reading ready/restoreFailed in a template causes a hydration mismatch; validate a `redirect` parameter before following it; don't cache routes that hydrate a user; a BFF without clientIpHeader lets one client put every visitor into the "couldn't reach the server" state. - The middleware example gains a /login guard and states that deferring renders the protected page on the server. - "Exactly" claims about when `ready` is false and what sets `restoreFailed` were wrong and are corrected. All seven code examples type-check in the playground.
…rected plugin and caching notes - Sign-in/logout handover and its limits (10s cap, BFF proxy refreshes, other tabs). - safeRedirect parses the URL: the old pattern let /.//evil.com through. - Deep-link example checks restoreFailed before redirecting to /login. - whenReady() plugin example lives in a .client.ts file; lukk:client dependency doesn't help; Nuxt 3 vs 4 reporting. - Nitro swr/cache routes render without cookies (hydration off), not a leak; varies: ['cookie'] warning. - restoreFailed doesn't survive clearNuxtState(); clientIpHeader needs TrustProxies and shares a 30/min bucket.
…cap/rotation wording
…viour
- Logout: 401 means nothing left to end; anything else may still be live,
so offer a retry; await before navigating.
- Refresh-and-retry exceptions and logout({ retry }) across lukk-core,
rotation, architecture and introduction pages.
- SSR hydration/no-store wording, restore diagram failure path, user.md
loggedIn and LukkUser augmentation, step-up 409, limits list, cross-tab
sync, grace_seconds > 0 in direct mode.
- lukk facts: grace window returns a full pair, login route throttle, event
reasons and lockout purposes, export example, per-guard 2FA.
- lukk 0.7.0: logout by refresh token + CSRF rule + 429, logout_all and
removed flags, 2FA with block_unverified_login, export lockouts.
- Seven dead anchors fixed.
Queued on the shared `pages` group, GitHub keeps only the newest pending run and cancels the others — opening three docs PRs together left one with no checks at all. Deploys still serialize.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First of three stacked docs PRs. Merge bottom-up.
Waiting for the session, telling a failed restore from signed out, session handover, a redirect validator that parses the URL, BFF guards for replaced sessions, and corrected plugin and caching notes.