Repository navigation
Keep sessions across restarts and container upgrades - #673
Conversation
Two things signed everybody out: - The wizard's database step rewrote .env with only the database settings, dropping the SESSION_KEY startup had just written. The first restart after an install generated a new key. The step now replaces only the database lines and keeps the rest of the file (#667). - The session cookie was named after the machine's hostname, which Docker makes up for every new container, so any upgrade that replaced the container signed everybody out. The name is now fixed. The install smoke test now checks that the browser the wizard logged in is still logged in after the container is restarted or replaced. Closes #667. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It changes the session cookie name and .env persistence during install, affecting authentication for all users (a one-time forced sign-out on upgrade), which warrants human sign-off.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
This PR fixes two independent causes of admins being signed out, so that sessions survive server restarts and container upgrades. The first is issue #667: the install wizard's database step (POST /wizard_db) rewrote .env with only the database settings, discarding the SESSION_KEY that startup had just written (and any SMTP/admin-pin lines an operator added). The second is that the session cookie was named after os.Hostname(), which Docker regenerates per container, so replacing a container invalidated everyone's cookies. It fits into the existing install-wizard and session-setup flow in main().
Changes:
- Added
dbConfig.mergedEnvFile, which replaces only the database lines in an existing.envand keeps everything else;updateDBnow uses it instead of overwriting the whole file. - Replaced the hostname-based session cookie name with a fixed constant
goblog_session, and removed the now-unusedos.Hostname()handling and debug logging. - Added/updated tests (
TestMergedEnvFile,TestInstallOnlysession-key check) and a smoke-test assertion that the wizard's session survives a restart/container replacement.
| File | Description |
|---|---|
| db.go | New isDatabaseEnvKey/mergedEnvFile helpers that preserve non-database .env lines while replacing database settings. |
| goblog.go | Uses the new merge when writing .env, introduces the fixed sessionCookieName constant, and removes hostname lookup/error handling. |
| db_test.go | Adds TestMergedEnvFile covering preservation, idempotency, and empty-input behavior. |
| wizard_install_only_test.go | Seeds .env with a session key and asserts the database step keeps it (#667). |
| scripts/install-smoke-test.sh | Adds a post-restart check that the wizard's browser is still an admin. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
The hostname cookie name was a separate problem from #667, which is the database step dropping the session key. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Closes #667.
Problem
Two separate things signed everybody out:
POST /wizard_dbrewrote.envwith only the database settings, losing theSESSION_KEYstartup had written moments earlier. The first restart after an install generated a new key, so the admin who had just finished was signed out. It would equally have dropped SMTP or admin-pin settings placed in.envbeforehand.sessions.Sessions(os.Hostname(), …). Docker gives every new container a random hostname, so any upgrade that replaces the container (including an Ansible redeploy) signed everyone out, even with the key intact. I found this when the smoke test's new check failed only in the "replace the container" configuration.Changes
dbConfig.mergedEnvFilereplaces the database lines (database,sqlite_db,MYSQL_*,POSTGRES_*) in the existing.envand keeps everything else;updateDBuses it.goblog_session.Upgrading
Because the cookie name changes, everyone is signed out once when a site upgrades to the release containing this. After that, upgrades no longer sign anyone out.
Testing
TestMergedEnvFile(keeps other lines, comments, idempotent, empty.env), andTestInstallOnlynow checks the session key survives the database step.go test ./...passes.🤖 Generated with Claude Code