Problem
The frontend permanently disables anonymous session-token acquisition after any failure from /api/session, including transient 5xx responses, network errors, CORS failures, and malformed responses.
With sessionAuth.enforce=true, later agent requests are sent without a token and continue failing until the user reloads the page, even after the session issuer recovers.
Root cause
fetchSessionToken() sets sessionEndpointAvailable = false for every non-success response and every caught exception. All later getSessionToken() calls then immediately return null.
postToAgent() also retries after 401/403 only when the initial token is truthy, so a failed initial token request cannot recover within the current agent request.
Proposed fix
- Permanently cache only explicit unsupported-endpoint responses (
404/405).
- Continue retrying after transient HTTP and network failures.
- Preserve a still-usable token when proactive refresh fails.
- Retry token acquisition once after
401/403, even if the initial token request returned nothing.
- Reject malformed successful responses without an access token.
Add regression coverage for the permanent-versus-transient status classification.
Problem
The frontend permanently disables anonymous session-token acquisition after any failure from
/api/session, including transient5xxresponses, network errors, CORS failures, and malformed responses.With
sessionAuth.enforce=true, later agent requests are sent without a token and continue failing until the user reloads the page, even after the session issuer recovers.Root cause
fetchSessionToken()setssessionEndpointAvailable = falsefor every non-success response and every caught exception. All latergetSessionToken()calls then immediately returnnull.postToAgent()also retries after401/403only when the initial token is truthy, so a failed initial token request cannot recover within the current agent request.Proposed fix
404/405).401/403, even if the initial token request returned nothing.Add regression coverage for the permanent-versus-transient status classification.