Skip to content

bug(frontend): transient session failures permanently disable token acquisition #253

Description

@sanjayy0612

Problem

The frontend permanently disables anonymous session-token acquisition after any failure from /api/session, including transient 5xx responses, network errors, CORS failures, and malformed responses.

With sessionAuth.enforce=true, later agent requests are sent without a token and continue failing until the user reloads the page, even after the session issuer recovers.

Root cause

fetchSessionToken() sets sessionEndpointAvailable = false for every non-success response and every caught exception. All later getSessionToken() calls then immediately return null.

postToAgent() also retries after 401/403 only when the initial token is truthy, so a failed initial token request cannot recover within the current agent request.

Proposed fix

  • Permanently cache only explicit unsupported-endpoint responses (404/405).
  • Continue retrying after transient HTTP and network failures.
  • Preserve a still-usable token when proactive refresh fails.
  • Retry token acquisition once after 401/403, even if the initial token request returned nothing.
  • Reject malformed successful responses without an access token.

Add regression coverage for the permanent-versus-transient status classification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions