Skip to content

Notify user about Session expiries - #365

Open
Bohreromir wants to merge 4 commits into
mainfrom
worktree-fix-356-session-expiry
Open

Bohreromir wants to merge 4 commits into
mainfrom
worktree-fix-356-session-expiry

Conversation

@Bohreromir

Copy link
Copy Markdown
Member

Now the user gets a blocking modal informing him about the session expiry.
This makes the cockpit not fail randomly from a user perspective.

API routes redirected unauthenticated requests to the HTML login page,
so client-side fetch callers failed with a JSON parse error once the
session had expired. Page routes still redirect to the login page.

Refs #356

asdf
@Bohreromir Bohreromir self-assigned this Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 51.02% 2514 / 4927
🔵 Statements 57.03% 3728 / 6536
🔵 Functions 65.73% 1036 / 1576
🔵 Branches 43.13% 1313 / 3044
File Coverage
File Stmts Branches Functions Lines Uncovered Lines
Changed Files
src/hooks.client.ts 0% 0% 0% 0% 10-26
src/hooks.server.ts 0% 0% 0% 0% 14-104
src/lib/client/session.svelte.ts 100% 100% 100% 100%
src/lib/components/Modal.svelte 80.76% 77.27% 100% 85.71% 25, 37-38, 44, 51
src/lib/components/layout/SessionExpiredModal.svelte 0% 100% 0% 0% 9-50
src/lib/server/auth-guard.ts 100% 100% 100% 100%
src/routes/(app)/+layout.svelte 0% 0% 0% 0% 10-70
Generated in workflow #1047 for commit 13cfaa7 by the Vitest Coverage Report Action

Wrap window.fetch in the client init hook so that any same-origin 401
triggers a session check. A 401 alone is not proof of an expired session
(the storage API uses it for a missing connection), so only an explicit
"no session" answer from better-auth marks the session as expired.

Refs #356

fix(auth): ignore session check results after the layout unmounts

Refs #356
Show a non-dismissible modal with a link to sign in again, returning the
user to the current page afterwards. The session is also checked when
the tab becomes visible again, so the modal appears before the next
API call. Modal gains a dismissible prop and passes through attributes
such as aria-labelledby.

Refs #356
Closes #356

test(e2e): check the session modal survives a repeated Escape

Refs #356
@Bohreromir
Bohreromir force-pushed the worktree-fix-356-session-expiry branch from e0ed631 to 13cfaa7 Compare October 8, 2026 09:04
@Bohreromir
Bohreromir marked this pull request as ready for review October 8, 2026 09:19
@Bohreromir Bohreromir linked an issue Oct 8, 2026 that may be closed by this pull request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Development: Waiting for Review

Development

Successfully merging this pull request may close these issues.

Error when signed out due to timelimit

1 participant