Repository navigation
Redirect expired sessions to login - #456
Merged
Merged
Conversation
There was a problem hiding this comment.
Sorry @JacquesDelfrate, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 4 days and 11 hours by commenting @sourcery-ai review. Upgrade to get a review now.
Reviewer's GuideThe PR adds a centralized expired-session flow that detects authenticated API 401s, clears stale authentication state, deduplicates redirects, and sends users to tenant login with a validated return path. Login consumes the redirect state, shows a localized message, restores the prior route after re-authentication, and public auth requests remain excluded. Sequence diagram for expired session detection and login recoverysequenceDiagram
participant API as PACS API
participant Client as Axios interceptor
participant Session as Session expiry handler
participant Storage as Local storage
participant Login as Login page
participant User as User
API-->>Client: 401 UNAUTHORIZED_ACCESS
Client->>Session: handleSessionExpiredError(error)
Session->>Session: isPublicAuthRequest(url)
Session->>Storage: Read sessionToken and redirect state
Session->>Storage: Clear sessionToken
Session->>Storage: Save safe returnTo and pending flag
Session->>Login: Redirect to /login with tenant, reason, returnTo
Login->>Session: consumeSessionExpiredRedirect(search)
Session->>Storage: Clear pending redirect state
Login->>User: Show translated session-expired message
User->>Login: Submit credentials
Login->>Login: navigateAfterAuth(user, returnTo)
Login-->>User: Restore previous safe route
Flow diagram for expired session redirect safeguardsflowchart TD
A[API response] --> B{401 and UNAUTHORIZED_ACCESS?}
B -- No --> Z[Keep normal error handling]
B -- Yes --> C{Public authentication endpoint?}
C -- Yes --> Z
C -- No --> D{Authenticated session exists?}
D -- No --> Z
D -- Yes --> E{Redirect already pending?}
E -- Yes --> Z
E -- No --> F[Clear stale session token]
F --> G[Validate current route as safe returnTo]
G --> H[Store pending state and returnTo]
H --> I[Redirect to tenant login]
I --> J[Re-authenticate and restore safe route]
File-Level Changes
Assessment against linked issues
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Tests
Closes #455
Summary by Sourcery
Handle expired authenticated sessions by clearing stale credentials, redirecting users to tenant login, and safely restoring their prior route after sign-in.
New Features:
Bug Fixes:
Enhancements:
Tests: