Pennywise

1 min read

Restore resilient PWA sessions

Summary

Restored authentication from the HttpOnly refresh cookie on startup and visibility resume, preserved sessions through transient failures, prevented refresh/logout races, and added frontend, browser, and proxy regression coverage.

Decisions

  • Treat refresh responses 400, 401, and 403 as terminal while preserving authentication state for network and 5xx failures
  • Coordinate rotating refresh cookies across browser contexts with Web Locks and BroadcastChannel without persisting access tokens
  • Make local logout authoritative and suppress stale refresh results with a session generation guard
  • Require redacted production Set-Cookie inspection because proxy tests cannot prove upstream cookie durability

Learnings

  • Goauth reports expired, reused, or missing refresh-token state as HTTP 400
  • In-memory single-flight refresh protection does not coordinate tabs that share a rotating refresh cookie