Pennywise
Restore resilient PWA sessions
Summary
Restored authentication from the HttpOnly refresh cookie on startup and visibility resume, preserved sessions through transient failures, prevented refresh/logout races, and added frontend, browser, and proxy regression coverage.
Decisions
- Treat refresh responses 400, 401, and 403 as terminal while preserving authentication state for network and 5xx failures
- Coordinate rotating refresh cookies across browser contexts with Web Locks and BroadcastChannel without persisting access tokens
- Make local logout authoritative and suppress stale refresh results with a session generation guard
- Require redacted production Set-Cookie inspection because proxy tests cannot prove upstream cookie durability
Learnings
- Goauth reports expired, reused, or missing refresh-token state as HTTP 400
- In-memory single-flight refresh protection does not coordinate tabs that share a rotating refresh cookie