Skip to content

fix: stop session refresh after sign-out - #141

Merged
KatBrandt merged 1 commit into
mainfrom
fix/stop-refresh-after-sign-out
Sep 29, 2026
Merged

KatBrandt merged 1 commit into
mainfrom
fix/stop-refresh-after-sign-out

Conversation

@workos-tars

@workos-tars workos-tars Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Stop the SDK from refreshing after signOut() clears its session credentials. Previously the refresh timer remained active and the client remained authenticated, so a timer firing before navigation completed (or after signOut({ navigate: false })) could submit a refresh grant without a refresh token.

  • Mark the client SIGNED_OUT and cancel its timer after constructing the logout URL, before clearing credentials.
  • Prevent new/queued refreshes and timer rescheduling after logout. Explicit token refreshes and organization switches on the signed-out client reject with the existing LoginRequiredError instead of making requests.
  • Ignore late refresh success/failure for session state and callbacks, so an in-flight request cannot restore the client session, trigger sign-in, or restart the timer.

Logout navigation, returnTo handling, and NoSessionError behavior are unchanged. Already-sent network requests are not aborted; their results are ignored by the signed-out client. This does not change initialization on the page loaded after a redirect.

Validation

Using Node 20.20.2 (the CI Node major):

  • Regression tests reproduced the post-logout refresh on the unmodified implementation; the pre-logout refresh control passed.
  • npm test -- --runInBand --runTestsByPath src/create-client.test.ts — 61 passed, including 9 new cases covering both navigation modes, explicit refresh calls, late 200/400/503 responses, and lock acquisition/timeout after logout.
  • npm run build — passed, including declaration generation.
  • npx --no-install prettier --check src/create-client.ts src/create-client.test.ts — passed.
  • git diff --check — passed.

Tests use synthetic sessions, mocked network/navigation, and controlled timers; no live customer session was changed. Full-repository tests are left to CI.

npm ci reported 16 existing dependency audit findings (3 low, 4 moderate, 8 high, 1 critical). Dependencies and the lockfile are unchanged in this PR.

Requested by kathleen.brandt@workos.com in Slack (TARS chain)

@greptile-apps

greptile-apps Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk]

The PR appears safe to merge; no actionable issue was identified.

Summary

The PR makes sign-out terminal for the current client instance, cancels automatic refresh, and ignores refresh results that arrive after sign-out.

  • Adds regression tests for both navigation modes, explicit refresh attempts, in-flight responses, and lock waits.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Authenticated client] -->|signOut| B[Signed out]
  B --> C[Cancel refresh timer and clear session data]
  B --> D[Reject new refresh attempts]
  E[Refresh already in flight] -->|response after sign-out| F[Ignore result and callbacks]
Loading

Reviews (1) · Last reviewed commit: "fix: stop session refresh after sign-out"

@KatBrandt
KatBrandt merged commit 040a8e7 into main Sep 29, 2026
4 checks passed
@KatBrandt
KatBrandt deleted the fix/stop-refresh-after-sign-out branch September 29, 2026 15:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants