Skip to content

Fix/auth retry stale cookies - #2351

Merged
hyperxpro merged 2 commits into
mainfrom
fix/auth-retry-stale-cookies
Sep 23, 2026
Merged

hyperxpro merged 2 commits into
mainfrom
fix/auth-retry-stale-cookies

Conversation

@hyperxpro

Copy link
Copy Markdown
Member

Motivation:

When a 401 or 407 response set or rotated a cookie, the authenticated retry still sent the old cookies. The server then saw a stale session on the request that carried the credentials.

Modification:

Refresh the retry's cookies from the store after the challenge, using the same keep-the-caller's-own rule as redirects. That logic moves into a shared package-private CallerCookies class.

Result:

The retry sends the cookies the challenge response set.

@hyperxpro
hyperxpro merged commit faccbab into main Sep 23, 2026
17 checks passed
@hyperxpro
hyperxpro deleted the fix/auth-retry-stale-cookies branch September 23, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant