Repository navigation
feat(auth): reuse the auth session's device id at finalize (campus#825) - #96
Merged
Merged
Conversation
campus.auth now observes a stable campus_device cookie at /authorize and records the id on the auth session. finalize() copies that id onto the login session it creates instead of always minting a fresh one, so re-logins from the same browser profile land on the same device id and audit spans attribute to the device, not just the user. The minted fallback keeps non-cookie flows and pre-#825 auth services working. Lock bump: campus-suite -> 14fc6a9 (AuthSession.device_id). Refs nyjc-computing/campus#825
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements the SDK half of the stable-device design accepted in nyjc-computing/campus#825 (design comment).
What changes
finalize()reuses the auth session'sdevice_idwhen campus.auth observed one (the stablecampus_devicecookie, recorded on the auth session by campus#832), instead of always minting a fresh per-login id. Re-logins from the same browser profile therefore land on the same device id, and the login sessions they create — whosedevice_idthe tracing middleware stamps onto spans — attribute to a device, not just a user.campus-suite→ 14fc6a9 (addsAuthSession.device_id; campus PR #832).Test plan
tests/unit/test_finalize_device_id.py: session device id rides through unchanged; absent → minteduid-device-*; both paths produce the same id shape (mock-driven, exercises the realcampus.model.AuthSession.from_resourcepath).auth/v1/__init__.pyis pre-existing on main).Ref nyjc-computing/campus#825