Skip to content

fix: fix Web Console hanging when SSO token refresh fails - #603

Open
glasstiger wants to merge 14 commits into
mainfrom
ia_token_refresh_fix
Open

glasstiger wants to merge 14 commits into
mainfrom
ia_token_refresh_fix

Conversation

@glasstiger

@glasstiger glasstiger commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Problem

When OIDC token refresh rejected (for example, because the IdP was unreachable or returned a non-JSON 502 response), the rejection escaped an async setInterval callback. The shared refreshTokenPending flag never cleared, so the Web Console stopped running queries until the page was reloaded. A refresh that never settled could leave it waiting just as long.

Fix

  • Use a single shared in-flight refresh promise. Queries wait on it without polling, and cancelling a query releases that waiter without cancelling the refresh for other queries.
  • Bound the entire refresh (including reading the response body) to 10 seconds. Abort the IdP request on timeout, discard late responses, catch failures, and release non-cancelled waiting queries.
  • Replace the unnecessary in-flight-query drain: requests already capture their headers when they start. A slow SQL query no longer delays refreshing the token or blocks other queries.
  • Keep the current token after a refresh failure. It may still be valid inside the 30-second refresh window. Retry with capped backoff instead of posting to the IdP on every query; reset backoff on success or a new login. While the old token is still valid, queries may succeed; a 401 follows only when it expires or is revoked.
  • Notify the user on refresh failure and show an explanatory login error if the session subsequently expires. Count only the first 401 from a burst of in-flight queries after logout, preserving the saved SSO shortcut and silent re-authentication. Repeated failures across separate login attempts still trigger the redirect-loop guard.

Testing

  • Unit tests cover successful header updates while another query is in flight, header preservation on failure, shared concurrent waiters, cancelling a waiter, retry backoff, session reset, hung refresh timeout, late responses, OAuth error bodies, and 401-burst handling.
  • Enterprise OIDC E2E cases added for both a refresh network error and a non-JSON 502 during login. These require an EE QuestDB/OIDC test environment and were not run locally.
  • Local typecheck, lint, full unit suite, and production build pass.

When an OIDC token refresh failed at the transport level (token endpoint
unreachable, or a non-JSON response body), refreshTokenMethod() rejected
inside the setInterval callback of refreshAuthToken(), before the static
refreshTokenPending flag was reset. The flag was left stuck true, the outer
promise never settled, and every subsequent query deadlocked waiting on it —
the console silently froze with no 401 and no logout.

Wrap the refresh in try/catch/finally so refreshTokenPending is always reset.
On failure the stale token is kept in place and the next request receives a
401, which drives the existing re-auth flow — matching the behaviour when
there is no refresh token at all.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@glasstiger glasstiger added bug Something isn't working web-console Issues relevant to "web-console" package labels Aug 25, 2026
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Web Console deploy preview

Preview Commit Logs
https://pr-603--web-console.netlify.app c24e68e build log

@glasstiger glasstiger changed the title fix: prevent auth token refresh failure from deadlocking the client fix: keep Web Console responsive when SSO token refresh fails Sep 28, 2026
Comment thread e2e/tests/enterprise/oidc.spec.js Outdated
Comment thread e2e/tests/enterprise/oidc.spec.js Outdated
Comment thread e2e/tests/enterprise/oidc.spec.js Outdated
The OIDC refresh-failure E2E test reuses the fake token fixtures used throughout oidc.spec.js. Ignore the findings in 0f4d4ac and mark the lines with gitleaks:allow so the squash commit on main is not flagged either.
@glasstiger glasstiger changed the title fix: keep Web Console responsive when SSO token refresh fails fix: fix Web Console hanging when SSO token refresh fails Sep 29, 2026
The legacy grid mounts only after the first result arrives, so asserting
.qg-viewport right after reloading with useNewGrid=0 always timed out.
Assert it after the first query instead.

Also release the old query's page before the new result loads that page.
The previous scroll away and back could refetch the page, hiding the stale
write, so the test only sometimes failed without the generation guard.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working security web-console Issues relevant to "web-console" package

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant