fix: fix Web Console hanging when SSO token refresh fails - #603
Open
glasstiger wants to merge 14 commits into
Open
glasstiger wants to merge 14 commits into
glasstiger wants to merge 14 commits into
Conversation
When an OIDC token refresh failed at the transport level (token endpoint unreachable, or a non-JSON response body), refreshTokenMethod() rejected inside the setInterval callback of refreshAuthToken(), before the static refreshTokenPending flag was reset. The flag was left stuck true, the outer promise never settled, and every subsequent query deadlocked waiting on it — the console silently froze with no 401 and no logout. Wrap the refresh in try/catch/finally so refreshTokenPending is always reset. On failure the stale token is kept in place and the next request receives a 401, which drives the existing re-auth flow — matching the behaviour when there is no refresh token at all. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
# Conflicts: # src/utils/questdb/client.test.ts
Web Console deploy preview
|
The OIDC refresh-failure E2E test reuses the fake token fixtures used throughout oidc.spec.js. Ignore the findings in 0f4d4ac and mark the lines with gitleaks:allow so the squash commit on main is not flagged either.
The legacy grid mounts only after the first result arrives, so asserting .qg-viewport right after reloading with useNewGrid=0 always timed out. Assert it after the first query instead. Also release the old query's page before the new result loads that page. The previous scroll away and back could refetch the page, hiding the stale write, so the test only sometimes failed without the generation guard.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
When OIDC token refresh rejected (for example, because the IdP was unreachable or returned a non-JSON 502 response), the rejection escaped an async
setIntervalcallback. The sharedrefreshTokenPendingflag never cleared, so the Web Console stopped running queries until the page was reloaded. A refresh that never settled could leave it waiting just as long.Fix
Testing