Loyal-Young opened a new issue, #5361: URL: https://github.com/apache/rocketmq-dashboard/issues/5361
### Summary The `AuthGate` checks `/auth/status` only when it mounts or when the user clicks Retry. Browser tabs share the session cookie and the persisted identity keys, but the gate never listens for identity changes in another tab. After signing out in tab A, tab B keeps its protected page and previously loaded account data on screen until a new API call happens to return 401 or the page reloads. Signing in as another account in tab A also leaves tab B showing the prior account's page state. ### Reproduction 1. Sign in and open Studio in two tabs. 2. Sign out in tab A. 3. Return to tab B without refreshing it. The protected page remains visible and `AuthGate` makes no new status request. `AuthGate` in `web/src/App.tsx` handles the initial status request, but has no `storage` event listener. `authStore.logout()` removes `rocketmq-studio-user`; browser storage changes in another tab are observable through that event. ### Expected behavior When another tab changes the persisted identity, immediately hide the protected route and recheck the server session. Restore the page only if the server confirms the current account; otherwise go to login. A status-check error should continue to fail closed. ### Scope Revalidate the gate on cross-tab identity changes and add a deterministic regression test. The server remains the authority for authentication; this does not change session or cookie semantics. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
