Loyal-Young opened a new issue, #5361:
URL: https://github.com/apache/rocketmq-dashboard/issues/5361

   ### Summary
   
   The `AuthGate` checks `/auth/status` only when it mounts or when the user 
clicks Retry. Browser tabs share the session cookie and the persisted identity 
keys, but the gate never listens for identity changes in another tab. After 
signing out in tab A, tab B keeps its protected page and previously loaded 
account data on screen until a new API call happens to return 401 or the page 
reloads. Signing in as another account in tab A also leaves tab B showing the 
prior account's page state.
   
   ### Reproduction
   
   1. Sign in and open Studio in two tabs.
   2. Sign out in tab A.
   3. Return to tab B without refreshing it. The protected page remains visible 
and `AuthGate` makes no new status request.
   
   `AuthGate` in `web/src/App.tsx` handles the initial status request, but has 
no `storage` event listener. `authStore.logout()` removes 
`rocketmq-studio-user`; browser storage changes in another tab are observable 
through that event.
   
   ### Expected behavior
   
   When another tab changes the persisted identity, immediately hide the 
protected route and recheck the server session. Restore the page only if the 
server confirms the current account; otherwise go to login. A status-check 
error should continue to fail closed.
   
   ### Scope
   
   Revalidate the gate on cross-tab identity changes and add a deterministic 
regression test. The server remains the authority for authentication; this does 
not change session or cookie semantics.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to