Recover expired Access sign-in while preserving open work - #719
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merge decision: ready — interrupted Access sign-in now has a normal sign-in route while the original tab retains its conversation, unsent text and attachments; proportionate tests show recovery without replaying a message.
User outcome
A lapsed Cloudflare Access session can make browser fetches fail even while Von is healthy. The recovery view now explains that sign-in, network or server problems may be responsible and offers Sign in again in a new tab. After sign-in, returning to the original tab rechecks the connection and retries failed conversation reads without reloading the composer.
Native task:
#V#task_agent_7e1403047bb7730408a837def239f77d.Material changes
TypeErrorremains uncertain.noopener noreferrerto both the open-page recovery view and cached offline shell. Keep all open work in the original tab.Evidence
tests/browser/outageComponents.cjspassed with production outage components and a disposable cross-origin HTTP/cookie fixture. The baseline fetch raisedTypeError; the candidate observedopaqueredirect. New-tab sign-in restored conversation access with text, attachment and selection retained. The cached offline shell also recovered after sign-in. Healthy, HTTP 503, device-offline, transient failure and active-thinking paths passed; zero non-GET requests..run/access-recovery/for the controller's execution archive.main.js;git diff --checkpassed.Ship boundary
Minimum ship evidence is satisfied for this bounded frontend recovery path. Lost drafts, replaced conversation selection, automatic message replay, false certainty about session expiry, or broken genuine-outage recovery would block merge.
The browser replay is a local fixture, not a real Cloudflare/Google OAuth session, full authenticated Von backend or physical-phone test. Production conversation-read recovery is separately covered by Jest. No model prompts were submitted. The assignment expressly permits nearest-faithful evidence when a real edge replay is unavailable.
No Cloudflare policy, credentials, database routing, backend authentication or infrastructure changes. This task authorises publication and merge but does not request deployment; live activation remains separate.