merged develop
This commit is contained in:
@@ -105,17 +105,29 @@ class MarianumConnectAuthInterceptor extends Interceptor {
|
||||
Future<bool> _performReLogin() async {
|
||||
final session = SessionManager().current;
|
||||
if (session is! CredentialSession) return false;
|
||||
final username = session.username;
|
||||
// A background engine (widget task) keeps the account it loaded. When
|
||||
// the app signed that account out, its revoked token answers 401 — a
|
||||
// re-login would mint a fresh token for it into the shared keystore.
|
||||
if (await SessionManager().readStoredUsername() != username) return false;
|
||||
try {
|
||||
await _loginClient.run(
|
||||
username: session.username,
|
||||
username: username,
|
||||
password: session.password,
|
||||
tokenName: await DeviceTokenName.resolve(),
|
||||
);
|
||||
return true;
|
||||
} catch (_) {
|
||||
await _tokenStorage.clear();
|
||||
if (await SessionManager().readStoredUsername() == username) {
|
||||
await _tokenStorage.clear();
|
||||
}
|
||||
return false;
|
||||
}
|
||||
final stored = await SessionManager().readStoredUsername();
|
||||
if (stored == username) return true;
|
||||
// Signed out during the login: drop the orphaned token, unless another
|
||||
// account already stored its own.
|
||||
if (stored == null) await _tokenStorage.clear();
|
||||
return false;
|
||||
}
|
||||
|
||||
Future<Response<dynamic>> _retryWithFreshToken(
|
||||
|
||||
@@ -19,6 +19,7 @@ class SessionValidator {
|
||||
// The probes use their own dio (bypassing the demo interceptor), so a demo
|
||||
// session must be skipped or its missing token would 401 into a logout.
|
||||
if (session == null || session.isDemo) return;
|
||||
final epoch = SessionManager().sessionEpoch;
|
||||
try {
|
||||
switch (session) {
|
||||
case CredentialSession(:final username, :final password):
|
||||
@@ -28,6 +29,9 @@ class SessionValidator {
|
||||
}
|
||||
} on AuthException catch (e) {
|
||||
if (e.statusCode != 401) return;
|
||||
// The probed account is no longer the active one; the 401 must not
|
||||
// sign out whoever took over meanwhile.
|
||||
if (!SessionManager().isCurrentSession(epoch)) return;
|
||||
log('MC: stored session rejected — forcing re-login');
|
||||
final next = await SessionLifecycle.signOut(
|
||||
notice: switch (session) {
|
||||
|
||||
Reference in New Issue
Block a user