Files
descrybe/apps/api
greeneclipseandClaude Fable 5 6facfbb0aa Self-heal duplicate session cookies from the Domain rollout
Browsers that logged in before the session cookie became Domain-scoped
still hold the old host-only descrybe_session for api.descrybe.io. They
then send BOTH cookies — older (stale) first — and Go reads the first
match, so the stale relic shadows the fresh Domain cookie and every
request 401s even immediately after a successful login. Clearing
browser cookies fixed it manually; users should never have to.

New DedupeSessionCookies middleware (mounted before scs LoadAndSave):
when duplicate session cookies arrive, pick the token that resolves in
the session store, rewrite the Cookie header to just that one, expire
the host-only relic (Set-Cookie without Domain only touches the
host-only variant), and re-issue the surviving token on the canonical
Domain cookie. One request converges the browser to a single cookie.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-18 01:19:46 +02:00
..
fix
2026-08-17 00:40:46 +02:00
fix
2026-08-14 01:38:34 +02:00
fix
2026-08-14 01:38:34 +02:00
2026-08-10 02:04:45 +02:00
fix
2026-08-14 01:38:34 +02:00