Skip to content

Conversation

@ybnd
Copy link
Member

@ybnd ybnd commented Aug 28, 2025

References

Add references/links to any related issues or PRs. These may include:

Description

This PR ensures that authentication methods are retrieved when the current authentication cookie hasn't expired yet, but is invalid for other reasons (such as Tomcat having restarted)

  • The AuthenticatedAction fired when a token appears valid is marked with checkAgain: true
  • If the authentication status indicates that we aren't authenticated, we'll now fire a CheckAuthenticationTokenCookieAction
  • When we fire AuthenticatedAction after parsing an authentication response, we mark it with checkAgain: false to make sure that we don't keep re-checking the cookie forever

Instructions for Reviewers

Confirm that the bug described in the linked issue can no longer be replicated.

Confirm that the following scenarios are still handled correctly:

  • Opening the app without authenticating (no cookie)
  • Logging in (with password, Shibboleth, ...)
  • Refreshing while authenticated
  • Logging out
  • Getting logged out when the authentication token expires

Checklist

This checklist provides a reminder of what we are going to look for when reviewing your PR. You do not need to complete this checklist prior creating your PR (draft PRs are always welcome).
However, reviewers may request that you complete any actions in this list if you have not done so. If you are unsure about an item in the checklist, don't hesitate to ask. We're here to help!

  • My PR is created against the main branch of code (unless it is a backport or is fixing an issue specific to an older branch).
  • My PR is small in size (e.g. less than 1,000 lines of code, not including comments & specs/tests), or I have provided reasons as to why that's not possible.
  • My PR passes ESLint validation using npm run lint
  • My PR doesn't introduce circular dependencies (verified via npm run check-circ-deps)
  • My PR includes TypeDoc comments for all new (or modified) public methods and classes. It also includes TypeDoc for large or complex private methods.
  • My PR passes all specs/tests and includes new/updated specs or tests based on the Code Testing Guide.
  • My PR aligns with Accessibility guidelines if it makes changes to the user interface.
  • My PR uses i18n (internationalization) keys instead of hardcoded English text, to allow for translations.
  • My PR includes details on how to test it. I've provided clear instructions to reviewers on how to successfully test this fix or feature.
  • If my PR includes new libraries/dependencies (in package.json), I've made sure their licenses align with the DSpace BSD License based on the Licensing of Contributions documentation.
  • If my PR includes new features or configurations, I've provided basic technical documentation in the PR itself.
  • If my PR fixes an issue ticket, I've linked them together.

ybnd added 2 commits August 28, 2025 15:39
@ybnd ybnd changed the title Fix auth method retrieval after Tomcat restart Fix authentication method retrieval after Tomcat restart Aug 28, 2025
@ybnd ybnd marked this pull request as ready for review October 16, 2025 07:39
@toniprieto
Copy link
Contributor

Thanks, @ybnd ! I've been using this change on a dev instance and it fixes the linked issue. Very helpful! I've run the basic tests with password authentication and haven't detected any problems.

@tdonohue I noticed that the PR isn’t added to any board

@tdonohue tdonohue added bug 1 APPROVAL pull request only requires a single approval to merge labels Nov 25, 2025
@tdonohue tdonohue moved this to 🙋 Needs Reviewers Assigned in DSpace 10.0 Release Nov 25, 2025
@tdonohue tdonohue moved this from 🙋 Needs Reviewers Assigned to 👍 Reviewer Approved in DSpace 10.0 Release Nov 25, 2025
@tdonohue
Copy link
Member

Temporarily closing & reopening to trigger an updated test run. Apologies for the delay in getting to this, but I'm hoping to get it merged soon,

@tdonohue tdonohue closed this Jan 14, 2026
@github-project-automation github-project-automation bot moved this from 👍 Reviewer Approved to ✅ Done in DSpace 10.0 Release Jan 14, 2026
@tdonohue tdonohue reopened this Jan 14, 2026
@tdonohue tdonohue moved this from ✅ Done to 👍 Reviewer Approved in DSpace 10.0 Release Jan 14, 2026
@tdonohue tdonohue added this to the 10.0 milestone Jan 16, 2026
@tdonohue tdonohue added port to dspace-9_x This PR needs to be ported to `dspace-9_x` branch for next bug-fix release port to dspace-8_x This PR needs to be ported to `dspace-8_x` branch for next bug-fix release labels Jan 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 APPROVAL pull request only requires a single approval to merge bug port to dspace-8_x This PR needs to be ported to `dspace-8_x` branch for next bug-fix release port to dspace-9_x This PR needs to be ported to `dspace-9_x` branch for next bug-fix release

Projects

Status: 👍 Reviewer Approved

Development

Successfully merging this pull request may close these issues.

Authentication check can't deal with a token that is invalid but not expired

3 participants