fix(marketplace): owned-only purchase session clear - #146
Merged
BitcoinErrorLog merged 5 commits intoSep 28, 2026
Merged
BitcoinErrorLog merged 5 commits into
BitcoinErrorLog merged 5 commits into
Conversation
localStorage and the BFF cookie are shared across tabs. When this tab's in-memory bearer reached its expiry margin, clearSession removed whatever record was persisted, including a newer bearer another tab had just saved, and unpaired the BFF session that tab had paired. - clearSession removes the persisted record only while it still carries the in-memory bearer, asks the BFF to unpair only that session id, and with nothing in memory removes nothing. - 401s and a session minted for another pubky clear through clearSessionIfBearer, so a newer session adopted while the request was in flight survives. - restorePersistedSession expires memory before reading the slot and removes only the exact record it read. - writePersistedSession does not overwrite a different bearer that expires later. - Sign-out and account switch use clearForSignOut, the one path that removes a record it did not write. Regressions drive the real service with the staging parity grant, including expiry in one tab while another tab's newer bearer is in storage.
…sion a tab owns DELETE /api/marketplace/session unpaired whatever bridge the shared cookie named, so one tab's expiry unpaired a newer session another tab had paired. A session_id query now deletes the bridge only while it pairs that session and keeps the cookie otherwise; a malformed id is refused. Without a session_id (sign-out) the bridge is removed as before.
…s are owner-scoped
…her tab's purchase bearer
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
When the in-memory purchase bearer reached its expiry margin, clearing the marketplace session removed whatever record was in
localStorage(shared across tabs), including a newer still-valid bearer another tab had persisted, and unpaired the BFF bridge through the shared cookie.This change clears or overwrites the persisted purchase session only when the caller owns that exact record (bearer or session id). Sign-out and account switch still wipe unconditionally.
MarketplaceSessionService: owned-onlyclearSession,clearSessionIfBearer, conditionalwritePersistedSession, scoped BFF unpair via?session_id=.Review: Sol and Kimi SHIP (see purchase-session-owned-clear/).
Head
7b1b93cb.