Skip to content

fix(marketplace): owned-only purchase session clear - #146

Merged
BitcoinErrorLog merged 5 commits into
release/shop-v0.6.8from
cursor/purchase-session-owned-clear-28b3
Sep 28, 2026
Merged

BitcoinErrorLog merged 5 commits into
release/shop-v0.6.8from
cursor/purchase-session-owned-clear-28b3

Conversation

@BitcoinErrorLog

Copy link
Copy Markdown
Owner

Summary

When the in-memory purchase bearer reached its expiry margin, clearing the marketplace session removed whatever record was in localStorage (shared across tabs), including a newer still-valid bearer another tab had persisted, and unpaired the BFF bridge through the shared cookie.

This change clears or overwrites the persisted purchase session only when the caller owns that exact record (bearer or session id). Sign-out and account switch still wipe unconditionally.

  • MarketplaceSessionService: owned-only clearSession, clearSessionIfBearer, conditional writePersistedSession, scoped BFF unpair via ?session_id=.
  • Callers updated for 401 / wrong-pubky / inventory revoke paths.

Review: Sol and Kimi SHIP (see purchase-session-owned-clear/).

Head 7b1b93cb.

localStorage and the BFF cookie are shared across tabs. When this tab's
in-memory bearer reached its expiry margin, clearSession removed whatever
record was persisted, including a newer bearer another tab had just saved,
and unpaired the BFF session that tab had paired.

- clearSession removes the persisted record only while it still carries the
  in-memory bearer, asks the BFF to unpair only that session id, and with
  nothing in memory removes nothing.
- 401s and a session minted for another pubky clear through
  clearSessionIfBearer, so a newer session adopted while the request was in
  flight survives.
- restorePersistedSession expires memory before reading the slot and removes
  only the exact record it read.
- writePersistedSession does not overwrite a different bearer that expires
  later.
- Sign-out and account switch use clearForSignOut, the one path that removes
  a record it did not write.

Regressions drive the real service with the staging parity grant, including
expiry in one tab while another tab's newer bearer is in storage.
…sion a tab owns

DELETE /api/marketplace/session unpaired whatever bridge the shared cookie
named, so one tab's expiry unpaired a newer session another tab had paired.
A session_id query now deletes the bridge only while it pairs that session
and keeps the cookie otherwise; a malformed id is refused. Without a
session_id (sign-out) the bridge is removed as before.
@BitcoinErrorLog
BitcoinErrorLog merged commit 7f0258c into release/shop-v0.6.8 Sep 28, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant