Repository navigation
feat(providers): derive + surface expiry for JWT-bearing web cookies (#11497) - #11505
Merged
diegosouzapw merged 1 commit intoAug 25, 2026
Merged
diegosouzapw merged 1 commit into
diegosouzapw merged 1 commit into
Conversation
…iegosouzapw#11497) Cookies that embed a standard JWT (ChatGPT __Secure-next-auth.session-token, Qwen/Z.ai localStorage tokens) now get their exp persisted as providerSpecificData.cookieExpiresAt at the connection save chokepoint — recomputed on every write so re-pasting refreshes it and an opaque replacement drops the stale date. Dashboard: ConnectionRow and the Limits-page QuotaCardHeader feed the new field into the existing token-expiry countdown badges; opaque cookies (claude sessionKey, grok sso) stay undated — no false precision.
oyi77
force-pushed
the
feat/webcookie-expiry-preview
branch
from
August 25, 2026 11:28
a196bcd to
9513031
Compare
Contributor
Author
|
CI triage for the current red batch (Docs Gates / unit shards / Vitest / ESLint-suppressions): reproduced at today's merge ref ( This branch's own receipts stay green: |
diegosouzapw
merged commit Aug 25, 2026
026d26e
into
diegosouzapw:release/v3.8.51
7 of 16 checks passed
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…iegosouzapw#11497) (diegosouzapw#11505) Validated in a combined 3-PR batch worktree off release/v3.8.51 tip (a sibling PR from the same author, diegosouzapw#11495, was held out — see its own comment for the isolated finding, unrelated to this diff). - Focused test: web-cookie-expiry.test.ts — part of batch's 94/94 node:test run - typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK - Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff Thanks for closing a real trust gap — operators deserve to know a cookie is about to expire before a live request fails.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #11497.
What
Web-cookie rows had no expiry signal even when the pasted credential embeds a standard JWT with an
expclaim (ChatGPT__Secure-next-auth.session-token, Qwen/Z.ai localStorage tokens). Operators got their first indication of expiry from a live request failing.src/shared/utils/webCookieExpiry.ts:decodeJwtPayloadExp— strict JWT-shaped decode (3 dot segments, base64url, JSON-object payload, positive numericexp), size-capped;deriveCookieExpiryIso— scans the whole credential then each cookie-pair value;withDerivedCookieExpiry— merge helper that RECOMPUTES on every save: re-pasting refreshes the date, an opaque replacement cookie drops the stale date instead of leaving a lie on the row.normalizeConnectionProviderSpecificDatainsrc/lib/db/providers.ts(same place the Codex fingerprint seed is applied) — covers create/edit/import/health-stamp writes for cataloguedWEB_COOKIE_PROVIDERSonly.ConnectionRowand the Limits-pageQuotaCardHeaderfeedproviderSpecificData.cookieExpiresAtinto the existing token-expiry countdown badges. Opaque cookies (claudesessionKey, groksso) stay undated — no false precision.No network calls, no schema migration (
providerSpecificDatais free-form JSON).Verification
tests/unit/web-cookie-expiry.test.ts: 9/9 pass — valid decode, url-safe/unpadded base64, cookie-header pair scan, opaque → null, malformed/non-positive/array/primitive payloads, reader guards, set/preserve-siblings, stale-drop-on-opaque-replacement, no-credential passthrough.db-provider-cookie-dedup-3368+db-provider-limitssuites 17/17 combined pass after the chokepoint change.npx tsc --noEmit -p tsconfig.json: zero diagnostics in the five touched files.src/lib/db/providers.tsare byte-identical on the pristine base commit (verified via stash diff) and untouched here.npm run check:file-size: OK.Changed files
src/shared/utils/webCookieExpiry.ts(new)src/lib/db/providers.ts(+40 wiring lines at the normalization chokepoint)src/app/(dashboard)/dashboard/providers/[id]/components/ConnectionRow.tsx(+8)src/app/(dashboard)/dashboard/usage/components/ProviderLimits/parts/QuotaCardHeader.tsx(+4)tests/unit/web-cookie-expiry.test.ts(new)