Skip to content

feat(auth): let a consumer replace initLogOut and the 401/403 handling - #350

Open
gcutrini wants to merge 2 commits into
v4.xfrom
feat/auth-handlers-v4
Open

gcutrini wants to merge 2 commits into
v4.xfrom
feat/auth-handlers-v4

Conversation

@gcutrini

@gcutrini gcutrini commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

ref: https://app.clickup.com/t/86bbnquuq

uicore's built-in auth redirects on logout and on 401/403: initLogOut does a location.replace to the IDP end-session URL built from window globals, and the 401/403 path runs uicore's own login/logout redirects. A cookie-based / SSR host needs to run its own server-side logout and surface auth errors its own way instead.

setAuthHandlers lets a consumer inject both — initLogOut (where logout goes) and the 401/403 handler; getAuthHandlers reads them back. When handlers are registered uicore delegates to them; otherwise the built-in flow is unchanged. Same opt-in shape as setAccessTokenResolver (#324). Covers setLogoutHandler + setAuthErrorHandler from the task.

setAuthHandlers registers optional replacements: initLogOut for the IDP
end-session redirect, authErrorHandler for the 401 login / 403 logout
paths. The two keys are independent, and without handlers uicore keeps
its built-in behavior.

The handlers live on globalThis under
Symbol.for('openstack-uicore-foundation.authHandlers'), so every copy of
the module shares them.
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 197ffade-3d55-45f3-9da4-a4bc1ea99e5f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Direct globalThis usage can break logout in environments already accommodated by the existing global fallback.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds injectable logout and authentication-error handlers while preserving default behavior.

Changes:

  • Adds globally shared setAuthHandlers and getAuthHandlers APIs.
  • Delegates logout and 401/403 handling to injected callbacks.
  • Adds tests for injected and default behavior.
File Description
src/​components/​security/​methods.js Implements handler registration and logout delegation.
src/​utils/​actions.js Delegates 401/403 errors to the injected handler.
src/​components/​security/​__tests__/​methods.test.js Tests registration, sharing, clearing, and logout behavior.
src/​utils/​__tests__/​actions.test.js Tests injected authentication-error handling.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/components/security/methods.js Outdated
setAuthHandlers and readAuthHandlers used bare globalThis. They now use
the _global fallback (globalThis → window → {}) that the resolver already
uses, so initLogOut keeps its built-in redirect on a runtime without
globalThis.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants