Repository navigation
Conversation
setAuthHandlers registers optional replacements: initLogOut for the IDP
end-session redirect, authErrorHandler for the 401 login / 403 logout
paths. The two keys are independent, and without handlers uicore keeps
its built-in behavior.
The handlers live on globalThis under
Symbol.for('openstack-uicore-foundation.authHandlers'), so every copy of
the module shares them.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Direct globalThis usage can break logout in environments already accommodated by the existing global fallback.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds injectable logout and authentication-error handlers while preserving default behavior.
Changes:
- Adds globally shared
setAuthHandlersandgetAuthHandlersAPIs. - Delegates logout and 401/403 handling to injected callbacks.
- Adds tests for injected and default behavior.
| File | Description |
|---|---|
src/components/security/methods.js |
Implements handler registration and logout delegation. |
src/utils/actions.js |
Delegates 401/403 errors to the injected handler. |
src/components/security/__tests__/methods.test.js |
Tests registration, sharing, clearing, and logout behavior. |
src/utils/__tests__/actions.test.js |
Tests injected authentication-error handling. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
setAuthHandlers and readAuthHandlers used bare globalThis. They now use
the _global fallback (globalThis → window → {}) that the resolver already
uses, so initLogOut keeps its built-in redirect on a runtime without
globalThis.

ref: https://app.clickup.com/t/86bbnquuq
uicore's built-in auth redirects on logout and on 401/403:
initLogOutdoes alocation.replaceto the IDP end-session URL built from window globals, and the 401/403 path runs uicore's own login/logout redirects. A cookie-based / SSR host needs to run its own server-side logout and surface auth errors its own way instead.setAuthHandlerslets a consumer inject both —initLogOut(where logout goes) and the 401/403 handler;getAuthHandlersreads them back. When handlers are registered uicore delegates to them; otherwise the built-in flow is unchanged. Same opt-in shape assetAccessTokenResolver(#324). CoverssetLogoutHandler+setAuthErrorHandlerfrom the task.