promote: daily cookie-session keep-alive (refresh every 24h, for cookie auth) - #106
Merged
Merged
Conversation
… cookie auth) Cookie-auth accounts have no OAuth refresh token to exchange, so a literal token-refresh job has nothing to call. The cookie equivalent: once a day reload each active cookie account with its stored cookies and re-save the rotated (sliding-expiry) cookies the site issues, which extends the session and staves off premature token_expired. Also proactively flags a session that HAS died so the user is prompted to reconnect before a scheduled post fails. - migration: sp_account.session_refreshed_at (gates the 24h cadence across worker restarts + surfaces "last kept alive" in the UI) - lib/sp/platforms/browser.ts: refreshCookieSession() — loads the home URL, checks login, returns the context's refreshed cookies - lib/sp/sessionRefresh.ts: refreshCookieSessions() sweep — per-platform home URLs, re-encrypts refreshed cookies, flags dead sessions token_expired; never flags on a transient/navigation error - worker/index.ts: run at startup + every 24h (23h per-account gate) - promote/accounts: shows "Session kept alive <time>" for active accounts Limitation: this PREVENTS decay of live sessions and warns early — it cannot revive an already-dead session (that still needs a fresh cookie export). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The ask & the reality
"Refresh tokens every 24h." Your social accounts are all
auth_mode: cookiewith no refresh token — a cookie isn't an OAuth token, so there's nothing to exchange on a schedule. The cookie-auth equivalent of a token refresh is a session keep-alive: reload the site with the current cookies and re-save whatever (rotated, sliding-expiry) cookies it hands back. That extends the session and delaystoken_expired.What it does
A worker sweep, at startup + every 24h:
enc_access_token) and stampsession_refreshed_at;token_expiredso the UI prompts a reconnect before a scheduled post fails.token_expired(a blip won't nuke a live session).Changes
sp_account.session_refreshed_at(applied to prod already)lib/sp/platforms/browser.ts—refreshCookieSession()reusinglaunchContext/assertLoggedInlib/sp/sessionRefresh.ts— the sweep (per-platform home URLs, re-encrypt, flag dead)worker/index.ts— schedule (startup + 24h)/promote/accounts— shows "Session kept alive "Honest limitation
This prevents live sessions from decaying and warns early when one dies. It cannot revive an already-dead session — that still needs a fresh cookie export (e.g. your current linkedin/x). Best results come from having warm cookies to begin with.
Verified
tsc(app + worker) clean ·next buildcompiles/promote/accounts. (Live cookie-extension behavior varies per platform and can only be confirmed running against real sessions.)🤖 Generated with Claude Code