Detect expired sessions + reconnect flow; collapse outreach history - #67
Merged
Merged
Conversation
Two social-posting UX fixes. 1. Session-expired detection & reconnect. After navigating with cookies (and clearing any code challenge), the worker checks for a login wall (login URL or visible password field) and throws a recognizable SESSION_EXPIRED error. browserPost flags the account status='token_expired' so it stops posting to a dead session and the setup page shows a "⚠ Session expired" prompt with a per-platform login link — log in, re-export cookies via Cookie-Editor, paste to reconnect (connectViaCookies already upserts status='active'). Replaces the opaque composer-timeout with an actionable message. 2. Collapse outreach history. The /recent history now shows one row per channel+provider (the latest attempt) instead of piling up every send/retry, so it updates in place (with the live refresh + retry already in place). Also broadens the Mastodon publish-button selector (it reached compose but missed the submit control). Note: reuses the existing sp_account.status 'token_expired' value — no migration. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to the browser-posting work, driven by the latest failures (all browser platforms timing out at the composer). Root cause for many of them: the cookie session is dead, so the platform serves a login wall and the composer never renders — an opaque
locator.waitFortimeout.1. Session-expired detection + reconnect (chosen: Reconnect + Cookie-Editor)
assertLoggedInchecks for a login wall (login URL or visible password field) and throws a recognizableSESSION_EXPIRED:error instead of letting the composer selector time out.browserPost— on that error, flags the accountstatus='token_expired', so it stops posting to a dead session (posting/retry queries already requireactive).token_expiredaccount now shows ⚠ Session expired with a per-platform Log in ↗ link and instructions to re-export cookies via Cookie-Editor and paste them to reconnect.connectViaCookiesalready upsertsstatus='active', so re-pasting reactivates it.httpOnly; page JS/bookmarklets can't read them — only the Cookie-Editor extension can. So reconnect reuses that extension (your call from the options).No migration — reuses the existing
sp_account.statustoken_expiredvalue.2. Collapse the outreach history
/recentnow shows one row per channel+provider (the latest attempt) instead of appending every send/retry. Combined with the live-refresh + retry already shipped, a platform's row updates in place rather than polluting the list.3. Mastodon publish selector
It reached the composer and filled text but missed the submit control; broadened the publish-button selector (
Publish!/Toot!+ compose-form submit fallback).Verification
tsc --noEmitclean;tests/sp/*35/35token_expired(no login wall) — that's the residual stale-selector case, which needs the real authenticated DOM to fix precisely.🤖 Generated with Claude Code