Skip to content

Detect expired sessions + reconnect flow; collapse outreach history - #67

Merged
ralyodio merged 1 commit into
masterfrom
browser-post-login-detect
Jul 4, 2026
Merged

ralyodio merged 1 commit into
masterfrom
browser-post-login-detect

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 4, 2026

Copy link
Copy Markdown
Contributor

Follow-up to the browser-posting work, driven by the latest failures (all browser platforms timing out at the composer). Root cause for many of them: the cookie session is dead, so the platform serves a login wall and the composer never renders — an opaque locator.waitFor timeout.

1. Session-expired detection + reconnect (chosen: Reconnect + Cookie-Editor)

  • Worker — after navigating with cookies (and clearing any code challenge), assertLoggedIn checks for a login wall (login URL or visible password field) and throws a recognizable SESSION_EXPIRED: error instead of letting the composer selector time out.
  • browserPost — on that error, flags the account status='token_expired', so it stops posting to a dead session (posting/retry queries already require active).
  • Setup page — a token_expired account now shows ⚠ Session expired with a per-platform Log in ↗ link and instructions to re-export cookies via Cookie-Editor and paste them to reconnect. connectViaCookies already upserts status='active', so re-pasting reactivates it.
  • Why not a "copy cookie" button: platform session cookies are httpOnly; page JS/bookmarklets can't read them — only the Cookie-Editor extension can. So reconnect reuses that extension (your call from the options).

No migration — reuses the existing sp_account.status token_expired value.

2. Collapse the outreach history

/recent now shows one row per channel+provider (the latest attempt) instead of appending every send/retry. Combined with the live-refresh + retry already shipped, a platform's row updates in place rather than polluting the list.

3. Mastodon publish selector

It reached the composer and filled text but missed the submit control; broadened the publish-button selector (Publish!/Toot! + compose-form submit fallback).

Verification

  • tsc --noEmit clean; tests/sp/* 35/35
  • Login detection / selectors are best-effort vs live DOM. If a platform is actually logged in but still times out, the account won't flip to token_expired (no login wall) — that's the residual stale-selector case, which needs the real authenticated DOM to fix precisely.

🤖 Generated with Claude Code

Two social-posting UX fixes.

1. Session-expired detection & reconnect. After navigating with cookies (and
   clearing any code challenge), the worker checks for a login wall (login URL
   or visible password field) and throws a recognizable SESSION_EXPIRED error.
   browserPost flags the account status='token_expired' so it stops posting to
   a dead session and the setup page shows a "⚠ Session expired" prompt with a
   per-platform login link — log in, re-export cookies via Cookie-Editor, paste
   to reconnect (connectViaCookies already upserts status='active'). Replaces
   the opaque composer-timeout with an actionable message.

2. Collapse outreach history. The /recent history now shows one row per
   channel+provider (the latest attempt) instead of piling up every send/retry,
   so it updates in place (with the live refresh + retry already in place).

Also broadens the Mastodon publish-button selector (it reached compose but
missed the submit control).

Note: reuses the existing sp_account.status 'token_expired' value — no
migration.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 4, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 7d9ec8c into master Jul 4, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant