1.6 KiB
1.6 KiB
Iteration Log: View-As Mode Session Leak Fix across Logout & Login
-
Requested: Fix critical security and UX bug where "View-As Mode" banner and session state persisted after logging out as Superadmin and logging in as an Agent viewer account.
-
Workflow: Test-Driven Development (TDD) Workflow.
-
Steps Taken:
- Created TDD unit test
test/view_as_cleanup_test.jsto reproduce state leak during logout and login events. - Executed
node test/view_as_cleanup_test.js-> Confirmed RED failure phase as expected. - Modified
src/lib/admin-api.tsto exportclearViewAsState()andvalidateViewAsSession(currentUserRole). - Modified
src/app/login/page.tsx(handleLogin) to wipelocalStorage.removeItem('backone_view_as')on user authentication. - Modified
src/components/layout/SidebarProfile.tsxto wipelocalStorage.removeItem('backone_view_as')on user sign out. - Modified
src/hooks/useInactivityTimeout.tsto wipelocalStorage.removeItem('backone_view_as')on automatic inactivity timeout. - Modified
backend/routes/auth/core.jsto clearview_as_tokencookie on server/logout. - Modified
src/components/layout/DashboardLayout.tsxto validate activeviewAsmode against/api/auth/meuser role on mount. - Executed
node test/view_as_cleanup_test.js-> GREEN pass achieved. - Ran
npx tsc --noEmit-> 0 TypeScript compilation errors. - Ran
npm run build-> Clean production build.
- Created TDD unit test
-
Outcome: View-As state is 100% isolated to the active session. Logging out or logging in as any account guarantees complete cleanup of View-As mode.