Files
Deep-Package-Inspection/docs/log/2026-07-30-0948-n.md
T

1.6 KiB

Iteration Log: View-As Mode Session Leak Fix across Logout & Login

  • Requested: Fix critical security and UX bug where "View-As Mode" banner and session state persisted after logging out as Superadmin and logging in as an Agent viewer account.

  • Workflow: Test-Driven Development (TDD) Workflow.

  • Steps Taken:

    1. Created TDD unit test test/view_as_cleanup_test.js to reproduce state leak during logout and login events.
    2. Executed node test/view_as_cleanup_test.js -> Confirmed RED failure phase as expected.
    3. Modified src/lib/admin-api.ts to export clearViewAsState() and validateViewAsSession(currentUserRole).
    4. Modified src/app/login/page.tsx (handleLogin) to wipe localStorage.removeItem('backone_view_as') on user authentication.
    5. Modified src/components/layout/SidebarProfile.tsx to wipe localStorage.removeItem('backone_view_as') on user sign out.
    6. Modified src/hooks/useInactivityTimeout.ts to wipe localStorage.removeItem('backone_view_as') on automatic inactivity timeout.
    7. Modified backend/routes/auth/core.js to clear view_as_token cookie on server /logout.
    8. Modified src/components/layout/DashboardLayout.tsx to validate active viewAs mode against /api/auth/me user role on mount.
    9. Executed node test/view_as_cleanup_test.js -> GREEN pass achieved.
    10. Ran npx tsc --noEmit -> 0 TypeScript compilation errors.
    11. Ran npm run build -> Clean production build.
  • Outcome: View-As state is 100% isolated to the active session. Logging out or logging in as any account guarantees complete cleanup of View-As mode.