19 lines
1.6 KiB
Markdown
19 lines
1.6 KiB
Markdown
# Iteration Log: View-As Mode Session Leak Fix across Logout & Login
|
|
|
|
- **Requested**: Fix critical security and UX bug where "View-As Mode" banner and session state persisted after logging out as Superadmin and logging in as an Agent viewer account.
|
|
- **Workflow**: Test-Driven Development (TDD) Workflow.
|
|
- **Steps Taken**:
|
|
1. Created TDD unit test `test/view_as_cleanup_test.js` to reproduce state leak during logout and login events.
|
|
2. Executed `node test/view_as_cleanup_test.js` -> Confirmed RED failure phase as expected.
|
|
3. Modified `src/lib/admin-api.ts` to export `clearViewAsState()` and `validateViewAsSession(currentUserRole)`.
|
|
4. Modified `src/app/login/page.tsx` (`handleLogin`) to wipe `localStorage.removeItem('backone_view_as')` on user authentication.
|
|
5. Modified `src/components/layout/SidebarProfile.tsx` to wipe `localStorage.removeItem('backone_view_as')` on user sign out.
|
|
6. Modified `src/hooks/useInactivityTimeout.ts` to wipe `localStorage.removeItem('backone_view_as')` on automatic inactivity timeout.
|
|
7. Modified `backend/routes/auth/core.js` to clear `view_as_token` cookie on server `/logout`.
|
|
8. Modified `src/components/layout/DashboardLayout.tsx` to validate active `viewAs` mode against `/api/auth/me` user role on mount.
|
|
9. Executed `node test/view_as_cleanup_test.js` -> GREEN pass achieved.
|
|
10. Ran `npx tsc --noEmit` -> 0 TypeScript compilation errors.
|
|
11. Ran `npm run build` -> Clean production build.
|
|
|
|
- **Outcome**: View-As state is 100% isolated to the active session. Logging out or logging in as any account guarantees complete cleanup of View-As mode.
|