Files
Deep-Package-Inspection/docs/log/2026-07-30-0948-n.md
T

19 lines
1.6 KiB
Markdown

# Iteration Log: View-As Mode Session Leak Fix across Logout & Login
- **Requested**: Fix critical security and UX bug where "View-As Mode" banner and session state persisted after logging out as Superadmin and logging in as an Agent viewer account.
- **Workflow**: Test-Driven Development (TDD) Workflow.
- **Steps Taken**:
1. Created TDD unit test `test/view_as_cleanup_test.js` to reproduce state leak during logout and login events.
2. Executed `node test/view_as_cleanup_test.js` -> Confirmed RED failure phase as expected.
3. Modified `src/lib/admin-api.ts` to export `clearViewAsState()` and `validateViewAsSession(currentUserRole)`.
4. Modified `src/app/login/page.tsx` (`handleLogin`) to wipe `localStorage.removeItem('backone_view_as')` on user authentication.
5. Modified `src/components/layout/SidebarProfile.tsx` to wipe `localStorage.removeItem('backone_view_as')` on user sign out.
6. Modified `src/hooks/useInactivityTimeout.ts` to wipe `localStorage.removeItem('backone_view_as')` on automatic inactivity timeout.
7. Modified `backend/routes/auth/core.js` to clear `view_as_token` cookie on server `/logout`.
8. Modified `src/components/layout/DashboardLayout.tsx` to validate active `viewAs` mode against `/api/auth/me` user role on mount.
9. Executed `node test/view_as_cleanup_test.js` -> GREEN pass achieved.
10. Ran `npx tsc --noEmit` -> 0 TypeScript compilation errors.
11. Ran `npm run build` -> Clean production build.
- **Outcome**: View-As state is 100% isolated to the active session. Logging out or logging in as any account guarantees complete cleanup of View-As mode.