feat(logout): improve logout flow

This commit is contained in:
Edouard Vanbelle
2026-08-09 14:09:54 +02:00
parent 321f3ad733
commit 2eb1e8a1d5
4 changed files with 37 additions and 10 deletions
+11
View File
@@ -8,6 +8,7 @@
*/
import { bindDpopIfPossible, fetchMe, tryRefresh } from '$lib/api/endpoints/auth';
import { setLogoutInProgress } from '$lib/api/client';
import { hasSessionHint } from '$lib/api/csrf';
import { drives } from '$lib/stores/drives.svelte';
import type { User } from '$lib/api/types';
import { ensureActiveUser } from '$lib/utils/localStoragePrefs';
@@ -41,6 +42,16 @@ class SessionStore {
*/
async load(): Promise<User | null> {
if (this.loaded) return this.user;
// No JS-visible session hint ⇒ nothing to probe. The server sets
// `oxicloud_csrf` alongside the HttpOnly session cookies and clears
// it on logout, so a missing hint means no session. Skips the
// doomed 2× /me + /refresh burst that would otherwise fire on
// every first landing / post-logout re-mount with no cookies.
if (!hasSessionHint()) {
this.user = null;
this.loaded = true;
return null;
}
try {
let me = await fetchMe();
if (!me && (await tryRefresh())) {