security(session): do not expose 'sid' from OIDC

prefer exposing origin of the session: passwod, opaque, magic_link, oidc, unknown
This commit is contained in:
Edouard Vanbelle
2026-08-09 15:14:59 +02:00
parent c28eb9b42e
commit 763ee82028
8 changed files with 225 additions and 17 deletions
-1
View File
@@ -767,7 +767,6 @@ export interface SessionSummary {
dpop_jkt_prefix: string | null;
is_revoked: boolean;
is_active: boolean;
oidc_sid: string | null;
/** `true` when this row IS the admin's currently-active session —
* compared server-side by `dpop_jkt`. Panel uses this to warn
* before revoking ("this will log you out"). Always `false` when