proposal-system/web
Adam Moussa 5441836274
fix(web): harden auth session teardown per /sh-security-review findings
- AUTH-L1 (confirmed medium): logout() now clears the react-query cache —
  the singleton cache survived SPA logout, serving the previous
  principal's cached GETs to the next login in the same tab for up to
  staleTime with no server round-trip.
- AUTH-L3 (confirmed low): isTokenValid decodes base64url before atob —
  valid Cognito JWTs containing '-'/'_' in the payload segment were
  misclassified as expired (login lockout/loop; inherited from the old
  authSlice).
- AUTH-L2 (unverified, hardened anyway): 401 interceptor broadcasts
  AUTH_SESSION_CLEARED_EVENT so AuthProvider drops in-memory state
  synchronously, restoring the old Redux atomic-clear semantics.
- INJ-1 (unverified, hardened anyway): Authorization header only set
  when the stored token is a string.

Each fix pinned by a test; 63 vitest green, tsc clean.
2026-07-13 19:43:48 -04:00
..
.claude/skills/verify refactor(web): fold Redux auth/ui slices into SHOC-shape auth context + storage module 2026-07-13 19:31:40 -04:00
src fix(web): harden auth session teardown per /sh-security-review findings 2026-07-13 19:43:48 -04:00
.env.example Implement Phases 2-5: Frontend, AI/RAG, PDF Generation (#22) 2026-05-17 13:06:23 -04:00
index.html feat(web): adopt SHOC design system and shell layout (ADR 0003) 2026-07-13 16:47:17 -04:00
package-lock.json refactor(web): fold Redux auth/ui slices into SHOC-shape auth context + storage module 2026-07-13 19:31:40 -04:00
package.json refactor(web): fold Redux auth/ui slices into SHOC-shape auth context + storage module 2026-07-13 19:31:40 -04:00
tsconfig.json fix(web): apply Phase 4 code-review findings (10 correctness + 4 cleanup) 2026-07-13 19:06:08 -04:00
vite.config.ts fix(web): apply Phase 4 code-review findings (10 correctness + 4 cleanup) 2026-07-13 19:06:08 -04:00
vitest.config.ts fix(web): apply Phase 4 code-review findings (10 correctness + 4 cleanup) 2026-07-13 19:06:08 -04:00