Skip to content

fix(auth): name a real remedy in logout failure messages - #880

Merged
remyluslosius merged 1 commit into
mainfrom
fix/logout-messages-name-a-real-remedy
Sep 27, 2026
Merged

remyluslosius merged 1 commit into
mainfrom
fix/logout-messages-name-a-real-remedy

Conversation

@remyluslosius

Copy link
Copy Markdown
Contributor

v0.8 scope-freeze exception, approved 2026-09-25 (projects/openwatch/V0_8_0_READINESS). No merge is authorized yet.

What was wrong

When logout could not revoke a session, or could not confirm that it did, its message sent the user to Settings:

  • "Check your active sessions in Settings."
  • "Revoke it from Settings."

Settings shows only the current session and cannot list or end others. Its own code says revoking other sessions is disabled "until /auth/sessions ships". The message told the user to do something they cannot do, on the one path where their session may still be live.

Change

All three failure messages now say the session may remain valid until it expires, and name the remedy that works: an administrator can end it by resetting the user's password. That reset revokes every interactive credential (system-auth-identity C-36, AC-38).

Outcome Status and retryability (unchanged)
Revocation failed and rolled back 500 auth.logout_incomplete, retryable
Revocation outcome unknown 503 server.error, not retryable
Account lock not acquired 503 server.error, not retryable

Contract and evidence

  • system-auth-identity 1.10.0: C-46 and AC-93 added, with explicit inputs and expected output.
  • AC-93 exercises all three paths:
    • a trigger that fails the refresh-token revocation;
    • an indeterminate commit;
    • the account lock held past the limit.
  • Mutation checks: each message restored to its old wording turned its own AC-93 case red.
  • make spec-check passed (100%). The existing logout, CSRF and lock tests pass.
  • CHANGELOG.md gains an [Unreleased] entry. It may conflict trivially with the other v0.8 exception PRs, which also add one.

Not changed: the Settings sessions placeholder itself, and OW-072, which is not in v0.8.

When logout could not revoke a session, or could not confirm that it
did, its message told the user to check or revoke sessions in Settings.
Settings shows only the current session and cannot list or end others,
so the message sent the user to do something they cannot do, on the one
path where their session may still be live.

All three failure messages (revocation rolled back, outcome unknown,
account lock not acquired) now say the session may remain valid until it
expires and name the remedy that works: an administrator can end it by
resetting the user's password, which revokes every interactive
credential. Status codes and retryability are unchanged.

system-auth-identity 1.10.0: C-46 and AC-93 added. Each of the three
messages was mutated back to its old wording, and each mutation turned
its own AC-93 case red.

Approved as a v0.8 scope-freeze exception on 2026-09-25
(projects/openwatch/V0_8_0_READINESS).
@remyluslosius
remyluslosius merged commit 8d13378 into main Sep 27, 2026
14 checks passed
@remyluslosius
remyluslosius deleted the fix/logout-messages-name-a-real-remedy branch September 27, 2026 00:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant