fix(auth): name a real remedy in logout failure messages - #880
Merged
Merged
Conversation
When logout could not revoke a session, or could not confirm that it did, its message told the user to check or revoke sessions in Settings. Settings shows only the current session and cannot list or end others, so the message sent the user to do something they cannot do, on the one path where their session may still be live. All three failure messages (revocation rolled back, outcome unknown, account lock not acquired) now say the session may remain valid until it expires and name the remedy that works: an administrator can end it by resetting the user's password, which revokes every interactive credential. Status codes and retryability are unchanged. system-auth-identity 1.10.0: C-46 and AC-93 added. Each of the three messages was mutated back to its old wording, and each mutation turned its own AC-93 case red. Approved as a v0.8 scope-freeze exception on 2026-09-25 (projects/openwatch/V0_8_0_READINESS).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
v0.8 scope-freeze exception, approved 2026-09-25 (
projects/openwatch/V0_8_0_READINESS). No merge is authorized yet.What was wrong
When logout could not revoke a session, or could not confirm that it did, its message sent the user to Settings:
Settings shows only the current session and cannot list or end others. Its own code says revoking other sessions is disabled "until /auth/sessions ships". The message told the user to do something they cannot do, on the one path where their session may still be live.
Change
All three failure messages now say the session may remain valid until it expires, and name the remedy that works: an administrator can end it by resetting the user's password. That reset revokes every interactive credential (
system-auth-identityC-36, AC-38).auth.logout_incomplete, retryableserver.error, not retryableserver.error, not retryableContract and evidence
system-auth-identity1.10.0: C-46 and AC-93 added, with explicit inputs and expected output.make spec-checkpassed (100%). The existing logout, CSRF and lock tests pass.CHANGELOG.mdgains an[Unreleased]entry. It may conflict trivially with the other v0.8 exception PRs, which also add one.Not changed: the Settings sessions placeholder itself, and OW-072, which is not in v0.8.