docs: finish the v0.43.0 docs and demos from the final review - #523
Merged
Merged
Conversation
Max-Age counts whole seconds, so under a second left made it 0: a session cookie, kept until the browser closes. The sealed expiry still refused it, so this only tidies what the browser holds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- UPGRADING v0.43.0 named federation.AutomaticRegistrationConfig for automatically registered clients, but a server integrator sets server.Config.AutomaticRegistration.AuthorizationDetailsTypes; federation's is for building NewAutomaticClientRepository directly. The section now mentions Server.CheckClientRegistration. - README lists the browser and storage helpers (interactioncookie, sessioncookie, TokenSetSealer, the FromHTTP constructors). ARCHITECTURE and client/doc.go name sessioncookie where they describe binding the session handle to the browser. - The cookie packages' Options docs agree: New refuses another Path for a __Host- name, and dropping the prefix lets a sibling subdomain toss a cookie in. Each says to give it keys of its own. sessioncookie explains a second tab replacing the first's cookie. - The demos and GETTING_STARTED parse the consent form before reading its tag, so a malformed form says so instead of "Session expired". federated-union clears the interaction cookie just before completing, as the others do, so a citizen-less submission can be retried. The RAR demo APIs call SetDPoPNonce. - GETTING_STARTED's snippet no longer shadows the keys package. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
osanderson
force-pushed
the
docs/v0-43-final-review
branch
from
October 2, 2026 08:07
d1c3ad6 to
b3ab52a
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
This makes the fixes from the final pre-release DevX review, plus one small cookie fix. It has two commits, for release-please.
fix: refuse a sealed cookie with under a second left (internal/sealedcookie, security review Info).Max-Agecounts whole seconds, so under a second left made it 0. The browser then kept it as a session cookie until it closed. The sealed expiry already refused it, so this only tidies what the browser holds.docs:federation.AutomaticRegistrationConfigfor automatically registered clients. A server integrator setsserver.Config.AutomaticRegistration.AuthorizationDetailsTypes(feat(server): catch client RAR types Config.RAR doesn't register #521); federation's struct is only for buildingNewAutomaticClientRepositorydirectly. The section also mentionsServer.CheckClientRegistration, which was in no doc.interactioncookie,sessioncookie,TokenSetSealer, and the*FromHTTPconstructors.client/doc.gonameclient/sessioncookiewhere they describe binding the session handle to the browser.Optionsdocs agree thatNewrefuses anotherPathfor a__Host-name.r.PostForm.Get(FormField)).PostFormValueused to swallow the parse error, so a malformed form showed "Session expired".CompleteAuthorization, as the other three do, so a submission with no citizen chosen can be retried.authz.SetDPoPNonce(w.Header()), as GETTING_STARTED says to.cookieKeys, so it no longer shadows thekeyspackage.The misplaced
foldKeydoc comment is fixed in #522, which rewrites that code.Tests
TestCookieExpiresWithTheInteraction:Setrefuses an interaction with 500ms left. Allowing it fails the test (mutation check).go test -race ./internal/... ./client/... ./server/...passes.🤖 Generated with Claude Code