Skip to content

docs: finish the v0.43.0 docs and demos from the final review - #523

Merged
osanderson merged 2 commits into
mainfrom
docs/v0-43-final-review
Oct 2, 2026
Merged

osanderson merged 2 commits into
mainfrom
docs/v0-43-final-review

Conversation

@osanderson

Copy link
Copy Markdown
Collaborator

Summary

This makes the fixes from the final pre-release DevX review, plus one small cookie fix. It has two commits, for release-please.

fix: refuse a sealed cookie with under a second left (internal/sealedcookie, security review Info). Max-Age counts whole seconds, so under a second left made it 0. The browser then kept it as a session cookie until it closed. The sealed expiry already refused it, so this only tidies what the browser holds.

docs:

  • UPGRADING v0.43.0 named the wrong struct. It pointed at federation.AutomaticRegistrationConfig for automatically registered clients. A server integrator sets server.Config.AutomaticRegistration.AuthorizationDetailsTypes (feat(server): catch client RAR types Config.RAR doesn't register #521); federation's struct is only for building NewAutomaticClientRepository directly. The section also mentions Server.CheckClientRegistration, which was in no doc.
  • Discoverability:
    • README lists the browser and storage helpers: interactioncookie, sessioncookie, TokenSetSealer, and the *FromHTTP constructors.
    • ARCHITECTURE and client/doc.go name client/sessioncookie where they describe binding the session handle to the browser.
  • Cookie package docs:
    • Both Options docs agree that New refuses another Path for a __Host- name.
    • Dropping the prefix lets a sibling subdomain plant a cookie (security review Info).
    • Each package says to use keys of its own.
    • sessioncookie explains that a second tab replaces the first tab's cookie, and that the failed callback is the binding working.
  • Demos and GETTING_STARTED:
    • Form parsing. They parse the consent form before reading its tag (r.PostForm.Get(FormField)). PostFormValue used to swallow the parse error, so a malformed form showed "Session expired".
    • federated-union retry. It clears the interaction cookie just before CompleteAuthorization, as the other three do, so a submission with no citizen chosen can be retried.
    • Nonces. The payment-consent, linked-accounts, payroll-run and decoupled-checkout APIs call authz.SetDPoPNonce(w.Header()), as GETTING_STARTED says to.
    • Naming. GETTING_STARTED's snippet uses cookieKeys, so it no longer shadows the keys package.

The misplaced foldKey doc comment is fixed in #522, which rewrites that code.

Tests

  • TestCookieExpiresWithTheInteraction: Set refuses an interaction with 500ms left. Allowing it fails the test (mutation check).
  • Other checks:
    • go test -race ./internal/... ./client/... ./server/... passes.
    • golangci-lint is clean.
    • All six demos pass their tests and lint.

🤖 Generated with Claude Code

osanderson and others added 2 commits October 2, 2026 16:07
Max-Age counts whole seconds, so under a second left made it 0: a
session cookie, kept until the browser closes. The sealed expiry still
refused it, so this only tidies what the browser holds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- UPGRADING v0.43.0 named federation.AutomaticRegistrationConfig for
  automatically registered clients, but a server integrator sets
  server.Config.AutomaticRegistration.AuthorizationDetailsTypes;
  federation's is for building NewAutomaticClientRepository directly.
  The section now mentions Server.CheckClientRegistration.
- README lists the browser and storage helpers (interactioncookie,
  sessioncookie, TokenSetSealer, the FromHTTP constructors).
  ARCHITECTURE and client/doc.go name sessioncookie where they describe
  binding the session handle to the browser.
- The cookie packages' Options docs agree: New refuses another Path for
  a __Host- name, and dropping the prefix lets a sibling subdomain toss
  a cookie in. Each says to give it keys of its own. sessioncookie
  explains a second tab replacing the first's cookie.
- The demos and GETTING_STARTED parse the consent form before reading
  its tag, so a malformed form says so instead of "Session expired".
  federated-union clears the interaction cookie just before completing,
  as the others do, so a citizen-less submission can be retried. The
  RAR demo APIs call SetDPoPNonce.
- GETTING_STARTED's snippet no longer shadows the keys package.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@osanderson
osanderson force-pushed the docs/v0-43-final-review branch from d1c3ad6 to b3ab52a Compare October 2, 2026 08:07
@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@osanderson
osanderson merged commit b74288e into main Oct 2, 2026
17 checks passed
@osanderson
osanderson deleted the docs/v0-43-final-review branch October 2, 2026 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant