Skip to content

Fix switch user w/ remember me (broke in last release) - #1117

Merged
barryo merged 2 commits into
mainfrom
fix-remember-me
Oct 7, 2026
Merged

barryo merged 2 commits into
mainfrom
fix-remember-me

Conversation

@afk11

@afk11 afk11 commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

When I scoped all the queries for Remember Me tokens to the currently logged in user, I would up breaking the 'switch user' feature when using remember me tokens

When using switch user, session user is different to the owner of the remember me token, so we need to refer to the original user id.

So this fixes the issue and provides some follow up work

Goal 1: Ensure that when SessionGuard calls logout that the session is completely cleaned up.

To accomplish this, we hook into the Logout event fired by SessionGuard::logout. The listener
InvalidSessionOnLogout does the session invalidation and CSRF token regeneration.

This is a win because we call Auth::logout in several other places but don't do the
session invalidation, which is a problem.

NOTE: Because this nukes the session, any alert messages, flash data, will be removed
unless they're pushed after logout.

Goal 2: React to Remember Me token integrity failures.

Add a middleware which does the Guard::check, and then checks to see if we've
identified the integrity failure and begun a logout. If so, set an appropriate alert
and redirect to login.

Auth::check happens all over the place, and SessionGuard isn't an appropriate place
to redirect / set messages, so do it in middleware!

Other work:

  • Refactor login controller - when extending a method, keep parameters named the same.
  • Refactor UserRememberTokenController - instead of redirecting to logout, just perform the logout and set appropriate message to display on login form
  • SessionGuard::cycleRememberToken - ensure recaller token is valid before deleting.
  • Add tests covering a variety of cases using remember me.

afk11 added 2 commits October 6, 2026 10:46
Goal 1: Ensure that when SessionGuard calls logout that the session is completely cleaned up.

To accomplish this, we hook into the Logout event fired by SessionGuard::logout. The listener
`InvalidSessionOnLogout` does the session invalidation and CSRF token regeneration.

This is a win because we call `Auth::logout` in several other places but don't do the
session invalidation, which is a problem.

**NOTE**: Because this nukes the session, any alert messages, flash data, will be removed
unless they're pushed _after_ logout.

Goal 2: React to Remember Me token integrity failures.

Add a middleware which does the Guard::check, and then checks to see if we've
identified the integrity failure and begun a logout. If so, set an appropriate alert
and redirect to login.

Auth::check happens all over the place, and SessionGuard isn't an appropriate place
to redirect / set messages, so do it in middleware!

Other work:
 - Refactor login controller - when extending a method, keep parameters named the same.
 - Refactor UserRememberTokenController - instead of redirecting to logout, just perform the logout and set appropriate message to display on login form
 - SessionGuard::cycleRememberToken - ensure recaller token is valid before deleting.
 - Add tests covering a variety of cases using remember me.

psalm fixes
@barryo
barryo merged commit 8562f3e into main Oct 7, 2026
3 checks passed
@barryo
barryo deleted the fix-remember-me branch October 7, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants