Two concurrent refresh calls (double-mounted bootstrap effect, second tab) replayed the same cookie; the loser tripped reuse detection and revoked the whole token family, forcing re-login. - Client: single-flight /auth/refresh — concurrent callers share one request. - Server: 30s grace window for a just-rotated token, but only while the family still has a live successor, so theft detection still kills a genuinely compromised family and logout stays final. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BFRyKxkKEjfAgpXygzoNiD |
||
|---|---|---|
| .. | ||
| src | ||
| eslint.config.mjs | ||
| package.json | ||
| tsconfig.json | ||