Two concurrent refresh calls (double-mounted bootstrap effect, second tab) replayed the same cookie; the loser tripped reuse detection and revoked the whole token family, forcing re-login. - Client: single-flight /auth/refresh — concurrent callers share one request. - Server: 30s grace window for a just-rotated token, but only while the family still has a live successor, so theft detection still kills a genuinely compromised family and logout stays final. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BFRyKxkKEjfAgpXygzoNiD |
||
|---|---|---|
| .. | ||
| backend | ||
| core | ||
| desktop | ||
| mobile | ||
| web | ||