feat: Share one session across tabs (M2-11052) - #2251
Open
sricharan-varanasi wants to merge 11 commits into
Open
feat: Share one session across tabs (M2-11052)#2251sricharan-varanasi wants to merge 11 commits into
sricharan-varanasi wants to merge 11 commits into
Conversation
sricharan-varanasi
force-pushed
the
session-sync-local
branch
from
August 13, 2026 15:16
50e94ba to
b8cc745
Compare
sricharan-varanasi
force-pushed
the
session-storage-local
branch
from
August 13, 2026 15:17
32f1efd to
ce42957
Compare
sricharan-varanasi
force-pushed
the
session-sync-local
branch
from
August 13, 2026 15:18
b8cc745 to
8504546
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📝 Description
🔗 Jira Ticket M2-11052
#2249 moved tokens into one shared, encrypted slot. But
react-secure-storagereads from a snapshot taken when the page loads, so a tab still can't see what another tab wrote.That leaves three problems:
Tabs now talk over a
BroadcastChannel.Changes include:
The main bug - a background tab logging out the tab you're actually using - is fixed by one line. The idle clock is shared now, so the timer just re-reads it instead of firing blind.
🪤 Peer Testing
Needs
enableSessionKeepAliveon locally,REACT_APP_IDLE_TIMEOUT_MIN=3,REACT_APP_REFRESH_LEAD_SEC=20.Use
chrome://discards(oredge://discards) → Freeze for the frozen-tab steps.Two tabs. Work in tab A past the idle timeout, leave tab B in the background
Expected outcome: neither logs out
Two tabs. Wait for a rotation, then click something in tab B
Expected outcome: one refresh call across the browser, and tab B doesn't 401
Log out in tab A
Expected outcome: tab B goes to the login page straight away
Edit something in the builder, then idle out
Expected outcome: soft-lock login, no unsaved-changes modal
Edit something in the builder, then log out from the account menu
Expected outcome: the save/discard prompt still appears
Freeze a tab, rotate a few times elsewhere, then focus it
Expected outcome: it catches up, no 401
Freeze tab B, log out in tab A, focus tab B
Expected outcome: tab B tears down on focus
Leave tab A on the login page, sign in on tab B
Expected outcome: tab A moves to the dashboard. Close tab B first and tab A reloads once instead
Flag off
Expected outcome: no channel traffic, no idle logout, same as feat: Move tokens to local storage (M2-11055) #2249 alone
✏️ Notes
session-storage-local(feat: Move tokens to local storage (M2-11055) #2249), which sits onsession-keep-alive(feat: keep session alive on Admin ( M2 - 11001 ) #2246). Merge in order.✅ Checklist
Functionality
Testing
Security & Data Privacy
Logging/Monitoring
Performance
Readability
Change Safety
Backend changes are backwards compatible with old clients, or it is well known they are not and a deployment/rollout plan is in place. This include backend changes being compatible with old mobile app versions, as well as applet versioning within Curious.Destructive database migrations are rolled out in stages. For example, renaming a column means adding a new column and migrating the existing data to that columns in one deployment. Then monitoring to ensure that field isn't used, and finally removing that old column in a separate deployment.