Skip to content

Use session storage for cached JWT - #70

Merged
buckett merged 1 commit into
masterfrom
token-caching
Feb 24, 2026
Merged

buckett merged 1 commit into
masterfrom
token-caching

Conversation

@buckett

@buckett buckett commented Feb 19, 2026

Copy link
Copy Markdown
Member

Summary

  • switch the LTI token retriever to read JWTs from sessionStorage instead of localStorage
  • ensure cached data handling still guards against missing or malformed entries

Testing

  • Not run (not requested)

Copilot AI review requested due to automatic review settings February 19, 2026 09:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the LTI token retriever’s cached-JWT lookup to use sessionStorage (matching the existing write path) instead of localStorage, improving cache consistency for token fallback behavior.

Changes:

  • Read cached JWT from sessionStorage in loadJwt().
  • Keep existing cached data parsing/handling behavior for missing entries.
Comments suppressed due to low confidence (2)

src/components/tokenRetriever/LtiTokenRetriever.tsx:158

  • loadJwt() rethrows any non-DOMException errors. A malformed cached value will cause JSON.parse(stored) to throw a SyntaxError, which will bubble up and show an internal parse error message instead of treating the cache as a miss (and contradicts the intent to guard against malformed entries). Consider catching parse/shape errors and returning null (optionally clearing the bad jwt entry) rather than rethrowing.
      const stored = sessionStorage.getItem('jwt');
      if (!stored) return null;
      const data = JSON.parse(stored);
      if (!data) return null;

      return data.token ?? null;
    } catch (e) {
      if (!(e instanceof DOMException)) {
        throw e;
      }

src/components/tokenRetriever/LtiTokenRetriever.tsx:155

  • The cached-JWT fallback path (including reading from sessionStorage and handling missing/malformed entries) isn’t covered by tests in LtiTokenRetriever.test.jsx. Add test cases for: (1) non-OK token response uses the cached JWT, (2) missing cache shows the generic failure message, and (3) malformed cache contents are ignored rather than surfacing a JSON parse error.
      const stored = sessionStorage.getItem('jwt');
      if (!stored) return null;
      const data = JSON.parse(stored);
      if (!data) return null;

      return data.token ?? null;
    } catch (e) {

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@sebastianchristopher sebastianchristopher left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@buckett
buckett merged commit 2463aea into master Feb 24, 2026
11 checks passed
@buckett
buckett deleted the token-caching branch February 24, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants