-
Notifications
You must be signed in to change notification settings - Fork 58
Open
Labels
Description
When a non-authorized user opens a page, it is forced to sign-in. But if while editing and for some unidentified yet reason (token expired, worker reloaded... ?) user is not authorized anymore, they can continue authoring for a long time. On page reload, all changes would be gone.
The websocket could detect that case and force a re-signing.
We need to be careful because we observe a lot of 401 in the logs, I suspect the auth to not be fully stable. It might end up that users get disconnected way too frequently (which would be expected but a consequence of something wrong...)
See also thread https://cq-dev.slack.com/archives/C08MJQ0Q3GA/p1757005611676039
In the video recording of the issue, we can see:
- someone authoring a page for a couple of minutes
- when trying to preview, the envelop icon becomes red
- after scrolling to the top of the page, an error message is shown:
Not authorized to preview - after re-login (IMS...), several minutes of changes are gone. Based on the logs, I would say aprox 4mins of changes...