fix session refresh persistence, 2fa login, bundle disposal, cross-tab labelers

Review fixes (PR #11182 round 1):
- PasswordSession fires onUpdated/onDeleted BEFORE committing its
  session data; thread the hook payload through to the provider instead
  of reading the live getter. Fixes rotated tokens never persisting
  (eventual forced logout) and expiry not logging out.
- getErrorName now gates on LexError, so LexAuthFactorError (a sibling
  of XrpcError) surfaces AuthFactorTokenRequired and email-2fa users
  get the code input.
- disposeBundle was a no-op; add a kill-switch closure around the
  session's injected fetch (covers the internal auto-refresh path) so a
  replaced session can't consume rotated refresh tokens. kill() also
  disarms the hooks so stale bundles can't dispatch into the reducer.
- cross-tab same-did rebuild now reapplies subscribed labelers to the
  fresh appview client (was built with an empty per-instance set).
- isAppLabeler reads Client.appLabelers instead of the hard-coded prod
  did, restoring test-env and regional-authority classification.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Samuel Newman
2026-07-17 15:17:40 +03:00
parent 564044f6ac
commit 4c2771eca3
5 changed files with 300 additions and 36 deletions
+10 -3
View File
@@ -1,4 +1,4 @@
import {XrpcError, XrpcResponseError} from '@atproto/lex-client'
import {LexError, XrpcError, XrpcResponseError} from '@atproto/lex-client'
/**
* True for an XRPC error from a lex `Client` (`@atproto/lex-client` `XrpcError`,
@@ -18,9 +18,16 @@ export function getErrorStatus(e: unknown): number | undefined {
return e instanceof XrpcResponseError ? e.status : undefined
}
/** The lexicon error code (`err.error`). */
/**
* The lexicon error code (`err.error`). Gated on `LexError` (the base of the
* lex error hierarchy) rather than `XrpcError` so sibling `LexError` subclasses
* that are NOT `XrpcError` also surface their `.error` - notably
* `LexAuthFactorError` (`'AuthFactorTokenRequired'`), which `PasswordSession`
* throws for email-2FA logins. Every `XrpcError` is a `LexError`, so all
* existing call sites keep working.
*/
export function getErrorName(e: unknown): string | undefined {
return isXrpcError(e) ? (e as {error?: string}).error : undefined
return e instanceof LexError ? e.error : undefined
}
/**