Review fixes (PR #11182 round 1):
- PasswordSession fires onUpdated/onDeleted BEFORE committing its
session data; thread the hook payload through to the provider instead
of reading the live getter. Fixes rotated tokens never persisting
(eventual forced logout) and expiry not logging out.
- getErrorName now gates on LexError, so LexAuthFactorError (a sibling
of XrpcError) surfaces AuthFactorTokenRequired and email-2fa users
get the code input.
- disposeBundle was a no-op; add a kill-switch closure around the
session's injected fetch (covers the internal auto-refresh path) so a
replaced session can't consume rotated refresh tokens. kill() also
disarms the hooks so stale bundles can't dispatch into the reducer.
- cross-tab same-did rebuild now reapplies subscribed labelers to the
fresh appview client (was built with an empty per-instance set).
- isAppLabeler reads Client.appLabelers instead of the hard-coded prod
did, restoring test-env and regional-authority classification.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
oxlint-suppressions.json gains a baseline entry for webpack.config.js: the
file was never previously staged/linted (lint script covers src+modules
only), and editing it exposed its pre-existing violations to lint-staged.
All suppressed counts are pre-existing; this change only removes a line.
Phase 3 foundations (task 1): src/lib/xrpc-error.ts matches both the old
@atproto/api XRPCError and lex-client XrpcError/XrpcResponseError during
the migration; errors.ts token-invalid matching goes through it. toLex<T>()
added to #/types/bsky as a marked interim cast for mixed-world boundaries.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>