Let a browser with cookies from an earlier database log in (closes #359) #362

Merged
clawbot merged 1 commits from issue-359-stale-cookie-login into next 2026-09-29 12:58:44 +02:00
1 Commits
Author SHA1 Message Date
clawbot a99ddbdcd3 Let a browser with cookies from an earlier database log in (closes #359)
check / check (push) Successful in 4m4s
A new database brings a new session key. A browser still holding the
old session cookie got a 500 on a correct login: Session.Get returned
the cookie's decode error and the login handler answered it with a
500. Get now treats a cookie that does not decode as absent, and
logging in replaces it. gorilla/csrf already did the same for the
CSRF cookie.

A start that creates webhooker.db now logs "created a new, empty
database" at WARN with its path, shortly before the first-boot banner,
so an unexpectedly empty DATA_DIR is noticed.

The codec tests now decode through the store, since Get no longer
reports the codec's reason.

Model: opus-5-5
2026-09-29 10:38:06 +00:00