Skip to content

[stable33] fix(session): only regenerate session id after valid remember-me cookie - #64927

Merged
susnux merged 1 commit into
stable33from
backport/64924/stable33
Sep 30, 2026
Merged

susnux merged 1 commit into
stable33from
backport/64924/stable33

Conversation

@backportbot

@backportbot backportbot Bot commented Sep 30, 2026

Copy link
Copy Markdown

Backport of PR #64924

loginWithCookie() regenerated the session id before validating the
remember-me cookie. With stale cookies (e.g. after the session token was
invalidated by an OIDC backchannel logout) every request rotated the
session and failed. Parallel requests then forked the same session, and
the browser could end up with a copy lacking data stored during the
login, such as user_oidc's OIDC state or the login flow v2 state token.

Regenerate the session id only once the cookie has been validated.

Signed-off-by: Jonas <jonas@freesources.org>
Assisted-by: ClaudeCode:claude-opus-5.5
@backportbot
backportbot Bot requested a review from a team as a code owner September 30, 2026 10:46
@backportbot
backportbot Bot requested review from a team, Altahrim, CarlSchwan, mejo-, provokateurin, salmart-dev and susnux and removed request for a team September 30, 2026 10:46
@backportbot backportbot Bot added this to the Nextcloud 33.0.10 milestone Sep 30, 2026
@github-actions github-actions Bot changed the title [stable33] [stable35] fix(session): only regenerate session id after valid remember-me cookie [stable33] fix(session): only regenerate session id after valid remember-me cookie Sep 30, 2026
@susnux
susnux merged commit 5ebb162 into stable33 Sep 30, 2026
227 of 232 checks passed
@susnux
susnux deleted the backport/64924/stable33 branch September 30, 2026 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants