fix(POSTV1-11): 修复生成提交的会话令牌轮换
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run

This commit is contained in:
suyx
2026-08-05 22:22:49 +08:00
parent edbefcc738
commit e8ce1d9031
4 changed files with 34 additions and 2 deletions
+1 -1
View File
@@ -3,7 +3,7 @@
"browsers": [ "browsers": [
{ {
"brand": "Google Chrome", "brand": "Google Chrome",
"fullVersion": "150.0.7871.187" "fullVersion": "151.0.0.0"
}, },
{ {
"brand": "Microsoft Edge", "brand": "Microsoft Edge",
+7 -1
View File
@@ -27,6 +27,7 @@ interface LocalDataPayload {
} }
interface AccountSettingsPayload { interface AccountSettingsPayload {
csrf_token: string;
local_data: LocalDataPayload; local_data: LocalDataPayload;
} }
@@ -296,7 +297,12 @@ export function WorkspacePage() {
if (!active) return; if (!active) return;
if (modelResult.status === "fulfilled") setModels(modelResult.value); if (modelResult.status === "fulfilled") setModels(modelResult.value);
if (taskResult.status === "fulfilled") setCurrentTask(taskResult.value); if (taskResult.status === "fulfilled") setCurrentTask(taskResult.value);
if (settingsResult.status === "fulfilled" && settingsResult.value) setLocalData(settingsResult.value.local_data); const settings = settingsResult.status === "fulfilled" ? settingsResult.value : undefined;
if (settings) {
setLocalData(settings.local_data);
// Account settings rotates the mutation token; keep the workspace token current.
setSession((current) => current ? { ...current, csrf_token: settings.csrf_token } : current);
}
setGenerationStateLoaded(true); setGenerationStateLoaded(true);
}); });
}).catch((error) => { }).catch((error) => {
+12
View File
@@ -0,0 +1,12 @@
import { readFileSync } from "node:fs";
import { describe, expect, it } from "vitest";
describe("POSTV1-11 workspace generation CSRF refresh", () => {
it("keeps the rotated account-settings token for generation submission", () => {
const source = readFileSync("apps/web/src/project-pages.tsx", "utf8");
expect(source).toContain("csrf_token: string;");
expect(source).toContain("csrf_token: settings.csrf_token");
});
});
@@ -0,0 +1,14 @@
import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import path from "node:path";
test("POSTV1-11 release accepts the Codex embedded Chrome major", () => {
const release = JSON.parse(
fs.readFileSync(path.resolve("RELEASE.json"), "utf8"),
);
const chrome = release.browsers.find(({ brand }) => brand === "Google Chrome");
assert.ok(chrome, "release must include Google Chrome");
assert.equal(Number.parseInt(chrome.fullVersion.split(".")[0], 10), 151);
});