fix: align the legacy and optional network paths with V3 authority

LEG-01. AuthSessionPort.recover now takes the request's lifetime context, and
the raw recovery helper returns data only. The sign-out notification moved to
the site that adopts the result, so a recovery that answers after the deadline
or a caller abort is observed and discarded instead of logging the user out of
a request nobody is waiting on.

LEG-02. The V2 client shares V3's credential admission validator instead of
checking the allowed set alone. A bearer profile whose patch omits, empties,
duplicates or corrupts Authorization now fails closed with zero fetches rather
than dispatching an anonymous request under an authenticated profile.

OPT-NET-01. A cursor loader rejection is re-thrown exactly as it is with no
signal at all. Only a signal that has actually aborted classifies the outcome
as PAGINATION_ABORTED, so a real upstream failure stops being filed as a user
cancellation.

OPT-NET-02. defineMutationIntent and the V3 admission site now share the single
isValidIdempotencyKey authority, closing the drift that let a control character
through intent definition.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
DongHyeonka
2026-08-14 13:50:44 +09:00
co-authored by Claude Opus 5
parent f4bfdf0365
commit ca210d3bc5
7 changed files with 504 additions and 52 deletions
+10 -1
View File
@@ -9,7 +9,16 @@ export type SessionGateway = Readonly<{
subscribe(listener: () => void): () => void;
beginSignIn(returnTo?: string): Promise<void>;
signOut(): Promise<void>;
recover(): Promise<"restored" | "no-session">;
/**
* LEG-01. Recovery is part of a request's lifetime, so it receives the same
* context a credential attach does. The context is optional for one release
* to keep existing owners working; the transport races the signal either way,
* and a recovery that answers after the request already ended is observed but
* never turned into a user-visible sign-out.
*/
recover(
context?: CredentialOperationContext,
): Promise<"restored" | "no-session">;
}>;
export type CredentialRequestBinding = Readonly<{