changes
This commit is contained in:
@@ -58,3 +58,24 @@ export function authHeader(): Record<string, string> {
|
||||
const token = readSessionToken();
|
||||
return token ? { Authorization: `Bearer ${token}` } : {};
|
||||
}
|
||||
|
||||
/**
|
||||
* Drop this tab's session, because the server says the token is no longer good.
|
||||
*
|
||||
* A session expires after twelve hours, and the signing key can be rotated
|
||||
* under a tab that is still open. Without this the console goes on sending a
|
||||
* dead token and every page shows an error — which reads to the person as "my
|
||||
* data has gone", not as "sign in again".
|
||||
*
|
||||
* Lives here rather than in `session.ts` for the same reason the reader does:
|
||||
* the HTTP client is what learns a session is dead, and it cannot import the
|
||||
* module that calls it.
|
||||
*/
|
||||
export function forgetSession(): void {
|
||||
try {
|
||||
sessionStorage.removeItem(SESSION_STORAGE_KEY);
|
||||
} catch {
|
||||
// Storage throws where site data is blocked. Nothing to do: the next read
|
||||
// returns undefined either way, which is the state this wanted.
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user