fix(auth): keep login state on rate-limited or failing token refresh

When the dashboard token refresh endpoint returned 429 (shared
critical rate limit) the frontend classified it as out_of_sync,
cleared local auth state, and redirected to /sign-in. The rate limit
itself is working as intended; the bug is that a temporary rejection
was treated as a terminal auth failure.

- Treat 429 refresh responses as transient errors on the frontend,
  keeping the session retryable instead of clearing it. Only explicit
  401 or confirmed session mismatch/race exhaustion clears auth state.
- Return Retry-After on all rate-limited responses (remaining TTL on
  Redis, window duration on the in-memory limiter) so clients can
  back off.
- Log the underlying error with request context when auth session
  errors map to 500 AUTH_INTERNAL_ERROR, and replace fmt.Println with
  request-scoped logging in the Redis rate limiter error paths.

Fixes #6361
This commit is contained in:
CaIon
2026-07-21 12:39:29 +08:00
parent e0d5156115
commit 1721144221
5 changed files with 57 additions and 14 deletions
+3 -1
View File
@@ -61,7 +61,9 @@ func TestRedisIPRateLimiterThresholdTTLAndNamespace(t *testing.T) {
require.NoError(t, err)
assert.Equal(t, http.StatusNoContent, performRateLimitRequest(router, "/limited", remoteAddr).Code)
assert.Equal(t, http.StatusNoContent, performRateLimitRequest(router, "/limited", remoteAddr).Code)
assert.Equal(t, http.StatusTooManyRequests, performRateLimitRequest(router, "/limited", remoteAddr).Code)
limitedResponse := performRateLimitRequest(router, "/limited", remoteAddr)
assert.Equal(t, http.StatusTooManyRequests, limitedResponse.Code)
assert.Equal(t, "37", limitedResponse.Header().Get("Retry-After"))
key := redisIPRateLimitKey("TEST", "192.0.2.10")
count, err := redisServer.Get(key)