fix(ui): scope deleteCookie sessionStorage cleanup to token key only

Also document the sessionStorage cross-tab trade-off: per-tab scope
means users behind an HttpOnly proxy must log in once per tab, but
this is intentional to avoid localStorage XSS exposure.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Hendrik Jaks 2026-03-13 11:12:35 +02:00
parent 523d1c388f
commit acdc6145b3
2 changed files with 10 additions and 4 deletions

View file

@ -56,10 +56,12 @@ import { ConfigProvider, theme } from "antd";
function deleteCookie(name: string, path = "/") {
// Best-effort client-side clear (works for non-HttpOnly cookies without Domain)
document.cookie = `${name}=; Max-Age=0; Path=${path}`;
try {
sessionStorage.removeItem(name);
} catch {
// sessionStorage may be unavailable
if (name === "token") {
try {
sessionStorage.removeItem(name);
} catch {
// sessionStorage may be unavailable
}
}
}

View file

@ -56,6 +56,10 @@ export function clearTokenCookies() {
* Stores the login token in sessionStorage.
* This ensures the token is available even when a reverse proxy adds HttpOnly
* to server-set cookies, making them invisible to JavaScript.
*
* Note: sessionStorage is per-tab, so users behind an HttpOnly proxy must log
* in once per tab. We intentionally avoid localStorage here because it persists
* after browser close and is readable by any injected script (XSS).
*/
export function storeLoginToken(token: string) {
if (typeof window === "undefined") return;