Conversation
|
| with ThreadingHTTPServer( | ||
| ("127.0.0.1", 0), partial(SimpleHTTPRequestHandler, directory=str(tmp_path)) | ||
| ) as server: |
There was a problem hiding this comment.
Host page may be unreachable If the frontend URL uses
127.0.0.1 and localhost resolves to IPv6 loopback, this test navigates to localhost while its host-page server listens only on 127.0.0.1. The page cannot load, so the cross-site iframe test fails before checking session behavior. Bind the server for the hostname the test selects.
| # The base harness supports binding the original port in both build modes. | ||
| AppHarness._start_backend(backend_path_app, port=port) | ||
| backend_path_app._poll_for_servers(timeout=10) |
There was a problem hiding this comment.
Production restart bypasses production setup This test also runs with
AppHarnessProd, but it restarts the backend through the base harness method. That skips the production starter’s worker configuration and compile-suppression setup, so the prod case does not exercise a production-style restart. Preserve those settings when rebinding the original port.
Exercise session ownership in real servers and browsers, migrate synthetic clients to server-issued credentials, and document rollout/deployment. The development AppHarness uses the same frontend/backend hostname so cookie behavior is realistic.
Covers ENG-12920 and ENG-12921. Top of the core stack: #7360 → #7361 → #7362 → #7363 → #7364. Enterprise companion: reflex-dev/reflex-enterprise#240.
The existing backend-path app now runs under enforce and covers held cookie exchange with immediate hydration/events, shared-session tabs, duplicated tabs, upload, short-TTL refresh, backend restart and cross-site iframe persistence. The existing EmbedPlugin host app also runs under enforce. A backend-only real Granian test proves state events complete while cookie exchange is held and reconnect preserves state; no new public harness server-switching API was necessary. Benchmark reconnects reuse cookies and bound client tokens, and issuance stays outside measured event latency. The reflex-bench driver already handled server replacement tokens, so its production implementation is unchanged; regression coverage includes the new control events. Legacy JavaScript behavior is covered at the protocol/unit boundary rather than bundling an old frontend build.
The guide documents key rotation/persistence, origin configuration, partitioned cookies, embedding, off/warn/enforce, explicit SYSTEM authority, anonymous overrides, tools and enterprise compatibility. Rate limiting uses existing reverse-proxy/api_transformer facilities instead of adding a second public hook.
Validation:
pyright reflex testsclean. Stub generation made no tracked changes. Full-repository pre-commit Pyright hits four existing macOS type errors in unchanged reflex-bench Linux CPU-affinity code (os.sched_setaffinity,os.sched_getaffinity,Process.cpu_affinity); these are outside the session changes. All remaining pre-commit hooks passed, including codespell, stub generation, ty and Biome, with no tracked changes.backend_vars; documented in the companion PR.The stack remains draft for the concrete review findings listed in #7362 and #7363.