Skip to content

Validate enforced sessions and document migration - #7364

Draft
masenf wants to merge 1 commit into
codex/session-frontendfrom
codex/session-integration
Draft

masenf wants to merge 1 commit into
codex/session-frontendfrom
codex/session-integration

Conversation

@masenf

@masenf masenf commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Exercise session ownership in real servers and browsers, migrate synthetic clients to server-issued credentials, and document rollout/deployment. The development AppHarness uses the same frontend/backend hostname so cookie behavior is realistic.

Covers ENG-12920 and ENG-12921. Top of the core stack: #7360 → #7361 → #7362 → #7363 → #7364. Enterprise companion: reflex-dev/reflex-enterprise#240.

The existing backend-path app now runs under enforce and covers held cookie exchange with immediate hydration/events, shared-session tabs, duplicated tabs, upload, short-TTL refresh, backend restart and cross-site iframe persistence. The existing EmbedPlugin host app also runs under enforce. A backend-only real Granian test proves state events complete while cookie exchange is held and reconnect preserves state; no new public harness server-switching API was necessary. Benchmark reconnects reuse cookies and bound client tokens, and issuance stays outside measured event latency. The reflex-bench driver already handled server replacement tokens, so its production implementation is unchanged; regression coverage includes the new control events. Legacy JavaScript behavior is covered at the protocol/unit boundary rather than bundling an old frontend build.

The guide documents key rotation/persistence, origin configuration, partitioned cookies, embedding, off/warn/enforce, explicit SYSTEM authority, anonymous overrides, tools and enterprise compatibility. Rate limiting uses existing reverse-proxy/api_transformer facilities instead of adding a second public hook.

Validation:

  • All 58 Chromium cases passed across development/production and zero/one/two-level backend paths, including six cross-site iframe configurations and four EmbedPlugin cases. Initial iframe failures were test-host local-network classification; the real isolated host fixture passes.
  • Real Granian session roundtrip: 1 passed. Session-related real Redis run: 270 passed.
  • Full unit run: 10,270 passed, 21 skipped, one unrelated localhost connection-refused test timed out. Its entire 19-test module passed on rerun. Aggregate coverage: 79.51% (72% required).
  • Ruff check/format and pyright reflex tests clean. Stub generation made no tracked changes. Full-repository pre-commit Pyright hits four existing macOS type errors in unchanged reflex-bench Linux CPU-affinity code (os.sched_setaffinity, os.sched_getaffinity, Process.cpu_affinity); these are outside the session changes. All remaining pre-commit hooks passed, including codespell, stub generation, ty and Biome, with no tracked changes.
  • Enterprise: 149 older-core tests and 10 focused core-overlay/runtime tests passed. Full AuthPlugin E2E remains unverified because its existing fixture uses removed core backend_vars; documented in the companion PR.

The stack remains draft for the concrete review findings listed in #7362 and #7363.

@masenf
masenf added this pull request to stack #7365 September 30, 2026 00:41
@masenf masenf changed the title Exercise enforced sessions across servers and browsers and document migration Validate enforced sessions and document migration Sep 30, 2026
@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[Critical risk] Enforces browser session ownership for state access across servers.

The PR appears safe to merge, though two integration-test setups should be made more representative and reliable.

Findings

  1. P2 Host page may be unreachable ▶
  2. P2 Production restart bypasses production setup ▶

Summary

This PR documents browser-session rollout and migration, adapts benchmark clients to obtain bound sessions, changes the development harness’s backend URL hostname, and adds server and browser integration coverage. Two test-harness details need tightening: the cross-site host’s bind address and the production restart path.

Reviews (1) · Last reviewed commit: "Exercise enforced sessions across server..."

Comment on lines +386 to +388
with ThreadingHTTPServer(
("127.0.0.1", 0), partial(SimpleHTTPRequestHandler, directory=str(tmp_path))
) as server:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Host page may be unreachable If the frontend URL uses 127.0.0.1 and localhost resolves to IPv6 loopback, this test navigates to localhost while its host-page server listens only on 127.0.0.1. The page cannot load, so the cross-site iframe test fails before checking session behavior. Bind the server for the hostname the test selects.

Comment on lines +360 to +362
# The base harness supports binding the original port in both build modes.
AppHarness._start_backend(backend_path_app, port=port)
backend_path_app._poll_for_servers(timeout=10)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Production restart bypasses production setup This test also runs with AppHarnessProd, but it restarts the backend through the base harness method. That skips the production starter’s worker configuration and compile-suppression setup, so the prod case does not exercise a production-style restart. Preserve those settings when rebinding the original port.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant