fix(auth) : keep Guide sessions beyond Sudloh token expiry
This commit is contained in:
@@ -17,9 +17,11 @@ endorsed by HoYoverse. The repository and deployment resources retain the
|
||||
- **Accounts:** Sudloh Account OIDC sign-in with local Buzz sessions, IDs, and
|
||||
roles. Legacy email/password and registration OTP remain available only before
|
||||
`SUDLOH_OIDC_ONLY=true` cutover. Linked profiles are managed at Sudloh Account;
|
||||
Guide refreshes their profile from UserInfo and checks Sudloh token activity on
|
||||
protected requests at least every five minutes. Access tokens expire after
|
||||
about an hour and require a new Sudloh authorization flow.
|
||||
Guide refreshes their profile from UserInfo on request. Guide sessions follow
|
||||
Better Auth's rolling session lifetime rather than the roughly one-hour Sudloh
|
||||
access token. A fresh Sudloh authorization is needed to refresh a profile after
|
||||
that token expires. Sudloh Account sign-out or revocation does not end an
|
||||
existing Guide session; users must also sign out of Guide.
|
||||
- **Media:** S3-compatible uploads and publication-aware delivery for staged files.
|
||||
- **Catalog updates:** Discord-triggered synchronization with Lunaris.
|
||||
- **Commissions:** PromptPay checkout, Slip2Go verification, ticket attachments,
|
||||
|
||||
Reference in New Issue
Block a user