fix(auth) : keep Guide sessions beyond Sudloh token expiry
CI / Verify (push) Successful in 1m31s
CI / Build immutable images and deploy (push) Successful in 2m16s

This commit is contained in:
2026-10-06 18:00:42 +07:00 Unverified
parent 41014ef654
commit 4b16941e11
14 changed files with 74 additions and 236 deletions
+5 -3
View File
@@ -17,9 +17,11 @@ endorsed by HoYoverse. The repository and deployment resources retain the
- **Accounts:** Sudloh Account OIDC sign-in with local Buzz sessions, IDs, and
roles. Legacy email/password and registration OTP remain available only before
`SUDLOH_OIDC_ONLY=true` cutover. Linked profiles are managed at Sudloh Account;
Guide refreshes their profile from UserInfo and checks Sudloh token activity on
protected requests at least every five minutes. Access tokens expire after
about an hour and require a new Sudloh authorization flow.
Guide refreshes their profile from UserInfo on request. Guide sessions follow
Better Auth's rolling session lifetime rather than the roughly one-hour Sudloh
access token. A fresh Sudloh authorization is needed to refresh a profile after
that token expires. Sudloh Account sign-out or revocation does not end an
existing Guide session; users must also sign out of Guide.
- **Media:** S3-compatible uploads and publication-aware delivery for staged files.
- **Catalog updates:** Discord-triggered synchronization with Lunaris.
- **Commissions:** PromptPay checkout, Slip2Go verification, ticket attachments,