fix: retry vault read on resume-window IPC failure to prevent false sign-out - #1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@BekibooBekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes#1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint:biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@BekibooBekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitaiBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s)Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check✅ PassedThe description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check✅ PassedThe PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check✅ PassedThe added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code ownerJuly 13, 2026 13:59

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+ `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =+ null;+
get vault() {
- return this.#readVaultResilient();+ if (!this.#pendingVaultRead) {+ this.#pendingVaultRead = this.#readVaultResilient().finally(+ () => {+ this.#pendingVaultRead = null;+ },+ );+ }+ return this.#pendingVaultRead;
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@BekibooBekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-outfix: retry vault read on resume-window IPC failure to prevent false sign-outJul 13, 2026
@coodos
coodos merged commit 1337847 into mainJul 15, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants

@Bekiboo@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: retry vault read on resume-window IPC failure to prevent false sign-out - #1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@BekibooBekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes#1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint:biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@BekibooBekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitaiBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s)Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check✅ PassedThe description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check✅ PassedThe PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check✅ PassedThe added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code ownerJuly 13, 2026 13:59

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+ `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =+ null;+
get vault() {
- return this.#readVaultResilient();+ if (!this.#pendingVaultRead) {+ this.#pendingVaultRead = this.#readVaultResilient().finally(+ () => {+ this.#pendingVaultRead = null;+ },+ );+ }+ return this.#pendingVaultRead;
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@BekibooBekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-outfix: retry vault read on resume-window IPC failure to prevent false sign-outJul 13, 2026
@coodos
coodos merged commit 1337847 into mainJul 15, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants

@Bekiboo@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: retry vault read on resume-window IPC failure to prevent false sign-out - #1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@BekibooBekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes#1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint:biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@BekibooBekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitaiBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s)Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check✅ PassedThe description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check✅ PassedThe PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check✅ PassedThe added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code ownerJuly 13, 2026 13:59

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+ `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =+ null;+
get vault() {
- return this.#readVaultResilient();+ if (!this.#pendingVaultRead) {+ this.#pendingVaultRead = this.#readVaultResilient().finally(+ () => {+ this.#pendingVaultRead = null;+ },+ );+ }+ return this.#pendingVaultRead;
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@BekibooBekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-outfix: retry vault read on resume-window IPC failure to prevent false sign-outJul 13, 2026
@coodos
coodos merged commit 1337847 into mainJul 15, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants

@Bekiboo@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: retry vault read on resume-window IPC failure to prevent false sign-out - #1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@BekibooBekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes#1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint:biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@BekibooBekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitaiBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s)Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check✅ PassedThe description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check✅ PassedThe PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check✅ PassedThe added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code ownerJuly 13, 2026 13:59

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+ `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =+ null;+
get vault() {
- return this.#readVaultResilient();+ if (!this.#pendingVaultRead) {+ this.#pendingVaultRead = this.#readVaultResilient().finally(+ () => {+ this.#pendingVaultRead = null;+ },+ );+ }+ return this.#pendingVaultRead;
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@BekibooBekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-outfix: retry vault read on resume-window IPC failure to prevent false sign-outJul 13, 2026
@coodos
coodos merged commit 1337847 into mainJul 15, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants

@Bekiboo@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: retry vault read on resume-window IPC failure to prevent false sign-out - #1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@BekibooBekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes#1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint:biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@BekibooBekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitaiBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s)Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check✅ PassedThe description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check✅ PassedThe PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check✅ PassedThe added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code ownerJuly 13, 2026 13:59

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+ `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =+ null;+
get vault() {
- return this.#readVaultResilient();+ if (!this.#pendingVaultRead) {+ this.#pendingVaultRead = this.#readVaultResilient().finally(+ () => {+ this.#pendingVaultRead = null;+ },+ );+ }+ return this.#pendingVaultRead;
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@BekibooBekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-outfix: retry vault read on resume-window IPC failure to prevent false sign-outJul 13, 2026
@coodos
coodos merged commit 1337847 into mainJul 15, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants

@Bekiboo@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: retry vault read on resume-window IPC failure to prevent false sign-out - #1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@BekibooBekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes#1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint:biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@BekibooBekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitaiBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s)Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check✅ PassedThe description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check✅ PassedThe PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check✅ PassedThe added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code ownerJuly 13, 2026 13:59

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+ `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =+ null;+
get vault() {
- return this.#readVaultResilient();+ if (!this.#pendingVaultRead) {+ this.#pendingVaultRead = this.#readVaultResilient().finally(+ () => {+ this.#pendingVaultRead = null;+ },+ );+ }+ return this.#pendingVaultRead;
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@BekibooBekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-outfix: retry vault read on resume-window IPC failure to prevent false sign-outJul 13, 2026
@coodos
coodos merged commit 1337847 into mainJul 15, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants

@Bekiboo@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: retry vault read on resume-window IPC failure to prevent false sign-out - #1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@BekibooBekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes#1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint:biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@BekibooBekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitaiBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s)Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check✅ PassedThe description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check✅ PassedThe PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check✅ PassedThe added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code ownerJuly 13, 2026 13:59

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+ `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =+ null;+
get vault() {
- return this.#readVaultResilient();+ if (!this.#pendingVaultRead) {+ this.#pendingVaultRead = this.#readVaultResilient().finally(+ () => {+ this.#pendingVaultRead = null;+ },+ );+ }+ return this.#pendingVaultRead;
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@BekibooBekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-outfix: retry vault read on resume-window IPC failure to prevent false sign-outJul 13, 2026
@coodos
coodos merged commit 1337847 into mainJul 15, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants

@Bekiboo@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: retry vault read on resume-window IPC failure to prevent false sign-out - #1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@BekibooBekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes#1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint:biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@BekibooBekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitaiBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s)Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check✅ PassedThe description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check✅ PassedThe PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check✅ PassedThe added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code ownerJuly 13, 2026 13:59

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+ `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =+ null;+
get vault() {
- return this.#readVaultResilient();+ if (!this.#pendingVaultRead) {+ this.#pendingVaultRead = this.#readVaultResilient().finally(+ () => {+ this.#pendingVaultRead = null;+ },+ );+ }+ return this.#pendingVaultRead;
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@BekibooBekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-outfix: retry vault read on resume-window IPC failure to prevent false sign-outJul 13, 2026
@coodos
coodos merged commit 1337847 into mainJul 15, 2026
4 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants

@Bekiboo@coodos