Skip to content

fix(auth): stop sweepStore aborting the sign-in purge on one throwing removeItem (#5763) - #5779

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-5763-sweepstore-per-key-try
Aug 23, 2026
Merged

fix(auth): stop sweepStore aborting the sign-in purge on one throwing removeItem (#5763)#5779
os-zhuang merged 1 commit into
mainfrom
claude/issue-5763-sweepstore-per-key-try

Conversation

@os-zhuang

@os-zhuangos-zhuang commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Fixes#5763

The shape

packages/auth/src/ActiveOrganizationStorage.ts, sweepStore():

functionsweepStore(store: Storage|undefined): void{if(!store)return;try{for(constkeyofObject.keys(store)){if(DEVICE_SCOPED_KEYS.has(key))continue;store.removeItem(key);}}catch{/* storage unavailable */}}

The try wrapped the WHOLE loop, not each removal. A removeItem that threw on key
n aborted the walk, so keys n+1..end were never swept, and the failure was
swallowed — purgePreviousUserClientState() returned normally and SessionUserScope.adopt
believed the sign-in purge had completed. This is the #5664 allowlist sweep (part 3 of
that fix) precisely so the next un-namespaced key — one nobody has written yet — cannot
re-open the cross-user pollution class; a partial sweep is a partial allowlist, and
which keys survived depended on Object.keys iteration order rather than on anything
bounded.

What changed

Object.keys(store) — the reason a guard exists here at all — stays guarded on its
own; only the per-key guard is new, so one uncooperative key now costs exactly that
key, not the rest of the purge (the invariant triage named).

functionsweepStore(store: Storage|undefined): void{if(!store)return;letkeys: string[];try{keys=Object.keys(store);}catch{return;/* storage unavailable */}constunswept: string[]=[];for(constkeyofkeys){if(DEVICE_SCOPED_KEYS.has(key))continue;try{store.removeItem(key);}catch{unswept.push(key);}}if(unswept.length>0){console.warn(`[purgePreviousUserClientState] could not remove ${unswept.length} key(s) …`);}}

The "should a failed sweep report" question — measured, and where it diverges from #5731

Triage directed following whatever #5731's landed answer (PR #5764, merged before this
branch was cut) was for clear(), and saying so explicitly if it doesn't transfer. Read
on origin/main at 286dd8d:

  • clear()'s verdict is a READ-BACK (removePersisted returns whether the key is
    still readable after the attempt), not "did removeItem throw" — because a wrapped or
    proxied localStorage whose removeItem is a silent no-op never throws and leaves
    identical residue.
  • clear() quarantines a key whose removal it cannot verify, in _unremovedKeys,
    so get() skips the persisted branch for it and answers from _memoryValue instead —
    the quarantine is what turns the verdict into an outcome.
  • clear() reports via console.warn, because none of its five callers (including
    purgePreviousUserClientState itself) can act on a storage failure.

Reporting transfers; read-back-verdict and quarantine do not, and here is why.
clear() can quarantine because it owns every future read of its ONE key, through
ActiveOrganizationStorage.get() — the quarantine is meaningless without a get() to
consult it. sweepStore walks an open-ended set of keys it does not own reads for
(another package's recents cache, a metadata seed written by MetadataProvider) — there
is no get() here to guard, so there is nothing to quarantine, and building a
generalized read-back-plus-quarantine mechanism for keys this function doesn't otherwise
touch would be the "general storage-error-handling refactor of the module" the card
scopes this fix away from. What is mirrored is the channel: a key whose removeItem
throws is named in a console.warn, same as clear(), so the failure the card's title
is about — a silent partial purge — is now discoverable. The caller
(SessionUserScope.adopt, on the sign-in path, inside an AuthProvider effect) still
cannot act on it and must not throw either, same reasoning #5731 laid out for the
sign-out callers.

One consequence worth naming: because the verdict here is "did removeItem throw" and
not a read-back, a wrapped/proxied localStorage whose removeItem is a silent no-op
(the "too narrow" case #5731's own docblock names) would sweep silently and unreported
through this function — narrower coverage than clear()'s. That gap is accepted as
in-scope-for-#5731-only, not closed here; closing it would mean the same generalization
just ruled out.

Tests

packages/auth/src/__tests__/sessionUserChangePurge-5664.test.tsx, two new cases (14
total in the file, up from 12; 23 total across it and activeOrgStorageFallback-5703.test.tsx):

  • sweeps every other non-device-scoped key when one removeItem throws (#5763) — a
    localStorage.removeItem spy throws for one poisoned key, with keys seeded on BOTH
    sides of it in insertion order. Asserts every other key — including the one seeded
    after the poison — is swept in both stores, the device-scoped allowlist survives,
    and the failure is named once in a console.warn containing the poisoned key.
  • reports nothing when every removal sticks — control on the case above: no
    console.warn call on a healthy sweep, so the warning is a measurement of an actual
    failure and not a constant.

Reverse verification (fix committed first, so the restore below is a real
checkpoint, not the working tree as the only copy):

git checkout origin/main -- packages/auth/src/ActiveOrganizationStorage.ts
pnpm exec vitest run packages/auth/src/__tests__/sessionUserChangePurge-5664.test.tsx -t "removeItem throws"
FAIL … > sweeps every other non-device-scoped key when one removeItem throws (#5763)
AssertionError: expected '["acct_2"]' to be null
345| expect(localStorage.getItem('objectui-favorites')).toBeNull();

objectui-favorites — seeded after the poisoned key — survives on pre-fix code
exactly as the card describes: the whole-loop try aborts the walk at the throw. Fix
restored with git checkout claude/issue-5763-sweepstore-per-key-try -- packages/auth/src/ActiveOrganizationStorage.ts;
tree byte-identical to the committed fix (git status clean), full suite re-run green
afterward.

A real-jsdom Storage gotcha found while writing the case, noted for the next
person:
vi.spyOn(localStorage, 'removeItem').mockImplementation(...) was observed to
survive this file's shared afterEach(() => vi.restoreAllMocks()) — the very next test
measured the mock still installed on entry ((localStorage.removeItem as any).mock !== undefined was true). Fixed by capturing the spy and calling .mockRestore()
explicitly in a finally inside the test that installs it, rather than relying on the
shared teardown for this particular spy target.

Verification — union run at 8e1409881 (final commit, clean tree)

checkresult
vitest run packages/auth/src/__tests__/sessionUserChangePurge-5664.test.tsx packages/auth/src/__tests__/activeOrgStorageFallback-5703.test.tsxexit 0 — 23 tests passed
vitest run packages/auth/exit 0 — 24 files, 248 tests passed (was 246 at #5764's baseline; +2 new here)
pnpm --filter @object-ui/auth type-checkexit 0 (tsc --noEmitandtsc -p tsconfig.test.json)
pnpm --filter @object-ui/auth lintexit 0 — ✖ 29 problems (0 errors, 29 warnings), same count as #5764's baseline, none in the changed files
check-control-bytesexit 0 — OK (scanned 4814 tracked text file(s); skipped 85 binary)
check-changeset-presenceexit 0 — 2 source file(s) of 1 released package(s) changed … declares 1 changeset(s)
check-changeset-no-major · check-changeset-fixedexit 0

@object-ui/auth is vitest-aliased to packages/auth/src, so every run above exercises
the edited source directly — no dist/ in the resolution path.

Serial-note discharge (triage's note)

Triage's serial note said this shares ActiveOrganizationStorage.ts with #5731's
then-in-flight PR and to land after it or rebase. #5731's PR #5764 merged to main at
0610ca74b (2026-08-23, before this branch was cut from origin/main at 286dd8daa),
so this branch already contains that fix — confirmed by reading the file on this base:
removePersisted's read-back verdict and ActiveOrganizationStorage._unremovedKeys are
already present. Nothing to serialise behind.

Out of scope

AuthProvider.tsx's purgeSignedOutClientCaches() — the sign-out counterpart, which
purges sessionStorage metadata-seed-cache keys — has the identical shape: a try
wrapping the whole loop instead of each removeItem. Same defect class, different file,
different caller, and this card's own scope note rules out widening into a general
refactor of the module. Filed separately, unassigned: #5777.


Generated by Claude Code

… removeItem
sweepStore's try wrapped the WHOLE loop, not each removal. A removeItem
that threw on key n aborted the walk, so keys n+1..end were never swept,
and the failure was swallowed — purgePreviousUserClientState() returned
normally and SessionUserScope.adopt believed the sign-in purge had
completed. This is the #5664 allowlist sweep; a partial sweep is a
partial allowlist, and which keys survived depended on Object.keys
iteration order rather than on anything bounded.
Object.keys(store) — the reason a guard exists here at all — stays
guarded on its own; only the per-key guard is new. Unlike
ActiveOrganizationStorage.clear() (#5731), a failed removal here is not
verified by read-back and not quarantined: clear() owns every future
read of its one key through get(), which is what makes a quarantine
meaningful; sweepStore walks keys it does not own reads for, so there is
no get() to guard and nothing to quarantine here — adding read-back
verification would be a general storage-error-handling refactor of the
module, out of this card's scope. What is mirrored is the reporting
channel: a key whose removeItem throws is named in a console.warn, the
same channel clear() uses, so a partial sweep is discoverable instead of
silent.
Adds a partial-failure test: a store whose removeItem throws on one key,
asserting every other non-device-scoped key on both sides of it is still
swept and the device-scoped allowlist is still respected, plus a control
that the warning fires only on an actual failure.
Fixes#5763
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EuPCi56cnGyykygi3z9w4m
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3918.5 KB3990.2 KB
Main entry chunk (gzip)152.5 KB350 KB
Entry fileindex-CIubIJsP.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)33.99KB8.57KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)511.23KB115.03KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)164.55KB45.67KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)44.39KB14.99KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.88KB1.85KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)3.40KB1.68KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 23, 2026 07:55
@os-zhuang
os-zhuang added this pull request to the merge queueAug 23, 2026
Merged via the queue into main with commit ff2d547Aug 23, 2026
23 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-5763-sweepstore-per-key-try branch August 23, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sweepStore's try wraps the whole loop, so one throwing removeItem silently cancels the rest of the session-user purge

2 participants

@os-zhuang@claude