Skip to content

fix(auth): honor Payload sessions for OAuth tokens#70

Merged
WilsonLe merged 2 commits into
mainfrom
52-integrate-auth-session
May 7, 2026
Merged

fix(auth): honor Payload sessions for OAuth tokens#70
WilsonLe merged 2 commits into
mainfrom
52-integrate-auth-session

Conversation

@WilsonLe
Copy link
Copy Markdown
Owner

@WilsonLe WilsonLe commented May 7, 2026

Summary

  • create Payload session records during OAuth callback when Payload sessions are active
  • include the session sid in OAuth-issued Payload JWTs and validate it in the auth strategy
  • reject sid-less or revoked session JWTs instead of recreating users from them
  • move project instruction files under docs/instructions and add session troubleshooting guidance

Closes #52
Closes #62

Tests

  • corepack pnpm build
  • corepack pnpm test

@WilsonLe WilsonLe force-pushed the 52-integrate-auth-session branch from dd99f92 to 9f3c1a7 Compare May 7, 2026 15:46
@WilsonLe WilsonLe merged commit 6fc088a into main May 7, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Auth strategy does not honor useSessions — logged-out JWTs are silently resurrected integrate auth session

2 participants