fix: IDEAS.md quickfixes — idle-timeout app config, id_token out of Claims, FormEvent import
session.idle_timeout (minutes, default 15) joins the app-config registry and drives the onboarding Garmin session eviction, distinct from session.duration (the login cookie lifetime in hours). The raw Keycloak ID token no longer rides in auth.Claims through every request context: it's minted into the session cookie separately and read back only by the logout handler via IDTokenFromSessionCookie. OnboardingWizard uses the type-imported FormEvent<HTMLFormElement> instead of the React.FormEvent namespace alias. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -53,6 +53,11 @@ type Server struct {
|
||||
// never call os.Getenv.
|
||||
EnvVars []EnvVar
|
||||
|
||||
// SetupSessionIdleTimeout is the app-config session.idle_timeout value
|
||||
// (see internal/config); zero falls back to
|
||||
// defaultSetupSessionIdleTimeout.
|
||||
SetupSessionIdleTimeout time.Duration
|
||||
|
||||
mu sync.Mutex
|
||||
userClient map[int64]garmin.Client
|
||||
userSync map[int64]*garmin.Sync
|
||||
|
||||
Reference in New Issue
Block a user