Skip to content

fix: serialize shared account credentials and await logout cleanup - #6

Closed
vani11agirl wants to merge 1 commit into
flarialmc:mainfrom
vani11agirl:slop/account-session-coordination
Closed

vani11agirl wants to merge 1 commit into
flarialmc:mainfrom
vani11agirl:slop/account-session-coordination

Conversation

@vani11agirl

@vani11agirl vani11agirl commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Account operations previously used only a launcher-local semaphore, allowing refresh rotation to race the injected DLL. Failed refresh/profile cleanup also queued a later logout that could remove a subsequently signed-in account.

Use the same per-Windows-user named mutex as https://github.com/flarialmc/dll-css/pull/1019 across refresh, credential commit, and logout. Preserve the local async gate, keep browser authorization outside the shared lease, and retain mutex ownership on one worker thread across async work. Cleanup now completes within its current transaction, and logout always clears beta access even if the vault is empty.

Validation:

  • Full launcher and runtime Debug/Release builds passed with zero warnings/errors. Release was restored with its normal ReadyToRun dependencies; no build settings were relaxed.
  • Account regressions pass in Debug and Release with synthetic credentials and an in-memory provider. They cover awaited cleanup, beta cache removal, async exclusion, exception release, cross-process exclusion, and abandoned-owner recovery.
  • The old AuthenticationManager fails the cleanup-order and missing-vault beta-cache regressions for the intended assertions.
  • Native/.NET exclusion and crash recovery passed against the actual DLL lease test executable.
  • PR-only CI passed the runtime build and account suite in Debug and Release with read-only repository permissions and no publishing path.

Ship alongside DLL PR #1019 after packaged-launcher/injected-game smoke testing of mutex permissions, vault visibility, refresh, logout, and account switching. Older versions bypass the shared lease, so mixed installations do not provide full coordination. A crash between issuer rotation and persistence can still require signing in again; already-issued JWT revocation is separate.

This draft uses a fork branch. No production vault/endpoints, signing, CDN deployment, workflow dispatch, or merge was performed.

@Aetopia

Aetopia commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Please clarify what the issue is & what the PR addresses.

  • Please explain the issue briefly without AI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants