Skip to content

Keep refresh ownership in the launcher and share read-only access - #7

Closed
aShanki wants to merge 3 commits into
mainfrom
rajesh/2c8b189ffca218f8c585
Closed

aShanki wants to merge 3 commits into
mainfrom
rajesh/2c8b189ffca218f8c585

Conversation

@aShanki

@aShanki aShanki commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Keep the launcher as the sole owner of the PasswordVault login credential. Publish a separate short-lived access entry for the read-only DLL in DLL PR #1020, clear it on logout/account replacement, and renew it while the launcher is open.

Renewal uses the existing account gate, skips busy operations and gives each exchange a ten-second timeout. Transient failures retain login. Failed-refresh/profile cleanup finishes before the gate is released, and logout clears access even when the refresh entry is missing. This replaces the shared-writer approach in #6.

The DLL never redeems or updates the refresh credential. Closing the launcher stops renewal; access expires normally and reopening the launcher renews it. Both changes must ship together. Existing issued server sessions retain their current expiry rules.

Validation: synthetic source-linked handoff/renewal/rotation/logout/exclusion/failure tests and full Windows Debug/Release builds passed, with zero build warnings/errors, in PR-only CI with read-only permissions and no publication steps. Packaged-launcher/injected-game vault visibility still needs a Windows smoke test. No merge or deployment.

@aShanki aShanki closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant