v2.4.0
This commit is contained in:
@@ -5821,6 +5821,26 @@ async function api(path, opts = {}) {
|
||||
return data;
|
||||
}
|
||||
|
||||
const LAST_USER_KEY = 'cherryclaw_last_user';
|
||||
|
||||
function clearLocalUserState(reason) {
|
||||
try {
|
||||
localStorage.removeItem(CHAT_SESSIONS_KEY);
|
||||
localStorage.removeItem(AGENT_SESSION_KEY);
|
||||
} catch {}
|
||||
try {
|
||||
chatSessions = [];
|
||||
activeChatSessionId = null;
|
||||
} catch {}
|
||||
setAgentSessionId(generateSessionId());
|
||||
// Rebuild a fresh "New chat" + re-render so the UI does not briefly
|
||||
// display the previous user's session list before the wipe takes effect.
|
||||
try { if (typeof loadChatSessions === 'function') loadChatSessions(); } catch {}
|
||||
try { if (typeof renderSessionsList === 'function') renderSessionsList(); } catch {}
|
||||
try { if (typeof renderMessages === 'function') renderMessages(); } catch {}
|
||||
console.log(`[auth] cleared local session state (${reason})`);
|
||||
}
|
||||
|
||||
async function checkAuth() {
|
||||
try {
|
||||
const res = await fetch('/api/auth/status');
|
||||
@@ -5835,6 +5855,16 @@ async function checkAuth() {
|
||||
}
|
||||
if (data.authenticated && data.username) {
|
||||
currentUser = { username: data.username, role: data.role };
|
||||
|
||||
// Multi-user safety: if a different user was logged in on this browser
|
||||
// before, wipe the cached session list & active sessionId so the
|
||||
// incoming user does not reuse the previous user's chat IDs.
|
||||
const lastUser = (localStorage.getItem(LAST_USER_KEY) || '').trim();
|
||||
if (lastUser && lastUser !== data.username) {
|
||||
clearLocalUserState(`user changed: ${lastUser} -> ${data.username}`);
|
||||
}
|
||||
try { localStorage.setItem(LAST_USER_KEY, data.username); } catch {}
|
||||
|
||||
// Show user pill with username
|
||||
const pill = document.getElementById('user-info-pill');
|
||||
const nameEl = document.getElementById('user-info-name');
|
||||
@@ -5852,6 +5882,10 @@ async function logout() {
|
||||
try {
|
||||
await fetch('/api/auth/logout', { method: 'POST', credentials: 'same-origin' });
|
||||
} catch (e) { /* ignore network errors */ }
|
||||
// Wipe cached chat list / sessionId so a different user logging in next
|
||||
// does not inherit any of this user's session IDs.
|
||||
clearLocalUserState('logout');
|
||||
try { localStorage.removeItem(LAST_USER_KEY); } catch {}
|
||||
window.location.href = '/login.html';
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user